Refine By
Clear all filter
About 91353 results for "*"
PRECEDENTS
This Data protection quick reference guide summarises the key features of data protection law, including the UK General Data Protection Regulation (UK GDPR). What is the UK GDPR? The UK General Data Protection Regulation (Assimilated Regulation (EU) 2016/679—UK GDPR) is the main source of data protection law in the UK. It is supplemented by the Data Protection Act 2018 (DPA 2018). Who is the data protection regulator in the UK? The Information Commissioner’s Office (ICO) is responsible for ensuring data protection laws are followed in the UK. What type of information does the UK GDPR regulate? The UK GDPR does not cover all types of information or data. It only protects personal data, which includes special category (sensitive) personal data.These terms are explained in more detail below. What is personal data? ‘Personal data’ means any information relating to a living person.This means any information which makes it possible to identify an individual, eg:—full name (first and last names together)—ID number (eg passport or driving licence number)—phone number or email address—photograph—postal address—employee or National Insurance numbers—IP address, and—CCTV images of individualsInformation
PRECEDENTS
1 Background information Assessment for [state whether the assessment relates to the whole organisation or a specific department] Person conducting assessment [insert name] Date of assessment [insert date] 2 What personal data do you receive and/or hold? Consider what personal data you receive and/or hold and any inherent risks. 2.1 Review Category of personal data Data type How is this received? How is this stored? Customer names and addresses Personal data ☐ Telephone☐ Email☐ Website☐ In person[insert other] ☐ On paper☐ IT system☐ Mobile devices[insert other] Customer orders and invoices ☐ Personal data☐ Special category personal data☐ Mix of personal and special category personal data ☐ Telephone☐ Email☐ Website☐ In person[insert other] ☐ On paper☐ IT system☐ Mobile devices[insert other] Employee data including HR files Mix of personal and special category personal data ☐ Telephone☐ Email☐ Intranet☐ In person[insert other, eg hard copy] [state how you store HR files and whether HR data could be stored anywhere else, eg email folders, HR system] [Supplier lists] [Could be some personal data] [[if you keep a supplier list, state where the information comes from]] [[state how you store supplier lists, eg on your intranet]] Information in customer relationship management (CRM) system ☐ Personal data☐ Special category personal data ☐ Mix of personal
PRECEDENTS
1 Background information Assessment for [state whether the assessment relates to the whole organisation or a specific department] Person conducting assessment [insert name] Date of assessment [insert date] 2 What personal data do you receive and/or hold? 2.1 Consider and list the categories of personal data you receive and/or hold: 2.1.1 Customer names and addresses 2.1.2 Customer orders and invoices 2.1.3 Employee data including HR files 2.1.4 [Supplier lists] 2.1.5 [Information in CRM system] 2.1.6 Customer website preferences/IP addresses 2.1.7 [Insert other] 2.1.8 [Insert other] 2.2 Complete the table below, identifying associated risks and action points. For each risk you identify: 2.2.1 record an action point to address the risk immediately (this is suitable for simple risks that can be resolved quickly), or 2.2.2 make a note to add the risk to your privacy risk register (which you should do for risks which cannot be addressed quickly and/or require complex solutions) Question Answer Associated risks Action point (if any) How do you receive data? [list different methods] [Identify and insert risks for each method of receiving data] ☐ No action required☐ Immediate action to be taken—[describe action]☐ Add to privacy risk register How do you store data? [list different methods] [Identify and insert risks for each method of storing data] ☐ No action required☐ Immediate action to be taken—[describe action]☐ Add
PRACTICE NOTES
Why you need to manage this risk Data protection is one of the most challenging areas of risk management—the law is complex and wide-ranging, it operates at UK, EU and international levels, is in a constant state of flux and subject to high-profile legal challenges. Failing to comply with data protection requirements under the UK General Data Protection Regulation (UK GDPR) can expose an organisation to serious reputational damage, claims by aggrieved data subjects and fines up to £17.5m or 4% of the total worldwide annual turnover. There are similar potential penalties under the EU GDPR. Top five priorities The table below identifies five key priorities for data protection risk management and gives the heads-up on why each one is a priority area. Each priority is then explained in further detail in the main body of this Risk management guide, including a series of mini action lists that: • suggest action points for each priority area • encourage you to record your level of compliance against each action point, and • signpost relevant materials
