Data protection in Botswana

Author(s):  
Tumelo Keakopa ◽  
Olefhile Mosweu

Data protection legislation is concerned with the safeguarding of privacy rights of individuals in relation to the processing of personal data, regardless of media or format. The Government of Botswana enacted the Data Protection Act in 2018 for purposes of regulating personal data and to ensure the protection of individual privacy as it relates to personal data, and its maintenance. This paper investigates opportunities and challenges for records management, and recommends measures to be put in place in support of data protection, through proper records management practices. The study employed a desktop approach and data was collected using content analysis. The study found that opportunities such as improved retrieval and access to information, improved job opportunities for records management professionals and a conducive legislative framework are available. It also revealed that a lack of resources to drive the records management function, limitations in electronic document and records systems and a lack of freedom of information to regulate access to public information by members of the public is still a challenge. The study recommends the employment of qualified records management staff with capacity to manage records in the networked environment for purposes of designing and implementing records management programmes that can facilitate compliance with the requirements prescribed by the Data Protection Act.

2021 ◽  
Vol 14 (2) ◽  
pp. 139-148
Author(s):  
Mriya Afifah Furqania ◽  
Tomy Michael

This study aims to analyze the Indonesian laws and regulations concerning the protection of intimate video makers. The research was conducted by analyzing the Pornography Law, the Information and Electronic Transaction Law, the Government Regulation on the Implementation of Electronic Transaction Systems, and the Regulation of the Minister of Information Communication on Personal Data Protection. This research found that data/documents that are made for oneself and for their own interests which are not prohibited by law and included to one of the privacy rights that must be protected by every human being and by the state. The making of this intimate video is included in the privacy rights to enjoy life and should not be contested. Activities contained in the video can range from holding hands, hugging, kissing to having sex with consent. Therefore, if there are those who oppose rights such as acquisition and distribution without consent, the owner of the personal data can file a lawsuit for damages and have a right to erase their electronic documents.Keywords: intimate video; protection; sexual lawAbstrakPenelitian ini bertujuan untuk menganalisis peraturan perundang-undangan Indonesia yang memuat tentang perlindungan terhadap pembuat video mesra. Penelitian dilakukan dengan menganalisis Undang-Undang Pornografi, Undang-Undang Informasi dan Transaksi Elektronik, Peraturan Pemerintah tentang Penyelenggaraan Sistem Transaksi Elektronik serta Peraturan Menteri Komunikasi dan Informasi tentang Perlindungan Data Pribadi. Penelitian ini menemukan bahwa data/dokumen yang dibuat untuk diri sendiri dan kepentingan sendiri bukanlah hal yang dilarang oleh undang-undang dan justru harus dilindungi baik oleh tiap manusia maupun negara. Pembuatan video mesra ini termasuk dalam hak pribadi untuk menikmati hidup dan tidak boleh diganggu gugat. Aktivitas yang termuat dalam video tersebut bisa dari bergandengan tangan, berpelukan, berciuman hingga berhubungan badan yang dilakukan atas persetujuan. Oleh sebab itu jika terdapat pelanggaran terhadap hak seperti perolehan dan penyebarluasan tanpa persetujuan, pemilik data pribadi dapat mengajukan gugatan kerugian dan mengajukan permohonan untuk menghapus data tersebut.


Jurnal Hukum ◽  
2021 ◽  
Vol 37 (1) ◽  
pp. 1
Author(s):  
Giosita Kumalaratri ◽  
Yunanto Yunanto

The development of information technology in the era of globalization makes it easier for people to carry out their daily activities, apart from socializing, it can also be a channel for work. Behind the simplicity coveted by technological developments opens up loopholes related to personal data that is easily misused. Indonesia does not yet have specific laws governing the protection of personal data as a whole. So that the author will examine the urgency of the draft personal data law in Indonesia, personal data protection schemes, to the impact of the implementation of the personal data protection bill. This study uses a normative juridical research method. The results of the study point to a privacy rights protection scheme in which everyone has the right to publish personal data or the right not to publish personal data to the public. The weakness of personal data protection regulations in Indonesia that have not been specifically regulated increases the potential for crimes against the right to privacy, but the drafting of the Personal Data Protection Bill brings fresh air not only to the public but to the government sector to the international business environment.


