Get a good background to data protection law and view practical guidance focused on data protection matters for commercial transactions. See also our UK GDPR compliant pro-party clauses for use in commercial agreements.
Protect trade secrets and know-how using the law of confidentiality. Get information and a set of pro-party confidentiality agreements here.
View a range of trackers to enable horizon scanning and monitoring of key developments. The trackers are maintained - making them useful for keeping up-to-date and for business development.
It’s our online practical guidance product for contentious and non-contentious lawyers dealing with Data Protection, Confidential Information, Privacy, Cybersecurity and Freedom of Information issues.
The European Data Protection Supervisor (EDPS) has published an Opinion on the European Commission’s Proposal for a Regulation establishing a common...
Welcome to this week’s edition of the Information Law weekly highlights: a hand-picked summary of news analysis, updates and new content related to...
The Data Protection Commission (DPC) has engaged extensively with technology companies regarding the use of personal data to train large language...
Law360, London: The government's bid to crack down on ransomware payments could heap pressure on companies in crisis without any guarantee that it...
The European Data Protection Board (EDPB) has published details regarding the Italian Supervisory Authority’s decision to impose an administrative...
Exemptions to the DPA 1998 [Archived]ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May 2018 and...
Notice obligations under the DPA 1998 [Archived]ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May...
Applicability and scope of the DPA 1998 [Archived]ARCHIVED: This archived Practice Note provides information on the data protection regime before 25...
How to incorporate C2P/P2P data protection provisions into commercial contractsThis Practice Note is a guide explaining ‘how to’ incorporate precedent...
Subject access requests under the DPA 1998 [Archived]Sections 7 and 8 of the Data Protection Act 1998 (DPA 1998) set out a data subject’s right of...
Policy—bring your own device (BYOD)This material considers the UK GDPR regime, and legislative links are to Assimilated Regulation (EU) 2016/679, UK...
Hardship clauseHardship•means[, subject to clause [1.6 OR 1.7],] a [fundamental OR material] change in the balance of a party’s benefits and...
Personal data sub-processing schedule—pro-supplier—UK GDPR and EU GDPRThis precedent is for use between a processor and sub-processor. It assumes the...
Personal data sub-processing schedule—pro-customer—UK GDPR and EU GDPRThis precedent is for use between a processor and sub-processor and assumes the...
Personal data processing schedule—short form—pro-controllerThis Precedent is drafted in contemplation of arrangements where the parties wish to insert...
The UK General Data Protection Regulation (UK GDPR)—NavigatorThis Practice Note serves as a reference guide to the Retained Regulation (EU) 2016/679...
Managing a breach of confidentiality or information securityMany companies and government bodies (such as HMRC) have been exposed to loss of...
The Information Commissioner’s Office (ICO)The Information Commissioner’s Office (ICO) is the UK’s independent regulator designed to uphold...
Privacy law—misuse of private informationThe tort of misuse of private information is focused on ‘the protection of human autonomy and dignity—the...
Data protection, privacy and confidential information case law trackerThis Practice Note tracks noteworthy High Court, Court of Appeal and Supreme...
Introduction to the EU GDPR and UK GDPRThis Practice Note provides a high-level introduction to the EU’s General Data Protection Regulation,...
Key definitions under data protection lawThis Practice Note provides further guidance on key definitions used in the EU’s General Data Protection...
UK GDPR—extra-territorial reachThis Practice Note discusses the territorial scope of the regime established by the United Kingdom General Data...
Letter of claim—breach of confidence[Insert name and address of recipient]Dear [insert organisation name],[Name of client] and confidential...
Confidential information, privacy and injunctionsThis Practice Note deals with the general principles of obtaining an injunction relating to...
What does IP completion day mean for Information Law? [Archived]ARCHIVED: This Practice Note has been archived and is not maintained.11 pm (GMT) on 31...
The UK General Data Protection Regulation (UK GDPR)This Practice Note provides a summary of the UK GDPR regime. For a higher-level introduction to UK...
Trade secrets and confidential information—protection and enforcementThis Practice Note sets out the protection available for trade secrets and...
The EU NIS Directive and UK NIS Regulations—timelineThis timeline sets out key dates and information relating to:•the EU’s Network and Information...
Under the EU GDPR or UK GDPR, generally defined as the natural or legal person, authority'>public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Legislation specifies the controller in certain limited situations.
“registrable estate or charge” means the legal estate and any charge which is sought to be registered as a registered estate or registered charge in an application for first registration,
to halt proceedings, apart from taking any steps allowed by the Rules or the terms of the stay—proceedings may be continued if a stay is lifted;