|
|
|
1 Problem Definition, Structure and Methodology |
|
|
3 | (24) |
|
|
4 | (14) |
|
|
4 | (5) |
|
1.1.2 The Modern History of the Right to Privacy |
|
|
9 | (4) |
|
1.1.3 Data Protection as a Tool of "Privacy" |
|
|
13 | (2) |
|
1.1.4 Internationalization and Regionalization |
|
|
15 | (2) |
|
1.1.5 Data Protection and Privacy Is Not Limited to One Area of Law |
|
|
17 | (1) |
|
1.2 Structure and Methodology |
|
|
18 | (2) |
|
1.3 Limitation of this Research |
|
|
20 | (1) |
|
|
20 | (2) |
|
|
22 | (1) |
|
|
23 | (4) |
|
|
|
2 Law, Technology and Digital Economy |
|
|
27 | (18) |
|
|
27 | (13) |
|
2.1.1 Identity in the New World |
|
|
33 | (5) |
|
2.1.2 Co-regulation [ Government and Industry] |
|
|
38 | (2) |
|
|
40 | (1) |
|
|
41 | (4) |
|
|
|
|
45 | (38) |
|
|
46 | (7) |
|
3.2 General Data Protection Regulation |
|
|
53 | (2) |
|
3.3 Definition of Personal Data |
|
|
55 | (3) |
|
3.4 Controller, Processor and Officer |
|
|
58 | (3) |
|
|
59 | (1) |
|
3.4.2 Data Protection Officer |
|
|
60 | (1) |
|
3.5 Right to Be Forgotten |
|
|
61 | (3) |
|
3.6 Agency [ Regulator] - Authority |
|
|
64 | (2) |
|
|
66 | (1) |
|
|
66 | (2) |
|
|
68 | (1) |
|
3.9 Extra-Territorial Reach |
|
|
68 | (1) |
|
|
69 | (1) |
|
3.11 Principles and Codes |
|
|
70 | (3) |
|
3.12 Cross Border Transfer |
|
|
73 | (4) |
|
|
77 | (2) |
|
|
79 | (1) |
|
|
79 | (2) |
|
|
81 | (2) |
|
|
83 | (32) |
|
|
84 | (2) |
|
4.2 Definition Personal Data |
|
|
86 | (4) |
|
|
90 | (1) |
|
|
91 | (1) |
|
4.5 Consent and Collection |
|
|
92 | (5) |
|
|
97 | (1) |
|
|
98 | (1) |
|
4.8 Data Transferred to a Foreign Country |
|
|
99 | (2) |
|
|
101 | (3) |
|
4.9.1 Notification of Breach |
|
|
103 | (1) |
|
4.9.2 Data Protection Impact Assessments |
|
|
103 | (1) |
|
4.10 Extraterritorial - Reach |
|
|
104 | (1) |
|
4.11 Agency [ Regulator], Principles and Codes |
|
|
104 | (2) |
|
4.12 Do Not Call Registry |
|
|
106 | (2) |
|
|
108 | (1) |
|
4.14 Right to Be Forgotten |
|
|
109 | (1) |
|
4.15 Supporting Cyber Security Laws |
|
|
109 | (2) |
|
|
111 | (2) |
|
|
113 | (2) |
|
|
115 | (32) |
|
|
116 | (9) |
|
|
125 | (1) |
|
5.3 Definition of Personal Information |
|
|
125 | (2) |
|
5.4 Consent and Collection |
|
|
127 | (2) |
|
|
129 | (1) |
|
5.5 Extra-Territorial Reach |
|
|
129 | (2) |
|
|
131 | (2) |
|
5.7 Quality of Information - Accuracy |
|
|
133 | (1) |
|
|
134 | (1) |
|
5.9 Breach & Notification |
|
|
135 | (1) |
|
5.10 Right to Be Forgotten |
|
|
136 | (4) |
|
|
140 | (1) |
|
5.12 Loss or Damage and Enforcement |
|
|
141 | (1) |
|
|
142 | (1) |
|
5.14 Additional Legislation and Standards |
|
|
143 | (2) |
|
|
145 | (1) |
|
|
146 | (1) |
|
|
147 | (22) |
|
|
148 | (6) |
|
|
154 | (1) |
|
6.3 Right to Be Forgotten |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
6.6 Consent and Collection |
|
|
157 | (1) |
|
6.7 Cross-Border Transfer |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
159 | (1) |
|
|
160 | (2) |
|
|
162 | (1) |
|
6.11 Controller Functions |
|
|
162 | (1) |
|
