Refine By
Clear all filter
About 91354 results for "*"
PRECEDENTS
Please click for an Excel version of this register. The Data breach register (also known as a data breach log) reflects reporting and recording requirements under Assimilated Regulation (EU) 2016/679, the UK General Data Protection Regulation (UK GDPR). It can be used to help you record, manage and monitor data breaches. It will ensure you capture the information you are required to record under the UK GDPR as well as the information you will need to notify a data breach to the Information Commissioner’s Office (ICO) and/or affected data subjects. This register has been prepared in Excel and it therefore cannot be downloaded to Word. See also Precedent: Personal data breach plan. Requirement to keep a record You must document any personal data breaches—record the facts relating to each personal data breach, its effects
PRECEDENTS
If you know or suspect a personal data breach has occurred, please: • complete this form, and • email or deliver it to the [insert, eg the data protection officer], ensuring you mark your email or the form as urgent Time is of the essence with data breaches. You must submit this report as soon as you know or suspect there has been
NEWS
Arbitration analysis: As Artificial Intelligence (AI) continues to revolutionise industries such as healthcare, finance, and logistics, it also raises complex legal questions, especially around data privacy. AI systems depend on massive datasets to perform functions like predictive analytics, natural language processing, and automated decision-making. These systems not only process vast amounts of personal data but often also interact autonomously, sometimes without human oversight. This makes AI both a transformative technology and a significant risk vector for data breaches. Tahir Khan, Barrister at The Barrister Group, considers data breaches and liability in the Age of AI, and who is responsible.
PRECEDENTS
1. Data breach team Damage limitation is a priority immediately following a security breach. You will need a team of people to manage the data breach. What should you do? ☐ Assemble a data breach team, including your data protection officer (DPO) and/or data protection manager (DPM) (if you have one), head of legal/compliance, head of IT and head of HR (if employee data is involved). ☐ Appoint someone to lead the team (preferably not your head of IT). 2. Preliminary notifications Your first instinct may be to tell affected individuals and regulators about the breach, but you need more information before you can decide whether this is necessary or desirable. The time limit for notifying the Information Commissioner’s Office (ICO) under the UK General Data Protection Regulation (UK GDPR) is 72 hours from becoming aware of the breach and the UK GDPR Recitals suggest you should notify the ICO first before communicating with data subjects. Your focus during the first 24 hours should be on containment and recovery. What should you do? ☐
NEWS
Law360, London: A former executive of GlobalData Plc has won his claim over share options allegedly worth £797,000 as a London court ruled that it would be 'unconscionable' for the business not to honour them after he left.
NEWS
Information Law analysis: In this case, the Court of Appeal unanimously allowed the appeal brought by the Information Commissioner’s Office (ICO), holding that it is sufficient that data which has been subjected to unauthorised or unlawful processing by a third party still constitutes personal data from the perspective of the data controller, even if it is pseudonymised ‘in the hands of’ the data controller and therefore anonymised ‘in the hands of’ the attacker. Accordingly, the court held, the data controller is required to take ‘appropriate technical and organisational measures’ (ATOMs) to protect that personal data against such hackers, even where those third parties cannot themselves identify the individuals to whom the data relates. Even though this judgment is under the Data Protection Act 1998 (DPA 1998), this decision is significant as it confirms, in terms equally applicable to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR), that the scope of the security obligation is not diminished merely because stolen or exfiltrated data would be anonymised in the hands of the third party with unlawful access. This development expands and makes more pressing the obligation on controllers to assess and guard against a broader range of threats—including ransomware, data destruction, and bulk exfiltration, regardless of the attacker's capacity to re-identify data subjects. Written by Adelaide Lopez, senior associate at Wiggin LLP.
