Refine By
Clear all filter
About 91354 results for "*"
PRECEDENTS
1 General information Date of this report [Insert date of this report] Date of last report [Insert date of last report] Period covered by this report [Insert period covered by this report] Report prepared and submitted by [Insert name and status of person(s) preparing and/or submitting the report] 2 Status of data protection compliance systems Event Date last completed Next scheduled date Organisation-wide data protection training session [Insert date of last organisation-wide data protection training session] [Insert date of next organisation-wide data protection training session] Data protection compliance audit [Insert date of last data protection compliance audit at the organisation] [Insert date of next data protection compliance audit at the organisation] Data protection risk assessment [Insert date of organisation’s last data protection risk assessment] [Insert date of organisation’s next data protection risk assessment] 3 Regulatory changes 3.1 Recent regulatory changes Recent regulatory change (ie since last [insert, eg quarter]) Impact on organisation and response [Summarise change] [Explain the impact of this change and how the organisation has responded] [Summarise change] [Explain the impact of this change and how the organisation has responded] 3.2 Other anticipated regulatory changes Anticipated regulatory change Impact on organisation and suggested response [Summarise anticipated change] [Explain whether this will have any impact on the organisation and
CHECKLISTS
This Data protection by design and default (DPbDD) checklist is intended for private-sector commercial organisations in the UK. It reflects the Information Commissioner’s Office’s Data protection by design and default guidance. Completing this checklist will help you demonstrate that you have taken action to meet the ICO’s expectations and record how you have done so. For more guidance on the principle of DPbDD, see Practice Note: How to implement data protection by design and default (DPbDD). See also Precedent: Data protection by design and default—policy. ICO expectation Evidence of compliance ☐ Consider privacy and data protection issues of any system, service, product or process:—at the design phase—throughout its lifecycle [Insert, eg Data protection impact assessments (DPIAs) or privacy impact assessments (PIAs) are conducted at the outset of all projects or initiatives that may involve processing personal data.] ☐ Map out:—what personal information you will use, how you will use it, and for what purpose—the risks that this may pose to individuals, and—the possible measures available to ensure
PRECEDENTS
1 Data protection by design and default—the concept 1.1 Data protection by design and default (DPbDD) is a requirement of the UK General Data Protection Regulation (UK GDPR). 1.2 In essence, DPbDD involves considering data protection and privacy issues upfront in everything we do. This means we have to integrate data protection into our processing activities and business practices, from the design stage right through the lifecycle. 1.3 Taking a DPbDD approach when designing or reviewing projects, policies, products or systems: 1.3.1 will help us comply with many other parts of the UK GDPR; 1.3.2 can reduce longer-term costs by preventing the need for future large-scale redesigns when data protection issues arise; 1.3.3 can help build user trust and confidence; 1.3.4 [can increase our chances of meeting procurement requirements for regulated markets such as healthcare;] 1.3.5 can help persuade other organisations to partner with us. 2 DPbDD—key principles 2.1 We consider data protection issues as part of the design and implementation of systems, services, products and business practices. 2.2 We make data protection an essential component of the core functionality of our processing systems and services. 2.3 We have systems in place to anticipate
PRACTICE NOTES
This Practice Note tracks cases currently being heard in the Court of Justice of the European Union related to the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) or the previous Directive 95/46/EC (Data Protection Directive). It is updated on a monthly basis. For an introduction to the EU GDPR, see: UK data protection law collection and Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Name and case reference Main Articles at issue Developments Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen Case C-458/25 EU GDPR: Article 83(7) 10 September 2026: Advocate General’s Opinion6 October 2025: Application (OJ)11 July 2025: Request for a preliminary hearing Ministar na zdraveopazvaneto Case C-546/26 EU GDPR: Article 9 24 August 2026: Application (OJ)26 May 2026: Request for a preliminary ruling Protectra Case C-323/26 EU GDPR: Articles 80(1) and 82 17 August 2026: Application (OJ)14 April 2026: Request for a preliminary ruling Bundesverband für Inkasso und Forderungsmanagement Case
