Frente a la abundante información sobre nuevas tecnologías y modernidad resulta difícil reflexionar sobre sus aristas y entramados sin un mínimo intercambio de opiniones. Este espacio da su mirada desde el derecho y pretende trae a la palestra de análisis temas de interés que en algún momento podrán ser de utilidad para algún visitante o bien para mi mismo. Sin grandes aspiraciones pero con mucho placer por bloggear.
The chief obstacle to being part of the 21st century world — in which jobs, education, healthcare, and access to government services are all online — is the cost of high-speed access and computers.
jueves, 30 de abril de 2015
lunes, 20 de abril de 2015
Relevant recommendations from Argentine National Personal Data Protection Direction regarding privacy protection in the development of Software Applications. IoT will be subject to these guidelines?
The National Personal Data Protection Direction
(hereinafter “NPDPD”) recently approved the Recommended Good Practices
regarding Privacy for the development of Software Applications (hereinafter
“RGPPSA”). Although the RGPPSA are not mandatory they should be considered as
guidelines to be followed as it is the first document issued by the NPDPD to
provide orientation in the management of privacy for the software
industry.
The RGPPSA become crucial for the new era of
software application developments related to Big Data and Internet of Things
where sensitive consumer information may be jeopardized.
The RGPPSA set forth the following 8 basic
steps to develop software safeguarding privacy: i) keep in mind privacy in all
the process of the company developing the software applications; ii) to develop
the applications following the Privacy by Design criteria meaning that the
privacy protection shall be considered since the first steps of the application
design and followed in all the other phases of the development of the system or
application; iii) set forth a clear privacy policy and accessible for the
personal data owners; iv) to set up by default the activation of privacy
options (Privacy by Default) in a way that shall imply an express voluntary act
from the data owner to share personal information or deactivate privacy options;
v) provide to data owner the right to choose and control; vi) to limit the
quantity of data to be collected and kept through the Privacy-Enhancing
Technologies (PET) that are certain measures that permit to eliminate or
minimize personal data and avoiding unwanted process of personal data without
affecting the functionalities of the information service; vii) ensure the
personal data collected; viii) to assume liability for the data collected with
the appointment of a Responsible for privacy issues.
Among the PET tools mentioned by the RGPPSA to
protect privacy are: a) Dissociation of data: mechanism to hide the data owner´s
identity avoiding the association of the data with determined person or
determinable person; b) Pseudonymisation: allow to perform operations without
identifying the data owner, identified only with a pseudonym; c) Information
Security: The main goal is to avoid any
unauthorized access to the systems, files or communications through a network;
d) Metadata: Recommended to incorporate
labels to be added to those files with personal data explaining the source,
obtained consent and scope of the referred consent, how they can be used,
privacy policy that are applicable and applicable term of storage; v)
Encryption: The use of this mechanism shall not be limited to secure storage as
it shall be extended to ensure its integrity, a safety transport through a
network or physical devices or secure access to personal data.
Recommendations given
by RGPPSA for privacy policy implementation: Provide clear explanation about the type of
information requested, the way in which it will be used and with whom is going
to be shared.
The privacy policy should be simple and
standardized to facilitate its reading and understanding by the data owners and
clearly explaining data process subject under the application. Therefore the
policy should explain the peculiarities of its application avoiding to incur in
cut and paste practices of other policy applicable to other application or
developer. Any change incorporated to the policy should be duly notified.
Pursuant to RGPPSA any privacy policy shall
comply with the following guidelines:
i)
Provide
a definition of the protected matter under the privacy policy (which is the
subject matter to be protected, the scope (obligors under the policy to be implemented) and compatibility and interrelation with other policies (commercial information protection).
subject matter to be protected, the scope (obligors under the policy to be implemented) and compatibility and interrelation with other policies (commercial information protection).
ii)
Include a section of definitions included in
the privacy policy that should follow the criteria of National Law of Personal
Data Protection, Law N° 25,326 (hereinafter “NLPDP”).
iii)
Comply with the following principles
applicable to data protection: a) quality of data; b) data protection
principles of free and informed consent in accordance with sections 5 and 6 of
NLPDP; c) sensitive personal data treatment following provisions of section 7
of NLDPD.
iv)
In the case of share or transfer of personal
data to a third party it shall be clearly noted in the policy and comply with
the requirements applicable to the personal data transfer in compliance of
Section 11 of NLDPD (inform purpose of the assignment and the identification of
third party receiving the data).
v)
Adopt confidentiality agreements with
employees and third parties providing services that make have notice of the
personal data to be treated by the application.
