of individuals residing in the EU, regardless of the company’s location. • Data Protection Officers: In some circumstances data controllers or processors must designate a Data Protection Officer as part of their accountability programme. This covers processing carried out by a public authority, where core activities are involved, monitoring data subjects on a large scale; and where core activities consist of processing on a large scale of special categories of data. • Consent: Restrictive approach to consent requiring that it must be “freely given, specific, informed and unambiguous.” • Penalties: A tiered approach to penalties is established with fines for some infringements of up to the higher of 4% of annual worldwide turnover and EUR20 million (e.g. breach of requirements relating to international transfers or the basic principles for processing, such as conditions for consent). Civil liability is also possible with a right to compensation. • Data breach notification: Data controllers must notify most data breaches to the Data Protection Authorities within 72 hours of awareness. • Data subject rights: Rights of individuals are bolstered including rights to: require information about data being processed about themselves; be forgotten entitling individuals to have personal data about them erased; correction of data which is wrong; a right to restrict certain processing; object to their personal data being processed for direct marketing purposes; and to an explanation about information based on algorithms. The GDPR may impact on New Zealand in two ways. First, any public agency or business in New Zealand that handles personal data of individuals residing in the EU will need to ensure that their internal data processing procedures comply. Second, it is possible that the EU may find that New Zealand’s data protection laws are no longer ‘adequate’ for the transfer of European- originated data for processing.42 The Office of the Privacy Commissioner has indicated that they are in regular communication with the European Commission on this issue.43 Asia-Pacific Region APEC Privacy Framework The APEC Privacy Framework was developed in light of the 1980 OECD Guidelines and applies to all 27-member countries.44 The Framework sets out principles and implementation guidance for the public and private sectors who control the collection, holding, processing, use, transfer or disclosure of personal information. Key principles include: • Preventing harm: Preventing misuse of personal information and consequent harm to individuals. • Notice: Individuals should know that information is collected about them and the purpose for which it is used. • Collection limitation: Limited collection of information to the purposes for which it is collected. • Use limitation: Limits the use of personal information to fulfilling the purposes of the collection. Also included in the framework are the principles of choice and consent, data integrity, security safeguards, access and correction and accountability. Progress on the implementation of the Framework includes the application of Information Privacy Individual Action Plans by 14 economies. New Zealand last updated its Data Privacy Individual Action Plan, in 2011.45 Comprehensive and Progressive Agreement for the Trans-Pacific Partnership Agreement (TPP) 42 Privacy Commissioner, Office of the Privacy Commissioner Briefing for the Incoming Minister of Justice: Hon Andrew Little, October 2017, para 4.14 https://privacy.org.nz/assets/Uploads/Briefing-for-Incoming-Minister-October-2017.pdf Ibid para 4.14. 43 Ibid 44 https://www.apec.org/Publications/2017/08/APEC-Privacy-Framework-(2015) 45 https://www.apec.org/Groups/Committee-on-Trade-and-Investment/ Electronic-Commerce-Steering-Group/Data-Privacy-Individual-Action-Plan.aspx 13

Выберите целевой абзац3