Home -> Law Blog Directory -> International Law Blogs -> The Canadian Privacy Law Blog
(866) 635-2689 for Personal Injury or (866) 635-9402 for Criminal Defense
Find a Local Lawyer
Divorce (866) 635-6190
Personal Injury (866) 635-2689
Criminal Defense (866) 635-9402
International Law
: The Canadian Privacy Law BlogInternational standard for privacy impact assessments
The International Standards Organization has earlier this year established ISO 22307:2008, which is a new international standard for privacy impact assessments. Here is the blurb, but you'll have to shell out 114 Swiss Francs for the real deal:
ISO 22307:2008 - Financial services -- Privacy impact assessmentISO 22307:2008 recognizes that a privacy impact assessment (PIA) is an important financial services and banking management tool to be used within an organization, or by ?contracted? third parties, to identify and mitigate privacy issues and risks associated with processing consumer data using automated, networked information systems.
ISO 22307:2008
- describes the privacy impact assessment activity in general,
- defines the common and required components of a privacy impact assessment, regardless of business systems affecting financial institutions, and
- provides informative guidance to educate the reader on privacy impact assessments.
A privacy compliance audit differs from a privacy impact assessment in that the compliance audit determines an institution's current level of compliance with the law and identifies steps to avoid future non-compliance with the law. While there are similarities between privacy impact assessments and privacy compliance audits in that they use some of the same skills and that they are tools used to avoid breaches of privacy, the primary concern of a compliance audit is simply to meet the requirements of the law, whereas a privacy impact assessment is intended to investigate further in order to identify ways to safeguard privacy optimally.
ISO 22307:2008 recognizes that the choices of financial and banking system development and risk management procedures are business decisions and, as such, the business decision makers need to be informed in order to be able to make informed decisions for their financial institutions. ISO 22307:2008 provides a privacy impact assessment structure (common PIA components, definitions and informative annexes) for institutions handling financial information that wish to use a privacy impact assessment as a tool to plan for, and manage, privacy issues within business systems that they consider to be vulnerable.
Full post as published by The Canadian Privacy Law Blog on June 09, 2008 (boomark / email).
International Privacy Officials Recommend Social Networking Privacy Safeguards
EPIC: "The International Working Group On Data Protection in Telecommunications has released a report and guidance (pdf) on privacy in...
Electronic Privacy Information Center's 2007 International Privacy Ranking
From the Report's overview: Each year since 1997, the US-based Electronic Privacy Information Center and the UK-based Privacy International have undertaken what has now become the most comprehensive survey of global privacy ever published...
It can be rational to sell your private information cheaply, even if you value privacy
One of the standard claims about privacy is that people say they value their privacy but behave as if they don't value it. The standard example involves people trading away private information for something of relatively little value...
Today is data privacy day
According to Sharon E. Herbert’s superb ghosts in the machine blog: January 28th is Data Privacy Day The IAPP (International Association of Privacy Professionals) has declared January 28, 2008 “Data Privacy Day”, in an effort to encourage privacy professionals to give presentations at schools, colleges and universities next week on the importance of privacy...
Globalization and International Law
The paper argues that globalization has had a significant impact on international law but that, in turn, international law could have a significant impact on globalization.
Politics and Privacy in the UK
Norman Fowler writes about the double standard with regard to privacy when it comes to political figures here in today's Guardian.
Privacy Protection Act 42 USC 21A
Federal Newsroom Law
Dumb Foreign Laws
Stupid Laws of Other Countries
Landlord Entry Right and Tenant Privacy
When can a landlord enter a rented dwelling
Mirrors
Recalled Due to Impact and Laceration Hazards
Google Sued for Violating the Privacy Rights of Millions of Americans
Google Sued for Violating the Privacy Rights of Millions of Americans
AOL Privacy Class Action
Can Proceed
CVS Mailing
Sparks Allegations of Privacy Violation
imbee Data Collection
Industrious Kid, Inc. pays $130,000 civil penalty for violating the Children’s Online Privacy Protection Act.
AT&T International Roaming Charges, AT&T lawsuit
AT&T Faces International Roaming Charges Lawsuit










