E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA:...

10
E-Privacy in the New Econ omy Conference, Hong Kong , 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant Commissioner Office of the Privacy Commissioner New Zealand

Transcript of E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA:...

Page 1: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

1

PRIVACY IMPACT ASSESSMENTPIA: Some Approaches, Issues and Examples

Blair Stewart

Assistant Commissioner

Office of the Privacy

Commissioner

New Zealand

Page 2: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

2

What is PIA? Assessment of any actual or

potential effects that a proposal may have on privacy and the ways in which any adverse effects can be mitigated

Not privacy compliance audit Not legal opinion

Page 3: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

3

When is PIA useful?

New technologies Known intrusive technology Major change to information

systems

Where privacy will be affected

Page 4: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

4

Example topic areas

Public health databases Linking of databases Surveillance projects Assigning population numbers New technology in ID applications Data warehouses

Page 5: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

5

Growth in PIA Interest since 1997 Take off 1999+

Page 6: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

6

PIAs as regulatory requirement Alberta: compulsary in health area Ontario: provincial govt practice NZ Req’d for data matching,

sometimes for exemptions

Future? Maybe where special permissions are needed, major public projects

Page 7: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

7

PIA Content See detailed guidelines Overview Description Data collection, use, disclosure Privacy standards, security

measures Conclusions, findings,

recommendations Sources

Page 8: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

8

Who might undertake PIA? Competent expertise Independent element

Some issues: Mouthpiece/ advocate or expert? In-house assessment?

Page 9: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

9

What happens when PIA complete? Integrate into decision-making Public release of findings

Page 10: E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001 1 PRIVACY IMPACT ASSESSMENT PIA: Some Approaches, Issues and Examples Blair Stewart Assistant.

E-Privacy in the New Economy Conference, Hong Kong, 26 March 2001

10

Privacy Impact Assessment Resources Bibligraphy Published guidelines List of PIAs