Print

Informationssicherheit

Informationssicherheit ist ein maßgebliches Element für den Schutz von Privatsphäre und personenbezogenen Daten. Darüber hinaus müssen die meisten Organisationen damit zurechtkommen, dass ihre Tätigkeiten von einem sich in stetem Wandel befindlichen Umfeld beeinflusst werden. Die durch diesen Wandel bedingten Unsicherheiten wirken sich darauf aus, wie die Organisation reagieren muss, um sicherzustellen, dass ihre Informationswerte angemessen geschützt sind. Infolgedessen benötigen die für die Informationssicherheit zuständigen Mitarbeiter einen spezifischen Rahmen, der sie beim Umgang mit Unsicherheiten unterstützt, die sich im Laufe der Zeit auf die Sicherheit der Daten ihrer Organisation auswirken könnten. Einen solchen Rahmen bietet der Prozess des Informationssicherheits-Risikomanagements.

Es gibt drei allgemein anerkannte Elemente, um Informationen angemessen zu schützen.

  1. Vertraulichkeit: nur befugte Personen haben Zugang zu den Informationen;
  2. Integrität: nur befugte Personen können die Informationen auf korrekte Weise aktualisieren; und
  3. Verfügbarkeit: die Informationen sind bei Bedarf verfügbar.

Filters

7
Dec
2009

Agency for large-scale IT systems

Opinion on the proposal for a Regulation establishing an Agency for the operational management of large-scale IT systems in the area of freedom, security and justice, and on the proposal for a Council Decision conferring upon the Agency tasks regarding the operational management of SIS II and VIS in application of Title VI of the EU Treaty, OJ C 70, 19.03.2010, p.13

22
Jul
2009

Intelligent Transport Systems

Opinion on the Communication from the Commission on an Action Plan for the Deployment of Intelligent Transport Systems in Europe and the accompanying Proposal for a Directive of the European Parliament and of the Council laying down the framework for the deployment of Intelligent Transport Systems in the field of road transport and for interfaces with other transport modes, OJ C 47, 25.02.2010, p. 6

The EDPS has adopted an opinion on the European Commission's proposed deployment plan for intelligent transport systems (ITS) in Europe that was adopted in December 2008 to accelerate and coordinate their deployment in road transport and their connection with other modes of transport. The deployment of ITS  has considerable privacy implications, for instance because these systems make it possible to track a vehicle and to collect a wide variety of data relating to European road users' driving habits.

The EDPS notes that data protection has been taken into consideration in the proposed legal framework and that it is also put forward as a general condition for the proper deployment of ITS. He however underlines that the Commission's proposal is too broad and too general to adequately address the privacy and data protection concerns raised by ITS deployment in the Member States. In particular, it is not clear when the performance of ITS services will lead to the collection and processing of personal data, what are the purposes and modalities for which data processing may take place, or who will be responsible for compliance with data protection obligations.

The EDPS opinion includes the following main recommendations:

  • clarification of responsibilities: it is crucial to clarify the roles of the different actors involved in ITS in order to identify who will bear the responsibility of ensuring that systems work properly from a data protection perspective (who is the data controller?);
  • safeguards for the use of location technologies: appropriate safeguards should be implemented by data controllers providing ITS services so that the use of location technologies is not intrusive from a privacy viewpoint. This should notably require further clarification as to the specific circumstances in which a vehicle will be tracked, strictly limiting the use of location devices to what is necessary for that purpose, and ensuring  that location data are not disclosed to unauthorized recipients;
  • "privacy by design" approach: the EDPS recommends to consider privacy and data protection from an early stage of the design of ITS to define the architecture, operation and management of the systems. Privacy and security requirements should be incorporated within standards, best practices, technical specifications and systems.

Background information
ITS apply information and communication technologies (satellite, computer, telephone, etc.) to transport infrastructure and vehicles with the intention to make transport safer and cleaner and to reduce traffic congestion. ITS applications and services are based on the collection, processing and exchange of a wide variety of data, both from public and private sources, including information on traffic and accidents but also personal data, such as the driving habits and journey patterns of citizens. Their deployment will also rely to a large extent on the use of geolocalisation technologies, such as satellite-positioning and RFID tags. As such, ITS constitute a "data-intensive area" and raise a number of privacy and data protection issues that should be carefully addressed in order to ensure the workability of ITS across Europe.

5
Mar
2009

Organ transplantation

Opinion of 5 March 2009 on the proposal for a directive on standards of quality and safety of human organs intended for transplantation, OJ C192, 15.08.2009, p. 6

COM(2008) 218 of 8.12.2008
Verfügbare Sprachen: Englisch, Französisch
26
Mar
2008

Security features and biometrics in passports

Opinion on the proposal for a Regulation amending Council Regulation (EC) No 2252/2004 on standards for security features and biometrics in passports and travel documents issued by Member States, OJ C 200, 06.08.2008, p. 1

COM(2007) 625 final of 16.10.2007
Verfügbare Sprachen: Englisch, Französisch
16
Feb
2007

European Police Office

Opinion on the proposal for a Council Decision establishing the European Police Office (Europol)(COM(2006) 817 final), OJ C 255, 27.10.2007, p. 13

Verfügbare Sprachen: Bulgarian, Czech, Danish, Deutsch, Estonian, Greek, Englisch, Spanish, Französisch, Italian, Latvian, Lithuanian, Hungarian, Maltese, Dutch, Polish, Portuguese, Romanian, Slovak, Slovenian, Finnish, Swedish
COM(2006) 817 final of 20.12.2006
Verfügbare Sprachen: Englisch, Französisch