2021 ◽  
Vol 5 (2) ◽  
pp. 65-88
Author(s):  
Anugrah Muhtarom Pratama ◽  
Umi Khaerah Pati

This article aims to review the application of the principle of personal data protection as part of privacy rights in the PeduliLindungi application considering that on the one hand, the PeduliLindungi application helps the government to reduce the spread of the COVID-19 virus. But on the other hand, there is a threat of misuse of personal data in the future. This background article is based on the use of the PeduliLindungi application, which was initially used to track the spread of the virus during the COVID-19 pandemic. But it seems that the public will increasingly use its use in the future, especially now that it has begun to be planned as an e-wallet and started integrating with several other applications. This article reveals that there has been a dual role by the Ministry of Communication and Informatics as a supervisor and controller of personal data in Indonesia so that it has implications for the PeduliLindungi application that has not fully applied the principles of personal data protection when collecting, processing, and storing personal data. For the future, a comprehensive legal development drive is needed related to the protection of personal data. There is a personal data protection agency and Data Protection Officer (DPO) to more strongly enforce the principles of personal data protection.


2017 ◽  
Vol 2017 (1) ◽  
pp. 35-44
Author(s):  
Dawid Zadura

Abstract In the review below the author presents a general overview of the selected contemporary legal issues related to the present growth of the aviation industry and the development of aviation technologies. The review is focused on the questions at the intersection of aviation law and personal data protection law. Massive processing of passenger data (Passenger Name Record, PNR) in IT systems is a daily activity for the contemporary aviation industry. Simultaneously, since the mid- 1990s we can observe the rapid growth of personal data protection law as a very new branch of the law. The importance of this new branch of the law for the aviation industry is however still questionable and unclear. This article includes the summary of the author’s own research conducted between 2011 and 2017, in particular his audits in LOT Polish Airlines (June 2011-April 2013) and Lublin Airport (July - September 2013) and the author’s analyses of public information shared by International Civil Aviation Organization (ICAO), International Air Transport Association (IATA), Association of European Airlines (AEA), Civil Aviation Authority (ULC) and (GIODO). The purpose of the author’s research was to determine the applicability of the implementation of technical and organizational measures established by personal data protection law in aviation industry entities.


2021 ◽  
Vol 7 (1) ◽  
Author(s):  
Iwona Karasek-Wojciechowicz

AbstractThis article is an attempt to reconcile the requirements of the EU General Data Protection Regulation (GDPR) and anti-money laundering and combat terrorist financing (AML/CFT) instruments used in permissionless ecosystems based on distributed ledger technology (DLT). Usually, analysis is focused only on one of these regulations. Covering by this research the interplay between both regulations reveals their incoherencies in relation to permissionless DLT. The GDPR requirements force permissionless blockchain communities to use anonymization or, at the very least, strong pseudonymization technologies to ensure compliance of data processing with the GDPR. At the same time, instruments of global AML/CFT policy that are presently being implemented in many countries following the recommendations of the Financial Action Task Force, counteract the anonymity-enhanced technologies built into blockchain protocols. Solutions suggested in this article aim to induce the shaping of permissionless DLT-based networks in ways that at the same time would secure the protection of personal data according to the GDPR rules, while also addressing the money laundering and terrorist financing risks created by transactions in anonymous blockchain spaces or those with strong pseudonyms. Searching for new policy instruments is necessary to ensure that governments do not combat the development of all privacy-blockchains so as to enable a high level of privacy protection and GDPR-compliant data processing. This article indicates two AML/CFT tools which may be helpful for shaping privacy-blockchains that can enable the feasibility of such tools. The first tool is exceptional government access to transactional data written on non-transparent ledgers, obfuscated by advanced anonymization cryptography. The tool should be optional for networks as long as another effective AML/CFT measures are accessible for the intermediaries or for the government in relation to a given network. If these other measures are not available and the network does not grant exceptional access, the regulations should allow governments to combat the development of those networks. Effective tools in that scope should target the value of privacy-cryptocurrency, not its users. Such tools could include, as a tool of last resort, state attacks which would undermine the trust of the community in a specific network.


