Refine By
Clear all filter
About 91354 results for "*"
PRACTICE NOTES
ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May 2018 and reflects the position under the Data Protection Act 1998. This Practice Note is for background information only and is not maintained. Under the GDPR, it is even less likely than it was under Data Protection Directive, Directive 95/46/EC that an employer will be able to rely on employee consent as the legal basis for data processing at work and given the serious consequences of failing to comply with obligations under the GDPR, employers should therefore avoid relying on consent as a lawful processing condition. In most cases, it is likely that the employer will instead be able to rely on ‘legitimate interests’ condition, provided: • the processing is necessary for the purposes of the employer’s legitimate interests • those interests are not overridden by the employee’s interests or fundamental rights and freedoms • the processing is proportionate and cannot be achieved by other, less intrusive means • the data being processed are adequate, relevant
PRACTICE NOTES
This new starter guide provides an introduction to data protection law for those who are not familiar with data protection and includes a general summary of key aspects of the general UK data protection regime. There are separate, more detailed Practice Notes for specialists or those advising on specific aspects of data protection law. For a toolkit which brings together various key guidance on aspects of data protection, see the UK data protection law collection. Data protection law and its purpose In summary, data protection law in the UK is intended to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, UK data protection law imposes a large number of obligations on those ‘processing’ personal data (and on the controllers of such processing). They also grant rights to those whose personal data is processed (the ‘data subjects’). ‘Processing’ includes doing almost anything with personal data, including storing, sharing, deleting or using it. It is virtually impossible to operate a business or other organisation
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to data protection impact assessments (DPIAs) in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation Summary
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (Guide). This part of the Guide addresses the negotiation of provisions relating to deletion and return of personal data at the end of the processing in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to: • the requirement under Article 28(3)(a) of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) that the processing contract must require that the processor processes personal data only on documented instructions from the controller, and • an additional related requirement in Article 28(3) of the UK GDPR, second paragraph, for a processor to immediately inform the controller if, in the processor’s opinion, an instruction infringes certain data protection laws For an introduction to the Guide and related content, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between
PRACTICE NOTES
This Practice Note links to a collection that collates a detailed Data Protection Negotiation Guide (the Guide) on the negotiation of provisions in agreements between controllers and processors that are subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). It also includes various supporting materials. Note that there are significant similarities between the UK GDPR and the EU’s General
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the guide addresses the negotiation of terms relating to information provision, audits and inspections in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation
PRACTICE NOTES
This Practice Note introduces the detailed Data Protection Negotiation Guide (the Guide) on the negotiation of provisions in agreements between controllers and processors that are subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). Note that there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and this Practice Note focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation. For further information on the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). The Guide is detailed and assumes a level of knowledge of general data protection law. For a more general introduction to the requirements that apply where a controller uses a processor, and guidance on the meaning of key terms such as ‘controller’ and ‘processor’, see Practice Note: Supply chains under data protection
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to the notification of breaches to the ICO in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note:
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to the notification of breaches to data subjects in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to prior consultation with the Information Commissioner’s Office (ICO) in agreements between controllers and processors subject to the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). For an introduction to the Guide, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and the Guide focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK
PRACTICE NOTES
This Practice Note forms part of the Data Protection Negotiation Guide (the Guide). This part of the Guide addresses the negotiation of provisions relating to the requirement under Article 28(1) of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) for controllers to only use processors providing ‘sufficient guarantees’ to implement technical and organisational measures so that their processing is UK GDPR-compliant and to ensure that data subjects’ rights are protected. For an introduction to the Guide, related content and instructions on how to use this information, see Practice Note: Data protection negotiation guide—controller: processor—introduction. This Practice Note utilises a number of common abbreviations. They are separately defined within the above introduction. As explained in Practice Note: Data protection negotiation guide—controller: processor—introduction: • the parties have commercial flexibility to allocate the costs and expenses of performing these obligations between themselves • there are significant similarities between the UK GDPR and the EU’s General Data Protection