Refine By
Clear all filter
About 91354 results for "*"
GLOSSARY
A data controller is any person, partnership or company who determines how and for what purposes personal data are processed. A third party may carry out processing on the controller’s behalf, although the latter remains responsible for the processing.
GLOSSARY
An agreement between a prosecutor and an organisation, approved by court, under which the prosecution of the organisation is deferred provided the organisation agrees to comply with the requirements imposed on it. Only available for certain offences in accordance with Schedule 17 to the Crime and Courts Act 2013.
GLOSSARY
Data Protection Act 1998 (DPA 1998): the UK’s main legislation governing and regulating the use of data referring to identifiable living people. While not specifically implemented to deal with privacy, in practice the DPA 1998 provides a number of fundamental rights and freedoms and methods for individuals to control how information about themselves is used by businesses and public authorities, with any organisation holding and using (or 'processing') personal data obliged to comply with its terms.
GLOSSARY
A data protection impact assessment is a way of assessing and minimising the data protection impacts and risks of a particular project or process. Data protection law requires they are undertaken in many circumstances.
GLOSSARY
An expert (DPO) who assists an organisation with internal compliance, information and advice on data protection obligations and acts as a contact point for data subjects and the supervisory authority. Data protection law requires DPOs to be appointed by certain organisations and to meet certain requirements.
GLOSSARY
Data protection officer; an expert who assists an organisation with internal compliance, information and advice on data protection obligations and acts as a contact point for data subjects and the supervisory authority. Data protection law requires DPOs to be appointed by certain organisations and to meet certain requirements.
NEWS
MLex: The Data Protection and Digital Information Bill has been given more time to ensure it completes its passage through Parliament as lawmakers unanimously agreed the motion on 7 February 2024 to extend it until December. The Bill is likely to be passed much sooner, particularly with the prospect of parliamentary elections later in 2024.
NEWS
The Data Protection and Digital Information Bill was lost in the wash-up period that preceded the prorogation of Parliament on Friday 24 May 2024 and its dissolution on 30 May 2024 for the purposes of the UK general election that will be held on 4 July 2024. Any unfinished business is lost at dissolution. The Bill, first read in the House of Commons on 8 March 2023, would have introduced significant data reform.
PRACTICE NOTES
This Practice Note provides a summary of how the Assimilated Regulation (EU) 2016/679, UK General Data Protection Regulation (UK GDPR) and the Freedom of Information Act 2000 (FIA 2000) regimes apply to the Higher Education Sector, including universities. It assumes the reader is familiar with key concepts under the UK GDPR, including ‘controller’, ‘data subject’, ‘personal data’, ‘processing’ and ‘processor’. For further guidance on those terms, click on the links above to navigate to the relevant section of Practice Note: Key definitions under UK data protection law. For higher-level introductions to data protection laws generally, see Practice Notes: Data protection law—new starter guide and Introduction to the EU GDPR and UK GDPR. The UK data protection law collection collates further general guidance on the UK GDPR regime and is a recommended starting point for data protection research. Data Protection Data Protection Principles The data protection regime in the UK is primarily governed by the UK GDPR and related sections of the Data Protection Act 2018 (DPA 2018). See Practice
PRECEDENTS
1 Data breach team The first step is to assemble a team to manage and respond to the breach. Data breach team lead [insert the name or description of the person who will lead the data breach team, eg DPO] [ Data protection officer (DPO)] [[insert name]] Head of legal [insert name] Head of compliance [insert name] Head of IT [insert name] [insert any other, eg head of HR if the breach involves employee data] [insert name] 2 Background information Refer to the Data breach report form, if appropriate. Name of person notifying the actual or suspected breach [insert name] Department and manager [insert department from which the report emanates and manager for that department] Date of actual or suspected breach [insert date] Date of discovery of actual or suspected breach [insert date] Date actual or suspected breach notified internally [insert date] 3 Preliminary assessment As soon as possible, you should take steps to contain the breach and recover lost data, but before you can do this you will need to make a preliminary assessment of what data has been lost, why and how. Summary of the facts [provide as much information as possible—including the amount, sensitivity and type of data involved] Categories
PRECEDENTS
1 General information Date of monitoring review [insert date] Person conducting monitoring review [insert name and job title] 2 Volume of data breaches identified and reported Review your Data breach register for the past 12 months and complete the information below. Category Over the last 12 months Suspected data security breaches [insert number of suspected data security breaches] Actual data security breaches [insert number of actual data security breaches] [Reports to [insert name of any relevant regulator or trade body]] [[insert number of reports sent to relevant regulator or trade body]] Reports to the ICO (involving actual or suspected data security breaches) [insert number of reports sent to the ICO] Data subjects notified of actual or suspected data security