vi)
Include reference to personal data security
policy and its applicable regulation regarding security manual. (Disposition
DNPDP N° 11/06).
vii)
In the event of international data transfer
the country receiving the data shall have sufficient level of protection in the
treatment of personal data or the owner such data should have consented the
transfer to such country. The RGPPSA clearly states that storage
in the cloud shall be considered as an international data transfer.
viii)
If the use of personal data includes an
advertisement goal the specific obligations mentioned in Section 27 of NLDPD
and applicable regulations (Dispositions DNPDP N° 10/08 and 4/09) shall be
complied.
ix)
Include the procedures to allow the owner of
the personal data exercise the access, rectification, suppression and blockage
rights.
x)
Inform who is the responsible of the Data
Protection (it can be either identified officer or a specific area of the
company). The Data Protection Officer will be responsible for: a) ensuring that
any data treatment performed by any applications shall comply with data
protection regulations; b) revise and keep updated the Privacy Policy of the
organization and that the applications followed such policy; c) respond to any
inquiry regarding the Privacy Policy, the rights of the personal data owner and
the requirements from the competent authorities; d) Provide training on
personal data protection to employees; and e) control those third parties to
whom data is transferred or from whom is received (verify whether they are
registered with the NPDPD).
viernes, 3 de abril de 2015
viernes, 20 de marzo de 2015
Importante impacto de la Circular 1468 de la FIFA sobre las deudas de los clubes y que rige desde el 1ero de marzo.
Las modificaciones introducidas por la FIFA a través de la Circular 1468 al Reglamento de Procedimiento de la Comisión del Estatuto del Jugador y de la Cámara de Resolución de Disputas de la FIFA que incluye el artículo 22(b) que aclara que en relación a las disputas relacionadas con contratos de empleo entre clubes y jugadores extranjeros, las partes pueden incluir expresamente una cláusula en el contrato aclarando que cualquier disputa puede ser resuelta por la Cámara de Resolución de Disputas del país en cuestión, en vez de la Cámara de Resolución de Disputas de la FIFA.
Para que dicha cláusula sea efectiva y válida es necesario que el tribunal de resoluciones local sea independiente y garantice procedimientos justos y donde estén igualmente representados tantos los jugadores como los clubes. ¿Podemos decir que en Argentina contamos con un tribunal que cumpla con dichas exigencias y que pueda asumir la resolución de dichas contiendas?
Sin embargo la modificación más relevante introducida por dicha Circular pasa es el nuevo agregado Artículo 12 bis del Reglamento sobre Estatuto y Transferencia de Jugadores, respecto a aquellas deudas impagas que tenga un club por más de 30 días sin una razón contractual que lo justifique. Lo que generará la aplicación de diferentes tipos de sanciones que puede llegar a la inhibición para transferir jugadores durante dos períodos de registración. Las deudas alcanzadas, en principio, estarían vinculadas con obligaciones financieras respecto a clubes y jugadores y que estén estipuladas en contratos de jugadores o acuerdos de transferencia. Aunque se pueden extender al supuesto de derechos de imagen, pagos correspondientes a mecanismos de solidaridad y formación, premios por puntos o campeonatos, siempre que dichos conceptos se encuentren incluidos en los contratos. Para hacer efectiva este derechos los jugadores deben intimar al club mediante notificación fehaciente otorgando un plazo de 10 días para su subsanación. Es decir el día 31 de mora enviar carta al club y el 41 informar de la situación a la FIFA.
Esta situación viene a mejorar la situación actual de los jugadores que en la actualidad práctica para rescindir el contrato deben tener acreencias de por lo menos tres meses de salarios.
La relevancia de las modificaciones enunciadas, no sólo es por tratar una temática interesante para considerar en la redacción de los contratos, sino por ya encontrarse vigente desde el primer día de este mes de marzo.
Circular 1468 de la FIFA anunciando los cambios a las regulaciones de FIFA sobre Estatuto y Transferencia de Jugadores y procedimiento de resolución de disputas.
miércoles, 18 de marzo de 2015
domingo, 8 de marzo de 2015
Dos resoluciones relevantes de la Dirección Nacional de Datos Personales. Una sobre recaudos para videovigilancia y otra actualizando sanciones por diferentes tipo de faltas a la Ley de PDP.
miércoles, 4 de marzo de 2015
En Estados Unidos y Europa las fusiones pueden ser motivo de objeción por los entes reguladores en caso que se vea afectada la privacidad de los consumidores con motivo de la referida fusión. En virtud de lo cual en todas las auditorías legales se deberá empezar a considerar el análisis de las políticas de privacidad utilizadas por las target companies.
