Refine By
Clear all filter
About 91354 results for "*"
PRECEDENTS
Note: These provisions are drafted on the assumption that the relevant agreement is a business to business arrangement under which the supplier acts as processor for a customer acting as a controller in respect of the processing of personal data subject to the United Kingdom General Data Protection Regulation (UK GDPR), Assimilated Regulation (EU) 2016/679. The terms ‘supplier’ and ‘customer’ (instead of ‘processor’ or ‘controller’ respectively) have been used to make these provisions easier to integrate into commercial agreements. They also use the additional defined terms ‘Agreement’, ‘Business Day’, ‘Customer’, ‘Data Protection Laws’, ‘Data Subject’, ‘GDPR’ and ‘Supplier’, which it is assumed are separately defined as appropriate in the relevant agreement. It is also assumed that the definition of ‘GDPR’ will refer to UK GDPR and that the definition of ‘Data Protection Laws’ will include UK GDPR. These provisions could also be adapted for use where the EU’s General Data Protection Regulation
PRACTICE NOTES
ARCHIVED: This Practice Note has been archived and is not maintained. It summarises the guidance set out in Opinion 2/2017 of the Article 29 Data Protection Work Party (referred to in this Practice Note as the Article 29 Opinion) on how Regulation (EU) 2016/679, EU GDPR affects data processing in the employment relationship and the balance between the legitimate interests of employers and the reasonable privacy expectations of employees. The Article 29 Opinion is based on Directive 95/46/EC, the Data Protection Directive, but looked towards the obligations under Regulation (EU) 2016/679, EU GDPR, which was not, at the time the Article 29 Opinion was published, in force. Since IP completion day (11 pm on 31 December 2020), Regulation (EU) 2016/679, General Data Protection Regulation (GDPR) is retained EU law (see Practice Note: Retained EU law in employment [Archived]) and known as UK GDPR. Together with the parts of the Data Protection Act 2018 that relate to general personal data processing, powers of the Information Commissioner and sanctions and enforcement, as amended, this makes up the UK
PRECEDENTS
Please click for the register. The register consists of two tabs: • Data processing register—several rows have been pre-populated to demonstrate how the register is intended to be used, using examples from the ICO’s
PRECEDENTS
This Agreement is made on [date] Parties 1 [Insert name of supplier], a company incorporated in [England and Wales] under number [insert registered number] whose registered office is at [insert address] (Supplier); and 2 [Insert name of customer], a company incorporated in [England and Wales] under number [insert registered number] whose registered office is at [insert address] (Customer), each of the Supplier and the Customer being a party and together the Supplier and the Customer are the parties. Background (A) The Supplier is an experienced provider of [insert details]. (B) This Agreement governs all processing of Protected Data undertaken by the Supplier under and in connection with [the Principal Agreement OR all of Our Arrangements]. The parties agree: 1 Definitions and interpretation 1.1 In this Agreement: Applicable Law • means: (a) any law, legislation, regulation, byelaw or subordinate legislation in force from time to time to which a party is subject and/or in any jurisdiction that the Services are provided to or in respect of; (b) the common law and laws of equity as applicable to the parties from time to time; (c) any binding court order, judgment or decree; (d) [any applicable guidance, guidelines or codes of practice issued by any relevant Data Protection Supervisory
GLOSSARY
A data processor is a person who processes personal data for a data controller, other than the controller's employee. Outsourced IT and HR service providers may be processors.
GLOSSARY
In an employment context, this refers to the obligation on an employer to protect the data of its employees and ensure that it complies with the law on how it uses the employees' data.
