<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where are we with GDPR Criminal penalties (including imprisonement)? in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4118#M147</link>
    <description>&lt;P&gt;If that is the case, there&amp;nbsp;are also Malaysia, South Korea, Philippines...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, China may surprise everyone in terms of criminal penalties including imprisonment&amp;nbsp;for those listed activities even though they do not have a law specific&amp;nbsp;to data protection/privacy like the GDPR.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2017 23:42:00 GMT</pubDate>
    <dc:creator>flyingboy</dc:creator>
    <dc:date>2017-12-04T23:42:00Z</dc:date>
    <item>
      <title>Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4089#M137</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I have seen this only in Germany:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Imprisonment or a fine for &lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;unlawful transfer / making accessible of non-publicly accessible personal data of a large number of individuals for commercial purposes; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;unlawful processing of non-publicly accessible personal data if done for money or with the intent of obtaining for himself or a third person enrichment or damaging another person; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;fraudulent obtaining of non-publicly accessible personal data if done for money or with the intent of obtaining for himself or a third person enrichment or damaging another person (personal offences based on responsibility).&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Do you know any other one?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:22:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4089#M137</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2023-10-09T08:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4096#M140</link>
      <description>&lt;P&gt;The main focus of GDPR is to encourage organisations to&amp;nbsp;have good hygiene data protection practices. The emphasis&amp;nbsp;is on the legal liability of data controllers and processors&amp;nbsp;where Article 83 and 84 advocate administrative fines. I believe Germany has taken extraordinary steps where personal liabilities (eg. imprisonment)&amp;nbsp;may implicate DPOs too and&amp;nbsp;discourage anyone&amp;nbsp;willing to step forward to assist their organisation in compliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have seen punishments like imprisonment&amp;nbsp;for the&amp;nbsp;listed illicit activities in other laws such as Computer Misuse Act, Cybersecurity Law.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 13:11:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4096#M140</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-12-04T13:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4100#M143</link>
      <description>&lt;P&gt;Hi Yves,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Denmark we are still debating if public authorities should be able to receive administrative fine. Very depressing....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Michael&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 14:28:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4100#M143</guid>
      <dc:creator>Tekmic</dc:creator>
      <dc:date>2017-12-04T14:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4105#M144</link>
      <description>&lt;P&gt;It's not in the EU, but here in Singapore the Personal Data Protection Act(PDPA) has got some teeth in the form of a catch all on inspection:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;General Offences and Penalties&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;It is an offence under section 51(3)(b) and (c) of the PDPA to:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;obstruct or impede the PDPC, its inspectors or other authorised officers in the exercise of their powers or performance of their duties under the PDPA; or&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;knowingly or recklessly make a false statement to the PDPC, or knowingly mislead or attempts to mislead the PDPC, in the course of the performance of the duties or powers of the PDPC under the PDPA.&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;An organisation or person that commits an offence under section 51(3)(b) or (c) of the&amp;nbsp;PDPA is liable to:&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;in the case of an individual, to a fine not exceeding $10,000 or to imprisonment for a term not exceeding 12 months or to both; and&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;EM&gt;in any other case, to a fine not exceeding $100,000.&lt;/EM&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also as you might expect there are some pretty far reaching powers of investigation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.pdpc.gov.sg/organisations/enforcement-matters/personal-data-protection-breaches" target="_blank"&gt;https://www.pdpc.gov.sg/organisations/enforcement-matters/personal-data-protection-breaches&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 16:46:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4105#M144</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-12-04T16:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4118#M147</link>
      <description>&lt;P&gt;If that is the case, there&amp;nbsp;are also Malaysia, South Korea, Philippines...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, China may surprise everyone in terms of criminal penalties including imprisonment&amp;nbsp;for those listed activities even though they do not have a law specific&amp;nbsp;to data protection/privacy like the GDPR.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 23:42:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4118#M147</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-12-04T23:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Where are we with GDPR Criminal penalties (including imprisonement)?</title>
      <link>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4119#M148</link>
      <description>&lt;P&gt;Yes, the more 'Authoritarian' the country is perceived&amp;nbsp;to be the higher likelihood there are criminal penalties covering actions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chinese Cyber Security Law covers privacy in the PRC, it's just that it's amalgamated with Critical Information Infrastructure protection(bits of it do read as an homage to GDPR).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Article 63 does actually cover 5-15 days of detention as well as fines for breach of article 27,and you could stretch the 'stealing of online data' and map that to privacy information and that seems to me to be a criminal sanction.&lt;/P&gt;&lt;DIV class="page"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://assets.kpmg.com/content/dam/kpmg/cn/pdf/en/2017/02/overview-of-cybersecurity-law.pdf" target="_self"&gt;https://assets.kpmg.com/content/dam/kpmg/cn/pdf/en/2017/02/overview-of-cybersecurity-law.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 02:56:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Where-are-we-with-GDPR-Criminal-penalties-including/m-p/4119#M148</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-12-05T02:56:26Z</dc:date>
    </item>
  </channel>
</rss>