6.12 Codes of Practice and Standards |
|
|
163 | (1) |
|
6.13 Proposed New Privacy and Protection Law & Supporting Laws |
|
|
164 | (3) |
|
|
167 | (1) |
|
|
168 | (1) |
|
|
169 | (24) |
|
|
170 | (5) |
|
7.2 Definition of Personal Information |
|
|
175 | (1) |
|
|
176 | (1) |
|
7.4 Controller or Officer |
|
|
176 | (1) |
|
7.5 Commissioner, Agency! Regulator], Principles and Codes |
|
|
177 | (1) |
|
7.6 Cross Border Transfer |
|
|
178 | (1) |
|
7.7 Right to Be Forgotten |
|
|
179 | (1) |
|
|
180 | (1) |
|
|
181 | (1) |
|
|
182 | (1) |
|
|
182 | (1) |
|
|
182 | (1) |
|
7.13 Supporting Laws & Proposed New Data Protection Laws |
|
|
183 | (6) |
|
7.13.1 Proposed New Data Protection Law |
|
|
184 | (5) |
|
|
189 | (2) |
|
|
191 | (2) |
|
|
193 | (24) |
|
|
194 | (5) |
|
8.2 Definitions of Personal Data |
|
|
199 | (1) |
|
|
200 | (4) |
|
8.4 Commissioner-Agency [ Regulator] |
|
|
204 | (2) |
|
|
206 | (1) |
|
8.6 Extra-territorial Reach |
|
|
206 | (1) |
|
8.7 Certificates of Registration |
|
|
207 | (2) |
|
|
209 | (1) |
|
|
209 | (2) |
|
8.10 Breach and Notification |
|
|
211 | (1) |
|
|
211 | (1) |
|
8.12 Right to be Forgotten |
|
|
212 | (1) |
|
|
213 | (1) |
|
8.14 Supporting Cyber Security Laws |
|
|
214 | (1) |
|
|
214 | (1) |
|
|
215 | (2) |
|
|
217 | (22) |
|
|
218 | (5) |
|
|
223 | (1) |
|
|
224 | (1) |
|
|
224 | (1) |
|
9.5 Commission - Agency [ Regulator], Principles, Codes |
|
|
225 | (1) |
|
|
226 | (1) |
|
9.7 Right to Be Forgotten |
|
|
227 | (1) |
|
9.8 Proposed Data Protection Law |
|
|
228 | (7) |
|
9.8.1 Potential Issues Concerning the Current Draft Bill-January 2018 |
|
|
232 | (3) |
|
|
235 | (2) |
|
|
237 | (2) |
|
|
239 | (26) |
|
|
240 | (5) |
|
10.1.1 Personal Data Protection |
|
|
240 | (5) |
|
10.2 Definition of Personal Information |
|
|
245 | (4) |
|
10.3 Business Operator [ Data Controller] |
|
|
249 | (2) |
|
10.4 Extra Territorial Reach |
|
|
251 | (2) |
|
10.5 Right to be Forgotten |
|
|
253 | (1) |
|
10.6 Commissioner - Regulator |
|
|
254 | (2) |
|
|
256 | (1) |
|
|
257 | (1) |
|
10.9 Collection [ Acquisition] and Consent |
|
|
258 | (1) |
|
|
259 | (1) |
|
10.11 Enforcement & Breach |
|
|
260 | (1) |
|
10.12 Supporting Laws and Policy |
|
|
260 | (1) |
|
|
261 | (1) |
|
|
262 | (3) |
|
|
|
11 Jurisdictional [ Comparative] Differences |
|
|
265 | (28) |
|
|
265 | (1) |
|
11.2 The Definition of Personal Data and Personal Information |
|
|
266 | (4) |
|
11.2.1 Sensitive Information [ Data] |
|
|
268 | (2) |
|
11.2.2 Anonymization and Pseudonymization |
|
|
270 | (1) |
|
|
270 | (1) |
|
11.4 Controllers & Enforcement |
|
|
271 | (4) |
|
11.4.1 Notification of Breach |
|
|
272 | (1) |
|
11.4.2 Complaints Mechanism |
|
|
273 | (1) |
|
|
273 | (1) |
|
|
274 | (1) |
|
11.5 Consent & Collection |
|
|
275 | (2) |
|
11.6 Storage & Localisation |
|
|
277 | (2) |
|
11.6.1 Storage Limitation |
|
|
278 | (1) |
|
11.7 International-Transfer |
|
|
279 | (3) |
|
11.7.1 Adequacy Test and Privacy Shield |
|
|
281 | (1) |
|
|
282 | (1) |
|
|
282 | (1) |