FTC merger review likely to incorporate analysis of privacy issues
Source: Lexology practical knowledge
The Federal Trade Commission (FTC or the Commission), along with the U.S. Department of Justice, can challenge mergers it believes will result in a substantial lessening of competition – for example through higher prices, lower quality or reduced rates of innovation.
Although the analysis of whether a transaction may be anticompetitive typically focuses on price, privacy is increasingly regarded as a kind of non-price competition, like quality or innovation. During a recent symposium on the parameters and enforcement reach of Section 5 of the FTC Act, Deborah Feinstein, the director of the FTC’s Bureau of Competition, noted that privacy concerns are becoming more important in the agency’s merger reviews. Specifically she stated, “Privacy could be a form of non-price competition important to customers that could be actionable if two kinds of companies competed on privacy commitments on technologies they came up with.”
At this same symposium, Jessica Rich, director of the FTC’s Bureau of Consumer Protection, remarked on the agency’s increasing expectations that companies protect the consumer data they collect and be more transparent about what they collect, how they store and protect it, and about third parties with whom they share the data.
The FTC’s Bureaus of Competition and Consumer Protection fulfill the agency’s dual mission to promote competition and protect consumers, in part, through the enforcement of Section 5 of the FTC Act. With two areas of expertise and a supporting Bureau of Economics under one roof, the Commission is uniquely positioned to analyze whether a potential merger may substantially lessen privacy-related competition.
The concept that privacy is a form of non-price competition is not new to the FTC. In its 2007 statement upon closing its investigation into the merger of Google, Inc. and DoubleClick Inc., the Commission recognized that mergers can “adversely affect non-price attributes of competition, such as consumer privacy.” Commissioner Pamela Jones Harbour’s dissent in the Google/DoubleClick matter outlined a number of forward-looking competition and privacy-related considerations for analyzing mergers of data-rich companies. The FTC ultimately concluded that the evidence in that case “did not support the theories of potential competitive harm” and thus declined to challenge the deal. The matter laid the groundwork, however, for the agency’s future consideration of these issues.
While the FTC has yet to challenge a transaction on the basis that privacy competition would be substantially lessened, parties can expect staff from both the Bureau of Competition and the Bureau of Consumer Protection to be working closely together to analyze a proposed transaction’s impact on privacy. The FTC’s review of mergers between entities with large databases of consumer information may focus on: (1) whether the transaction will result in decreased privacy protections,i.e., lower quality of privacy; and (2) whether the combined parties achieve market power as a result of combining their consumer data.
This concept is not unique to the United States. The European Commission’s 2008 decision in TomTom/Tele Atlasexamined whether there would be a decrease in privacy-based competition by investigating whether the combination of the portable navigation device manufacturers would enable a dominant player to offer less privacy protections without fearing a loss of business. More recently, the European Data Protection Supervisor issued a preliminary opinion entitled Privacy and Competitiveness in the Age of Big Data (March 26, 2014) with the goal of initiating a dialogue between experts and practitioners on potential gaps in EU competition, consumer protection and data protection policies.
With former and current FTC commissioners advocating for the inclusion of privacy considerations in merger investigations, Feinstein’s recent remarks, and the European Data Protection Supervisor offering similar views, companies in data-rich industries who are considering merging with or acquiring a competitor should expect privacy to play a prominent role in the antitrust review of their proposed transaction. For proposed transactions that implicate combinations of large databases of consumer information, the parties’ chief privacy officers will likely play an unprecedented role in the antitrust defense of the transaction, and parties should expect inquiry into how the merger might affect consumer privacy post-transaction and how the data will be maintained, protected and used. If privacy concerns are likely to arise, parties can prepare in advance as part of their overall antitrust defense. For example:
- Companies, through their counsel, should undertake due diligence of the target’s privacy practices, as well as its statements to consumers, including privacy policies– not only their current state, but how they have changed over time in response to competitive pressures;
- Antitrust counsel should interview personnel and review the parties’ own internal ordinary course documents to understand how each has responded in the marketplace to privacy-based competition;
- Merging companies may want to consider engaging economic consultants to assess the transaction’s potential competitive impact on privacy or consider efficiencies arguments that might help mitigate competitive concerns;
- Companies should consider in advance how the combined entity will address consumer privacy post-transaction – and whether they can preempt FTC concerns through certain commitments such as consumer opt-outs or maintaining the quality of their privacy protection
Suscribirse a:
Entradas (Atom)