Refine By
Clear all filter
About 91353 results for "*"
PRACTICE NOTES
Under the UK GDPR, certain organisations are required to appoint an individual to act as their data protection officer (DPO). This Practice Note sets out when organisations must appoint a DPO to comply with the UK GDPR and the pros and cons of voluntarily appointing a DPO. It also considers who should be the organisation’s DPO, the duties of the DPO and the risk of conflicts of interest. It should be read in conjunction with: DPO appointment decision tree. For more information on governance and accountability under UK GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Accountability and governance. This Practice Note is based on the UK GDPR, guidance issued by the Information Commissioner’s Office (ICO) and guidelines on DPOs published by the Article 29 Data Protection Working Party and subsequently endorsed by the European Data Protection Board (EDPB) (EDPB guidance on DPOs). Although EDPB guidance on DPOs is not directly relevant to, or binding under, the UK regime, the ICO has confirmed it may provide helpful guidance on certain issues. Mandatory
CHECKLISTS
This data protection officer (DPO) Checklist pulls together requirements in the UK General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) relating to the appointment of a DPO. It provides guidance which is of general application and also contains recommended actions based on ICO guidance and Guidelines on Data Protection Officers (DPOs) published by the Article 29 Data Protection Working Party and subsequently endorsed by the European Data Protection Board (EDPB guidance). Although EDPB guidance is no longer directly relevant to, or binding under the UK regime, the Information Commissioner’s Office (ICO) has confirmed it may still provide helpful guidance on certain issues. The Checklist signposts relevant Precedents you can use or adapt to comply with these requirements and recommendations. You can tick when you have completed each requirement and you can also insert comments or note action points. For more guidance, see Flowchart: DPO appointment decision tree and Practice Note: Data protection officer, or for law firms: Data protection officer—law firms. Requirement Compulsory or recommended Comment/action ☐ Determine:—are you required to appoint
PRECEDENTS
1 DPO details Name of organisation [Insert name of organisation] Name of DPO [Insert name] Reports to [Insert name and/or position] Full time/part time [Insert] Details of any other roles held within the organisation [Insert details of any other roles held] Date appointed [Insert date] 2 Role summary To act as the data protection officer (DPO) for [insert name of organisation] under the UK General Data Protection Regulation (UK GDPR) and to: 2.1 facilitate [insert name of organisation]’s compliance with the UK GDPR and other applicable data protection legislation by ensuring effective systems and controls are in place to enable [insert name of organisation], including its managers and employees, to comply with their legal obligations 2.2 act as intermediary between relevant stakeholders, including the Information Commissioner’s Office (ICO), data subjects and business units within [insert name of organisation] 2.3 act as [insert name of organisation]’s focal point for data protection activities and foster a good data protection culture within [insert name of organisation] 3 Job description/role profile 3.1 Responsibilities under the UK GDPR 3.1.1 Inform and advise [insert name of organisation], its managers and employees [insert name of organisation] of their obligations under the UK GDPR and
PRACTICE NOTES
Under the UK GDPR, certain firms are required to appoint an individual to act as their data protection officer (DPO). This Practice Note sets out when firms must appoint a DPO to comply with the UK GDPR and the pros and cons of voluntarily appointing a DPO. It also considers who should be the firm’s DPO, the duties of the DPO and the risk of conflicts of interest. It should be read in conjunction with: DPO appointment decision tree. For more information on governance and accountability under UK GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Accountability and governance. This Practice Note is based on the UK GDPR and the following guidance: • Information Commissioner’s Office (ICO) guidance: UK GDPR guidance and resources, Accountability and governance, Data protection officers • guidelines on DPOs published by the Article 29 Data Protection Working Party and subsequently endorsed by the European Data Protection Board (EDPB guidance on DPOs)—although EDPB guidance is not directly relevant to, or binding under, the UK regime, the ICO has confirmed it
PRACTICE NOTES
This Practice Note covers the principles for handling personal data that form the core of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) regime. For a general introduction to data protection law, including links to guidance on additional duties that arise under the UK GDPR, see the UK data protection law collection. In relation to the subject matter of this Practice Note, there is great similarity between the UK GDPR regime and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) regime. This Practice Note focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation, and for more details on similar principles in the EEA applying under the EU GDPR, see Practice Note: EU GDPR—data protection principles. Note that, in certain circumstances, both the UK GDPR and EU GDPR may
GLOSSARY
Compliance with the Data Protection Act 1998 principally concerns compliance with eight data protection principles set out within it.
