15
1 Symposium Interpreting Privacy Principles: Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

Symposium Interpreting Privacy Principles: Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

  • Upload
    agatha

  • View
    26

  • Download
    1

Embed Size (px)

DESCRIPTION

Symposium Interpreting Privacy Principles: Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher. Methodology of Investigation. Identify issues Identify ‘cases’ expressly involving the security principle - PowerPoint PPT Presentation

Citation preview

Page 1: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

1

SymposiumInterpreting Privacy Principles:

Chaos or Consistency?17 May 2006, Sydney

Interpreting the Security Principle

Nigel Waters, Principal Researcher

Page 2: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

2

Methodology of Investigation

• Identify issues• Identify ‘cases’ expressly involving the

security principle • Primary source - WorldLII Privacy Law

Project

Page 3: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

3

Page 4: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

4

Methodology of Investigation• Search for relevant material• Iterative process • Will review all published cases• Initial focus on information privacy laws • Progressively extension to other relevant

laws

Page 5: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

5

… Unauthorised Use of p.i. … Unauthorised Disclosure of p.i. …

… Loss or corruption of p.i.

Security measures are designed to mitigate the RISK of …

… by someone with authorised accessi.e. exceeding their authority

… by an unauthorised third party e.g. by hacking or phishing

MisuseIncluding: Authorised but improper use?

Page 6: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

6

Security Principle - Issues• Reasonableness• Generic Industry standards vs

customised standards for personal information?

• Generic ‘all mode’ vs mode/technology-specific standards

• Human (Personnel) security

Page 7: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

7

Security Principle - Issues• Liability – organisation vs employee vs

contractors• Relationship between security and

disclosure• Carelessness

Page 8: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

8

Page 9: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

9

Page 10: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

10

Page 11: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

11

Page 12: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

12

Page 13: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

13

Page 14: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

14

Page 15: Symposium Interpreting Privacy Principles:  Chaos or Consistency? 17 May 2006, Sydney Interpreting the Security Principle Nigel Waters, Principal Researcher

15