Hypertension ◽  
2021 ◽  
Vol 77 (4) ◽  
pp. 1029-1035
Author(s):  
Antonia Vlahou ◽  
Dara Hallinan ◽  
Rolf Apweiler ◽  
Angel Argiles ◽  
Joachim Beige ◽  
...  

The General Data Protection Regulation (GDPR) became binding law in the European Union Member States in 2018, as a step toward harmonizing personal data protection legislation in the European Union. The Regulation governs almost all types of personal data processing, hence, also, those pertaining to biomedical research. The purpose of this article is to highlight the main practical issues related to data and biological sample sharing that biomedical researchers face regularly, and to specify how these are addressed in the context of GDPR, after consulting with ethics/legal experts. We identify areas in which clarifications of the GDPR are needed, particularly those related to consent requirements by study participants. Amendments should target the following: (1) restricting exceptions based on national laws and increasing harmonization, (2) confirming the concept of broad consent, and (3) defining a roadmap for secondary use of data. These changes will be achieved by acknowledged learned societies in the field taking the lead in preparing a document giving guidance for the optimal interpretation of the GDPR, which will be finalized following a period of commenting by a broad multistakeholder audience. In parallel, promoting engagement and education of the public in the relevant issues (such as different consent types or residual risk for re-identification), on both local/national and international levels, is considered critical for advancement. We hope that this article will open this broad discussion involving all major stakeholders, toward optimizing the GDPR and allowing a harmonized transnational research approach.


This new book provides an article-by-article commentary on the new EU General Data Protection Regulation. Adopted in April 2016 and applicable from May 2018, the GDPR is the centrepiece of the recent reform of the EU regulatory framework for protection of personal data. It replaces the 1995 EU Data Protection Directive and has become the most significant piece of data protection legislation anywhere in the world. This book is edited by three leading authorities and written by a team of expert specialists in the field from around the EU and representing different sectors (including academia, the EU institutions, data protection authorities, and the private sector), thus providing a pan-European analysis of the GDPR. It examines each article of the GDPR in sequential order and explains how its provisions work, thus allowing the reader to easily and quickly elucidate the meaning of individual articles. An introductory chapter provides an overview of the background to the GDPR and its place in the greater structure of EU law and human rights law. Account is also taken of closely linked legal instruments, such as the Directive on Data Protection and Law Enforcement that was adopted concurrently with the GDPR, and of the ongoing work on the proposed new E-Privacy Regulation.


2019 ◽  
Author(s):  
Anya Skatova ◽  
Rebecca Louise McDonald ◽  
Sinong Ma ◽  
Carsten Maple

Data is key for the digital economy, underpinning business models and service provision, and a lot of these valuable datasets are personal in nature. Information about individual behaviour is collected regularly by organisations. This information has value to businesses, the government and third parties. It is not clear what value this personal data has to consumers themselves. Much of the digital economy is predicated on people sharing personal data, however if individuals value their privacy, they may choose to withhold this data unless the perceived benefits of sharing outweigh the perceived value of keeping the data private. Further, they might be willing to pay for an otherwise free service if paying allowed them to avoid sharing personal data. We used five evaluation techniques to study preferences for protecting personal data online and found that consumers assign a positive value to keeping a variety of types of personal data private. We show that participants are prepared to pay different amounts to protect different types of data, suggesting there is no simple function to assign monetary value that can be identified for individual privacy in the digital economy. The majority of participants displayed remarkable consistency in their rankings of the importance of different types of data, a finding that indicates the existence of stable individual privacy preferences in protecting personal data. We discuss our findings in the context of research on the value of privacy and privacy preferences, and in terms of implications for future business models and consumer protection.