PRACTICE NOTES
We have produced a collection that collates key practical guidance on the specific legal and practical implications of data protection law in the UK. The collection focuses on the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). In relation to the subject matter of the collection, there are
PRECEDENTS
This form is intended to help you to submit a data protection complaint in a way that will enable us to investigate and deal with it as quickly as possible. The form is entirely optional and, if you prefer, you can simply write to us or email us with your complaint using the contact details in section 5. 1 About you This section should be completed in relation to the person who is making the complaint, even if the complaint relates to someone else. Your name [Details to be inserted here] Your contact details [Details to be inserted here] [Account OR Customer OR Client] number, if known [Details to be inserted here] [Your identity information] [ For security reasons, we cannot respond to a complaint unless we have confirmed your identity. Please provide [insert details of identity information required, eg a certified copy of a driving
PRACTICE NOTES
This Practice Note addresses FAQs on data protection complaints following the Data (Use and Access) Act 2025 (DUAA 2025), covering the pre-existing position under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018 (DPA 2018), the new obligation on controllers to facilitate and handle complaints which applies from 19 June 2026, and key guidance from the UK’s data protection regulator, the Information Commissioner’s Office (ICO) on this new obligation. What is the pre-Data (Use and Access) Act 2025 (DUAA 2025) position on data protection complaints? Under UK data protection law, data subjects have the right to lodge complaints with the ICO if they believe their personal data has been processed in a manner that breaches the UK GDPR or DPA 2018, Pt 3 or 4. This right is enshrined in Article 77 of the UK GDPR and DPA 2018, s 165. The ICO is required to inform the complainant of the progress and outcome of the complaint. Under
PRECEDENTS
1 We are committed to providing a high-quality service, in accordance with data protection law. At all times, we seek to comply with data protection principles by ensuring we: 1.1 process personal data lawfully, fairly and in a transparent way; 1.2 collect personal data for specific and legitimate purposes and do not process personal data in a way that is incompatible with those purposes; 1.3 collect and use adequate, relevant and minimal personal data; 1.4 take reasonable steps to make sure personal data is accurate and kept up to date; 1.5 do not keep personal data longer than necessary; and 1.6 implement appropriate security measures. 2 We acknowledge that we may not always get things right, so if something has gone wrong, we need you to tell us. This will help us to improve our standards of service and data protection controls. 3 How
PRECEDENTS
1 General information Date of review [Insert date] Person(s) conducting review [Insert name(s)] 2 Data analysis Criteria In the last [insert period, eg quarter] Over the last 12 months Total number of complaints received [Insert number] [Insert number] Categories of complaints received ☐ No response to a data subject request—[insert number]☐ Incomplete response to data subject access request (DSAR)—[insert number]☐ Personal data security breach—[insert number]☐ Inaccurate personal data—[insert number]☐ Inappropriate data sharing—[insert number]☐ Direct marketing—[insert number]☐ Excessive data retention—[insert number]☐ Using personal data for something other than notified to data subject☐ Exceeding the scope of consent—[insert
PRECEDENTS
This Precedent is intended for private-sector commercial organisations in the UK. It will allow you to keep a record of data protection complaints, including the category of each
PRECEDENTS
[Insert complainant’s name] [Insert complainant’s contact address] Our ref: [insert complaint reference number] Dear [insert complainant’s name] My name is [insert name of person dealing with complaint] and I am [insert job title of person dealing with complaint]. I will be dealing with your data protection complaint that we received on [insert date complaint received]. You can email me at [insert email address of person
PRECEDENTS
[insert complainant’s name] [insert complainant’s contact address] Our ref: [insert complaint reference number] Dear [insert complainant’s name] I am writing to confirm I have concluded the investigation of your complaint that I received on [insert date complaint received]. 1 Your complaint The specific issues of your complaint were: [insert details] The investigations I undertook were: [insert details] 2 Outcome of our investigation The conclusions we reached from our investigations are: [insert details,