PRACTICE NOTES
ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May 2018 and reflects the position under the Data Protection Act 1998 (DPA 1998). This Practice Note is for background information only and is not maintained. What is meant by image? Two kinds of image are discussed in this Practice Note: (1) the likeness of a person’s physical characteristics and the physical circumstances of their proximity (ie a photograph or picture)—the ontic definition; and (2) the perception of a person in the mind of the public—the ontological definition. Both are relevant in a data protection context. For a comprehensive introduction to the GDPR, collating key practical guidance, see: UK data protection law collection. Data protection The purpose of the law of data protection is to ensure that those who process personal data for other than strictly domestic purposes are regulated. The basis for the necessity of such regulation is outside the scope of this Practice Note. Under the DPA 1998, personal data are data
PRACTICE NOTES
Increasingly, organisations are required to conduct investigations to meet their legal obligations. Common scenarios that may trigger an investigation include: • an individual raising a concern internally via a whistleblowing hotline or otherwise • a response to a regulatory or criminal agency demand • part of due diligence in advance of a merger or acquisition • a civil litigation claim • an internal or external auditor’s report • media reports • an external allegation, eg from a customer or counter-party One of the most challenging areas for multinational businesses is the tension between data protection laws and requirements imposed by legislation aimed at tackling financial crime. For example, under the Bribery Act 2010, the burden of proof is reversed and the company has to prove that it had adequate procedures to prevent those who perform services for it from committing bribery rather than the prosecution prove that it did not. The tax evasion facilitation regime operates in a similar way. See Practice Notes: Failure to prevent bribery—the offence and Failure to prevent facilitation of tax
PRACTICE NOTES
ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May 2018 and reflects the position under the Data Protection Act 1998 (DPA 1998). This Practice Note is for background information only and is not maintained. Data protection regime The DPA 1998 is the principal law in the UK which deals with data protection. For more information on the DPA 1998 generally, see Practice Note: Applicability and scope of the DPA 1998. When outsourcing, the customer and supplier should consider the requirements set out in the DPA 1998 (see: Data protection regime—overview) and, in particular, the following principles: • the first principle: see Practice Note Data protection principles under the DPA 1998—Principle 1: Personal data must be processed fairly and lawfully. Who is the 'data controller' of the 'personal data'? Typically the customer is the data controller (eg it decides how the personal data is 'processed') and the supplier is the 'data processor' • the seventh principle: see Practice Note Data protection principles under the DPA 1998. What
PRACTICE NOTES
This Practice Note contains practical guidance on how the UK film and photography industry has adapted in order to comply with data protection law, which in the UK is primarily based on the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018. It also contains specific guidance on both the Information Commissioner’s Office’s (ICO) Data protection and journalism code (the Code) and the impact of data protection laws on release agreements. This Practice Note assumes basic knowledge of UK data protection law. For an introduction to the general principles underpinning this, see Practice Notes: • Introduction to the EU GDPR and UK GDPR • The Data Protection Act 2018 and the UK GDPR The UK media and creative industries, which produce and publish visual content depicting people, have faced unenviable dilemmas when it comes to the interpretation of data protection law. These dilemmas often translate into uncertainty as to the robustness of adopted processes despite, in many cases, the incurrence of significant legal costs in
CHECKLISTS
This Checklist is designed to assist trustees to review and amend their working practices in relation to the personal information they collect, process and continue to hold about settlors, protectors, beneficiaries and other individuals connected to the trust. For a comprehensive introduction to Retained Regulation (EU) 2016/679, the UK General Data Protection Regulation (UK GDPR), collating key practical guidance, see: UK data protection law collection. see: UK data protection law collection.Assimilated law is the name given to retained EU law (‘REUL’) which remains in force after the end of 2023. The re-categorisation of REUL (and associated terms) to assimilated law reflects a change in its status and treatment under UK law, in that it is generally to be interpreted according to ordinary domestic law and principles. From 1 January 2024, REUL is ‘assimilated’ into domestic law by virtue of the fact it is generally stripped of EU-derived interpretive effects (eg supremacy of EU law, directly effective rights, and general principles previously retained under EU(W)A 2018). Trustees should also consider any amendments made to the UK data protection
PRECEDENTS
Date: [insert date] 1 Introduction As our [senior management team OR board], it is important for you to understand how data protection law affects our business, why it is so important and what we need to do to ensure compliance. This briefing sets out the key elements of the UK General Data Protection Regulation (UK GDPR) and what we do to ensure we comply. If any of the terms in this briefing are unfamiliar, please refer to our [insert name of document, eg detailed board briefing]. 2 Which data protection laws apply to our business? The main data protection rules can be found in the UK GDPR and Data Protection Act 2018 (DPA 2018). Much of our direct marketing activities are also regulated by the Privacy and Electronic Communications Regulations 2003 (PECR 2003). The EU GDPR also applies to activities directed at people in the EU. Breaching the data protection rules can expose us to fines of up to £17.5 million under the UK GDPR (€20 million under the EU GDPR) or 4% of total worldwide annual turnover, whichever is higher—as well as