Author(s):  
Yola Georgiadou ◽  
Rolf de By ◽  
Ourania Kounadi

The General Data Protection Regulation (GDPR) protects the personal data of natural persons and at the same time allows the free movement of such data within the European Union (EU). Hailed as majestic by admirers and dismissed as protectionist by critics, the Regulation is expected to have a profound impact around the world, including in the African Union (AU). For European–African consortia conducting research that may affect the privacy of African citizens, the question is ‘how to protect personal data of data subjects while at the same time ensuring a just distribution of the benefits of a global digital ecosystem?’ We use location privacy as a point of departure, because information about an individual’s location is different from other kinds of personally identifiable information. We analyse privacy at two levels, individual and cultural. Our perspective is interdisciplinary: we draw from computer science to describe three scenarios of transformation of volunteered/observed information to inferred information about a natural person and from cultural theory to distinguish four privacy cultures emerging within the EU in the wake of GDPR. We highlight recent data protection legislation in the AU and discuss factors that may accelerate or inhibit the alignment of data protection legislation in the AU with the GDPR.


Author(s):  
Agnese Reine-Vītiņa

Mūsdienās tiesības uz privāto dzīvi nepieciešamas ikvienā demokrātiskā sabiedrībā, un šo tiesību iekļaušana konstitūcijā juridiski garantē fiziskas personas rīcības brīvību un vienlaikus arī citu – valsts pamatlikumā noteikto – cilvēka tiesību īstenošanu [5]. Personas datu aizsardzības institūts tika izveidots, izpratnes par tiesību uz personas privātās dzīves neaizskaramību saturu paplašinot 20. gadsimta 70. gados, kad vairāku Eiropas valstu valdības uzsāka informācijas apstrādes projektus, piemēram, tautas skaitīšanu u. c. Informācijas tehnoloģiju attīstība ļāva arvien vairāk informācijas par personām glabāt un apstrādāt elektroniski. Viena no tiesību problēmām bija informācijas vākšana par fizisku personu un tiesību uz privātās dzīves neaizskaramību ievērošana. Lai nodrošinātu privātās dzīves aizsardzību, atsevišķas Eiropas valstis pēc savas iniciatīvas pieņēma likumus par datu aizsardzību. Pirmie likumi par personas datu aizsardzību Eiropā tika pieņemti Vācijas Federatīvajā Republikā, tad Zviedrijā (1973), Norvēģijā (1978) un citur [8, 10]. Ne visas valstis pieņēma likumus par datu aizsardzību vienlaikus, tāpēc Eiropas Padome nolēma izstrādāt konvenciju, lai unificētu datu aizsardzības noteikumus un principus. Nowadays, the right to privacy is indispensable in every democratic society and inclusion of such rights in the constitution, guarantees legally freedom of action of a natural person and, simultaneously, implementation of other human rights established in the fundamental law of the state. The institute of personal data protection was established by expanding the understanding of the content of the right to privacy in the 70’s of the 19th century, when the government of several European countries initiated information processing projects, such as population census etc. For the development of information technology, more and more information on persons was kept and processed in electronic form. One of the legal problems was gathering of information on natural persons and the right to privacy. In order to ensure the protection of privacy, separate European countries, on their own initiative, established a law on data protection. The first laws on the protection of personal data in Europe were established in the Federal Republic of Germany, then in Sweden (1973), Norway (1978) and elsewhere. Not all countries adopted laws on data protection at the same time, so the Council of Europe decided to elaborate a convention to unify data protection rules and principles.


Sign in / Sign up

Export Citation Format

Share Document