|
11.10 Right to Be Forgotten |
|
|
283 | (6) |
|
11.10.1 Adoption of the Right to Be Forgotten |
|
|
288 | (1) |
|
|
289 | (1) |
|
|
290 | (3) |
|
|
|
|
293 | (24) |
|
|
294 | (8) |
|
12.1.1 Internet Systems, Platforms and Infrastructure |
|
|
295 | (3) |
|
12.1.2 Economic Value Personal Data |
|
|
298 | (4) |
|
12.2 Consent & Personal Data |
|
|
302 | (7) |
|
12.2.1 Withdrawal of Consent |
|
|
304 | (1) |
|
12.2.2 Sensitive - Personal Data |
|
|
305 | (4) |
|
|
309 | (1) |
|
|
310 | (1) |
|
|
311 | (2) |
|
|
313 | (1) |
|
|
314 | (3) |
|
13 Competition Law and Personal Data |
|
|
317 | (30) |
|
|
317 | (4) |
|
13.2 Data Protection and Competition |
|
|
321 | (7) |
|
|
328 | (3) |
|
|
331 | (11) |
|
13.4.1 Abuse of Power and the Consumer |
|
|
333 | (2) |
|
|
335 | (1) |
|
13.4.3 Mergers and Acquisitions |
|
|
336 | (4) |
|
|
340 | (2) |
|
|
342 | (3) |
|
|
345 | (2) |
|
14 Conflict of Laws, Transnational Contracts in Personal Data |
|
|
347 | (28) |
|
|
347 | (25) |
|
|
351 | (13) |
|
|
364 | (8) |
|
|
372 | (1) |
|
|
373 | (2) |
|
15 Personal Data and Cybersecurity [ Crime] |
|
|
375 | (26) |
|
|
376 | (19) |
|
|
379 | (2) |
|
15.1.2 Data Protection & Cybersecurity |
|
|
381 | (14) |
|
|
395 | (2) |
|
|
397 | (4) |
|
|
|
16 International & Regional Institutions |
|
|
401 | (22) |
|
|
402 | (1) |
|
16.2 International Law and Regional Programs |
|
|
402 | (1) |
|
|
403 | (2) |
|
16.4 Organization for Economic Development [ OECD] |
|
|
405 | (3) |
|
16.5 International Conference of Data Protection and Privacy Commissioners [ ICDPPC] |
|
|
408 | (1) |
|
16.6 International Law Commission [ ICL] -- Associations and Organizations |
|
|
409 | (1) |
|
16.7 World Economic Forum |
|
|
410 | (1) |
|
|
411 | (3) |
|
16.8.1 Asia-Pacific Economic Cooperation [ APEC] |
|
|
411 | (3) |
|
16.9 Association of South East Nations [ ASEAN] |
|
|
414 | (2) |
|
|
416 | (1) |
|
16.11 Commonwealth of Nations |
|
|
416 | (1) |
|
|
417 | (1) |
|
|
418 | (2) |
|
16.13.1 United States of America (US) and Korean Free Trade Agreement |
|
|
419 | (1) |
|
16.13.2 Proposed Australia and the European Union Free Trade Agreement |
|
|
419 | (1) |
|
16.13.3 Potential Australian and United Kingdom Free Trade Agreement |
|
|
420 | (1) |
|
|
420 | (1) |
|
|
421 | (2) |
|
17 What Is at Issue and A Possible Pathway Forward |
|
|
423 | |
|
|
424 | (1) |
|
17.2 Technology and Regulation |
|
|
425 | (2) |
|
17.3 International & Regional Institutions |
|
|
427 | (1) |
|
17.4 Current Data Protection and Privacy Regulation |
|
|
428 | (1) |
|
17.5 Convergence or Disconnection of Data Protection and Privacy? |
|
|
429 | (1) |
|
|
430 | (1) |
|
|
430 | (2) |
|
|
432 | (1) |
|
|
432 | (1) |
|
17.10 Definition of Personal Data and Personal Information |
|
|
433 | (2) |
|
|
434 | (1) |
|
|
435 | (1) |
|
17.12 Measuring the Harm in Data Breaches |
|
|
436 | (4) |
|
17.12.1 What Is a Privacy Harm? |
|
|
436 | (2) |
|
17.12.2 Penalties & Enforcement |
|
|
438 | (2) |
|
|
440 | (4) |
|
|
444 | (2) |
|
|
446 | |