PRACTICE NOTES
ARCHIVED: This archived Practice Note provides information on the data protection regime before 25 May 2018 and reflects the position under the Data Protection Act 1998 (DPA 1998). This Practice Note is for background information only and is not maintained. Under the DPA 1998 data controllers that handle personal data must comply with the following eight principles: • Principle 1: personal data must be processed fairly and lawfully • Principle 2: personal data must be obtained only for specified and lawful purposes • Principle 3: personal data must be adequate, relevant and not excessive • Principle 4: personal data must be accurate and kept up to date • Principle 5: personal data must not be kept for longer than necessary • Principle 6: personal data must be processed in accordance with the rights of data subjects • Principle 7: there must be measures against unauthorised or unlawful processing of personal data • Principle 8: there must be adequate protection for personal data transferred outside the EEA Other laws applicable
PRECEDENTS
[Insert name of organisation] Data protection privacy notice We refer to our separate letter telling you that [we are proposing to transfer our [insert details] business to [insert name of transferee] OR we are proposing to outsource our [specify business function] to [insert name of transferee] OR our contract for the provision of [insert details] services to [insert name of client] is coming to an end and, on its termination, those services will be performed by [insert name of new contractor/client]]. This notice explains what personal data (information) [insert name of employer][ trading as [insert trading name, if different]] (‘we’ or ‘Company’) will process and share with [insert name of transferee] in connection with the transfer. We are required to notify you of this information under data protection legislation. Please ensure that you read this notice (sometimes referred to as a ‘privacy notice’) and any other similar notice we may provide to you from time to time when we collect or process personal information about you. Due diligence process [Insert name of transferee] needs further information
PRECEDENTS
[Insert name of organisation] Data protection privacy notice (employment) This notice explains what personal data (information) we hold about you, how we collect it, and how we use and may share data about you during your employment and after it ends. We are required to notify you of this information under data protection legislation. Please ensure that you read this notice (sometimes referred to as a ‘privacy notice’) and any other similar notice we may provide to you from time to time when we collect or process personal data about you. Who collects the data [Insert name of employer] [trading as [insert trading name, if different]] (‘Company’) is a ‘controller’ of personal data and gathers and uses certain data about you.[ This data is also used by our affiliated entities and group companies, namely [insert details or a link, or otherwise show where details of group companies can be obtained] (our ‘group companies’) and so, in this notice, references to ‘we’ or ‘us’ mean the Company and our group companies.] Data protection principles We will comply with the data protection
PRECEDENTS
[Insert name of organisation] Data protection privacy notice (recruitment) This notice explains what personal data (information) we will hold about you, how we collect it, and how we will use and may share data about you during the application process. We are required to notify you of this information, under data protection legislation. Please ensure that you read this notice (sometimes referred to as a ‘privacy notice’) and any other similar notice we may provide to you from time to time when we collect or process personal data about you. Who collects the data [Insert name of employer][ trading as [insert trading name, if different]] (‘Company’) is a ‘controller’ of personal data and gathers and uses certain data about you.[ This data is also used by our affiliated entities and group companies, namely [insert details or a link, or otherwise show where details of group companies can be obtained] (our ‘group companies’) and so, in this notice, references to ‘we’ or ‘us’ mean the Company and our group companies.] Data protection principles We will comply with the data protection principles
PRECEDENTS
[Insert name of organisation] Data protection privacy notice (secondment) As you know, it is proposed that you will be seconded to [insert name] (host employer). This notice explains what personal data (information) [insert name of employer][ trading as [insert trading name, if different]] (‘we’ or ‘Company’) will share with, and receive from, your host employer for the purposes of your secondment. We are required to notify you of this information under data protection legislation. Please ensure that you read this notice (sometimes referred to as a ‘privacy notice’) and any other similar notice we may provide to you from time to time when we collect or process personal data about you. This privacy notice As set out in the [data protection privacy notice (employment)], the Company is a ‘controller’ and gathers and uses certain data about you.[ This data is also used by our affiliated entities and group companies, namely [insert details or a link, or otherwise show where details of group companies can be obtained] (our ‘group companies’) and so, in this notice, references
PRACTICE NOTES
This Practice Note provides guidance on an individual’s rights as a data subject in the employment context. In particular, it considers the issues that an employer organisation will need to address when drafting a privacy notice to comply with the right to be informed, enjoyed by employees and other workers and contractors. It refers to employers and to employees, however similar principles apply where the individuals have the status of workers or independent contractors. It reflects the UK GDPR regime, and legislative links are to Assimilated Regulation (EU) 2016/679, UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018), unless expressly stated otherwise. For an overview of the key themes of Assimilated Regulation (EU) 2016/679, UK GDPR and DPA 2018 and guidance on particular issues of relevance to employment lawyers, see Practice Notes: • The UK GDPR and DPA 2018: key data protection issues for employment lawyers, and • The UK GDPR and DPA 2018: lawful processing of personal data in employment Data subject rights Individuals (as data subjects)