Odpri menu

Moderna arhivistika 2019, 2 (1) str./pp. 57-66

mag. Marko POTOKAR
Fakulteta za informacijske študije, Novo mesto, Slovenija
Danilo BURNAČ, Sanja ANDROIĆ, dr. Milka PUNGARTNIK
Mariborski vodovod, j. p., Maribor, Slovenija

Splošna uredba o varstvu podatkov in  uporaba videonadzora za varovanje kritične infrastrukture
General Data Protection Regulation and Use of Video Surveillance to Protect Critical Infrastructure

(Moderna arhivistika 2019, 2 (1), str/pp. 57-66)

https://doi.org/10.54356/MA/2019/DYTF4809

Izvleček:
S 25. majem 2018 je v veljavo stopila nova evropska uredba o varstvu osebnih podatkov (Splošna uredba o varstvu podatkov, angl.: GDPR), ki dviguje nivo varovanja zasebnosti posameznikov in hkrati bolj zavezuje upravljavce in obdelovalce osebnih podatkov. Upravljavci bodo dolžni poskrbeti za strožje varnostne kontrole pred in med obdelavo osebnih podatkov. Zadostiti bodo morali načelu vgrajenega in privzetega varstva osebnih podatkov. Dodano je tudi načelo odgovornosti, ki od upravljavcev osebnih podatkov zraven ustreznega zavarovanja terja tudi zmožnost dokazovanja skladnosti s Splošno uredbo. Upravljavci bodo morali preveriti ustreznost že pridobljenih privolitev in razmisliti o morebitni določitvi pooblaščene osebe za varovanje osebnih podatkov. Novost so tudi določila Splošne uredbe, ki od obdelovalcev zahtevajo višji standard pri obdelavi osebnih podatkov. Tudi ti bodo po novem dolžni voditi evidenco obdelav, zagotoviti bodo morali zadostna jamstva za tehnične in organizacijske ukrepe, v primeru zaposlitve dodatnih obdelovalcev pa bodo morali pridobiti soglasje upravljavca. Enake pa zaenkrat ostajajo določbe področnih ureditev, med drugim tudi videonadzora, v kolikor niso v nasprotju s katero od določb Splošne uredbe.
V prispevku bomo na primeru podjetja Mariborski vodovod prikazali, kako vzpostaviti zakonsko skladen videonadzor vodooskrbnih objektov in naprav, ki so eden izmed bistvenih delov kritične infrastrukture. Podjetje je največji enovit vodooskrbni sistem ter regionalni vodovod v Sloveniji in z izvajanjem javne službe distribucije vode predstavlja enega izmed najpomembnejših deležnikov kritične infrastrukture.

Ključne besede:
Splošna uredba o varstvu podatkov, videonadzor, kritična infrastruktura, varovanje, upravljavci, obdelovalci

 

Abstract:
General Data Protection Regulation and Use of Video Surveillance to Protect Critical Infrastructure
On 25 May 2018, a new European regulation on the protection of personal data (the General Data Protection Regulation (GDPR)), which raises the level of protection of individuals' privacy came into force. GDPR is more binding on the controllers and processors of personal data. Controllers will be obliged to provide stricter security controls before and when processing personal data. They will have to satisfy the principle of embedded and default protection of personal data. The principle of liability is also added, which also requires, among eligible data controllers, the appropriate insurance, the ability to demonstrate compliance with the General Regulation. Controllers will have to verify the appropriateness of the consent already obtained and consider the possible identification of an authorized person for the protection of personal data. New features are also the provisions of the General Regulation, which require a higher standard in the processing of personal data from processors. They will also be obliged to keep track of the processing, they will have to provide sufficient guarantees for the provision of technical and organizational measures, and in the case of additional processors, they will need to obtain the consent of the controller. However, for the time being, the provisions of sectoral arrangements remain, including video surveillance, insofar as they do not conflict with any of the provisions of the General Regulation.
In the article we will show how to establish a legally compliant video surveillance of water supply facilities and devices in Mariborski vodovod, which is one of the essential parts of the critical infrastructure. The company is the largest unified water supply system and regional water supplier in Slovenia, and with the implementation of the public water distribution service is one of the most important stakeholders in critical infrastructure.

Key words:
General Data Protection Regulation, Video Surveillance, Critical Infrastructure, Security, Controllers, Processors