This Q&A considers the meaning of ‘controller’ and ‘processor’ under the General Data Protection Regulation and the differences between a company director and an employee who handles personal data on behalf of a company.
This Q&A considers whether sending personal data in the EU to a non-EU country comes under data transfer under the GDPR and whether appropriate safeguards are required.
This Q&A considers whether the contractual terms required by Articles 28(3) or 28(4) of the EU GDPR must be governed by the law of an EEA state and whether the contractual terms to be required by Articles 28(3) or 28(4) of the UK GDPR must be governed by a UK law.
This Q&A considers the privacy and data protection implications that may arise from failure to notify affected individuals what information is monitored, recorded and shared.
This Q&A considers whether the correct group entity is under an obligation to reply to a subject access request sent to the wrong group entity under the GDPR.
This Q&A considers data export restrictions under the eighth data protection principle.
If you expected to see yourself on this page, click here.
0330 161 1234