Title: Privacy Protection AuditSeal of Quality Practical Experience
1Privacy Protection Audit/Seal of Quality -
Practical Experience
- Dr. Helmut Bäumler
- Independent Centre for Privacy Protection
- Schleswig-Holstein, Germany
2Privacy Protection Audit/Seal of Quality -
Practical Experience
Reasons for the Establishment of the Privacy
Protection Audit Shortcomings of the previous
Privacy Protection System
-
- ? One-sided focus on legal aspects
-
- ? Too much geared towards Rules and
Prohibitions - ? Lack of incentive for good Privacy Protection
Concepts - ? Customers and Citizens not enough involved
3Privacy Protection Audit/Seal of Quality -
Practical Experience
Reasons for the Establishment of the Privacy
Protection Audit
- ? Privacy Protection makes an arrival at the free
economy - ? Influence on the technical Design
- ? Increased Possibility for Control
- ? Privacy Protection as a winning Model
4Privacy Protection Audit/Seal of Quality -
Practical Experience
Legal Situation in Germany
- ? Federal Data Protection Act
- ? Member States Privacy Protection Acts
- ? Privacy Protection Act of Schleswig-Holstein
- ? Privacy Protection Audit
- ? IT Seal of Quality
5Privacy Protection Audit/Seal of Quality -
Practical Experience
Privacy Protection Audit in Schleswig-Holstein
- ? Legal Situation
- ? Rules
- ? How to execute the Audit
- ? Subject of the Audit
- ? Public Authorities
- ? Parts of Public Authorities
- ? Administrative Proceedings
6Privacy Protection Audit/Seal of Quality -
Practical Experience
Privacy Protection Audit in Schleswig-Holstein
- ? On voluntary Basis
- ? Increasing Personal Responsibility
- ? Using the Audit as an Image und Commercial
factor
7Privacy Protection Audit/Seal of Quality -
Practical Experience
Procedure of the Privacy Protection Audit in
Schleswig-Holstein
- ? Examining the current Privacy Protection
Situation - ? Determination of Privacy Protection Aims
- ? Establishment of a Privacy Protection
Management System - ? Appraisal by the Independent Centre for
Privacy Protection
8Privacy Protection Audit/Seal of Quality -
Practical Experience
Procedure of the Privacy Protection Audit in
Schleswig-Holstein
- ? Awarding with the Audit Seal
- ? First Experience
9Privacy Protection Audit/Seal of Quality -
Practical Experience
IT Seal of Quality in Schleswig-Holstein
- ? Legal Regulation 4 par. 2 Priv.Prot.Act
- ? Further Steps
- ? July 01, 2000 Enactment of the
Priv.Prot.Act - ? April 04, 2001 Quality Seal Decree by the
State Government - ? Nov 05, 2001 Beginning of the Expert
Accreditation Procedure - ? Feb 01, 2002 Publication of the Product
Criteria - ? Feb 01, 2002 Accreditation of the first
Experts
10Privacy Protection Audit/Seal of Quality -
Practical Experience
Course of the Quality Seal Procedure in
Schleswig-Holstein
- ? Product to be certified
- ? Conclusion of an Expert Agreement
- ? Examination and Evaluation of the Product by
the Expert - ? Expert Opinion
- ? The Independent Center for Privacy Protection
checks the Expert Opinion on conclusiveness and
understandability
11Privacy Protection Audit/Seal of Quality -
Practical Experience
? Awarding with the Mark of Quality
12Privacy Protection Audit/Seal of Quality -
Practical Experience
Experts in the Schleswig-Holstein Seal of Quality
Procedure
- ? Competence and Expert Knowledge
- ? Independence
- ? Reliability
- ? List of Experts
- http//www.datenschutzzentrum.de/guetesiegel/
13Privacy Protection Audit/Seal of Quality -
Practical Experience
Criteria for the Schleswig-Holstein Seal of
Quality
- ? No violation of Privacy Protection Laws
- ? Support of Privacy Protection and Data
Security Aims by Means of technical Design - ? Possible organisational Backup Measures are
described in an understandable Way and can be put
into Action with appropriate Effort - ? Easily understandable Documentation
- ? Altogether adequate to the User
14Privacy Protection Audit/Seal of Quality -
Practical Experience
Special Criteria for the Schleswig-Holstein Seal
of Quality
- ? Data Avoidance/Data Austerity
- ? Guarantee for Data Security and Ability to
Revision - ? Guarantee for the Rights of the involved
citizen
15Privacy Protection Audit/Seal of Quality -
Practical Experience
The Schleswig-Holstein Seal of Quality Procedure
- ? Supported by the EU
- ? Results Influence the Federal Legislation
- ? International Congress 2003 in Kiel
16Privacy Protection Audit/Seal of Quality -
Practical Experience
- The Independent Centre for Privacy Protection
- Where? Holstenstraße 98, 24103 Kiel
- Telephone? 0431/988-1200
- Telefax? 0431/988-1223
- E-Mail? mail_at_datenschutzzentrum.de
- Internet? www.datenschutzzentrum.de