PRACTICE NOTES
A data centre is a facility that houses computer and communications equipment. This Practice Note covers the following key issues: • Security • Personal data • Technology • Service descriptions and service levels • Business continuity • Encryption • The supplier • Contracting issues • Ongoing management Data centre services may be provided through various models, which may be summarised at a high level as follows: • co-location service—a co-location service enables the customer to rent space in the data centre and for the supplier to provide the facilities in which the customer operates its own servers. The supplier will also provide ancillary services that are essential to use such space relating to the maintenance of the security of the data centre and the rented space, provision of power and the control of the humidity and temperature throughout the data centre. The amount of space taken may range from use of a shelf on an equipment rack, to a dedicated room or cage, through to an entire floor and/or building. The space
PRACTICE NOTES
This Practice Note builds on the overview provided in Practice Note: Data centre projects—key aspects by examining the principal construction-related legal and contractual arising in the development of data centre projects in Great Britain (GB). It considers which parties are typically involved on data centre projects, procurement routes and contract selection, and the requirements, risks and areas of dispute particularly relevant to such projects. In this Practice Note, it is assumed that the data centre project: • is a standalone data centre development • may be financed using a variety of funding structures, including sponsor funding, institutional investment, corporate finance or project finance This Practice Note forms part of a series of Practice Notes on data centre projects. Practice Note: Data centre projects—key aspects is the principal overview of the series and includes links to all the specialist Practice Notes covering the legal, commercial and technical aspects of data centre development. Introduction to data centre projects Data centres have moved rapidly to the centre
PRACTICE NOTES
The regulatory framework governing electricity network connections has undergone, and continues to undergo, significant reform. This Practice Note provides an overview of the evolving legal and regulatory framework governing electricity network connections for data centres in Great Britain (GB) and explains the key reforms. The reforms considered in this Practice Note have developed and continue to evolve through a number of related workstreams led by the government, Ofgem and the National Energy System Operator (NESO). For more information on the roles, functions and governance of Ofgem and NESO, see Practice Notes: Ofgem and The National Energy System Operator (NESO). Although each workstream has a distinct purpose, together they form part of a broader programme intended to improve the operation of the electricity connections queue, facilitate the timely connection of data centres (as strategically important demand projects) and accelerate the delivery of the electricity infrastructure required to support economic growth, digital infrastructure and the transition to a low carbon electricity system. This Practice Note considers the key consultations, policy papers, regulatory decisions and implementation
PRACTICE NOTES
This Practice Note builds on the overview provided in Practice Note: Data centre projects—key aspects by examining the principal energy-related legal, regulatory and commercial issues arising in the development of data centre projects in GB. It considers the electrical capacity and connection requirements of different types of data centre, the process and challenges associated with securing an electricity network connection, and the evolving reforms affecting large electricity demand connections. It also considers behind-the-meter and other alternative electricity supply strategies, electricity licensing, electricity procurement strategies, heat networks and waste heat recovery, and the energy-specific factors relevant to site selection. These issues are also likely to be relevant to investors and lenders assessing the technical, commercial and regulatory risks associated with a proposed data centre development. In this Practice Note, it is assumed that the data centre project: • is a standalone data centre development (although this Practice Note considers co-located generation, private wire arrangements and other alternative electricity supply strategies, where relevant) • is principally supplied by low-carbon electricity (although this Practice Note
PRACTICE NOTES
This Practice Note provides an overview of the key legal, regulatory, commercial and practical issues arising in the development, financing, construction, operation, and eventual expansion or the sale of a data centre. It is aimed at lawyers and other professional advisors who have limited or no prior experience of data centre projects, or who need to understand how the relevant workstreams fit together. It may also be useful for lawyers involved in acquisitions, disposals, investment, refinancing or due diligence of operational data centre assets or development sites In this Practice Note it is assumed that the data centre project: • relies on low-carbon electricity supply (and, therefore, excludes the supply of electricity generated from natural gas without carbon capture technology) • is a standalone project, as opposed to a ‘hybrid’ project being simultaneously developed alongside co-located electricity generation or energy storage assets ◦ may be financed through a variety of funding structures, including sponsor balance sheet funding, institutional investment, corporate debt facilities or, where appropriate,
GLOSSARY
The process of trying to ensure that the pension scheme records about members and their rights are in good order.