PRECEDENTS
Parties 1 [Insert the company name (the name of the sponsor)] with a registered office at [insert address] hereinafter referred to as the Controller; and 2 [Insert the company name (the name of the Contract Research Organisation (CRO))] with a registered office at [insert address] hereinafter referred to as the Processor, each of the Controller and the Processor being a Party and together the Controller and the Processor are the Parties. BACKGROUND (A) The Parties have entered into one or more written agreements for the purposes of providing certain Services related to [add description of the Services (eg the conduct and management of clinical trials)], as amended from time to time, and collectively, the ‘Principal Agreement’, which involve the processing of certain Personal Data. (B) The Parties wish to lay down their rights and obligations regarding the processing of Personal Data in this data protection schedule, the ‘Schedule’, which is intended to be attached to the Principal Agreement. (C) This Schedule between the Parties forms part of the Principal Agreement and consists of the main body of the Schedule, Appendix 1(Subject matter and details of the data processing operations), Appendix
PRECEDENTS
The training materials are customisable. Click the links below to download the training presentation and speaker notes. Contents • What is the EU GDPR? • Terminology • Data protection principles • Material scope • Territorial scope • Processors • Lawful processing—personal data • Lawful processing—standard of consent • Lawfulness of processing—children • Special categories of personal data • Lawful processing—special categories of data • Pseudonymous data • Rights of data subjects • Exemptions • Data protection officers (DPOs) • Breach notification & communication • Data protection impact assessments • Accountability • Data protection by design & default • Transfers outside of the EEA • Sanctions
PRACTICE NOTES
This Practice Note tracks noteworthy High Court, Court of Appeal and Supreme Court decisions related to data protection, ePrivacy, misuse of private information and confidential information. For an introduction to the data protection regimes under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and the Data Protection Act 2018 (DPA 2018), see: UK data protection law collection and Practice Notes: The UK General Data Protection Regulation (UK GDPR) and The Data Protection Act 2018. For introductions to ePrivacy, misuse of private information and confidential information, see: • ePrivacy—overview • Privacy and misuse of private information—overview • Confidential information—overview For a freedom of information and environmental information case tracker, see: Freedom of information case tracker. Cases Case Court and key date Summary Vince v Associated Newspapers Ltd [2026] EWCA Civ 899 Court of Appeal 15 July 2026 Data protection—Unfair processing The Court of Appeal held that the Daily Mail's juxtaposition of a claimant's photographs alongside a ‘sex pest donor’ headline (which referred to an entirely different
PRACTICE NOTES
This Practice Note answers some commonly raised queries faced by pensions lawyers in relation to the United Kingdom Regulation (EU) 2016/679 (UK GDPR), the Data Protection Act 2018 (which sits alongside the UK GDPR) and related issues. For further information on the UK GDPR and Data Protection Act 2018 (DPA 2018), see Practice Notes: • Data Protection for pensions lawyers • Introduction to the EU GDPR and UK GDPR • The UK General Data Protection Regulation (UK GDPR) • The Data Protection Act 2018 What was the impact of Brexit? Between 25 May 2018 and IP completion day (being 11 pm on 31 December 2020, the time at which the UK left the European Union), the UK applied the data protection regime introduced by the General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Before that, the UK’s data protection regime was set out in the Data Protection 1998 (DPA 1998), now repealed. The EU GDPR introduced a raft of changes to the previous data protection regime, including new and extended data subject rights,
PRECEDENTS
A: General information    Date of review [insert date] Person(s) conducting review [insert name(s) and/or role(s)] B: Review and findings Is your Data protection policy up to date and fit for purpose? ☐ Yes☐ NoIf no, please describe any changes needed and ensure you set an action point at section C below to update your Data protection policy accordingly Are you satisfied your Data protection procedures are in effective operation, in particular your procedures in relation to:• your obligations regarding the Information Commissioner’s Office (ICO)? • giving clients a notice in
PRECEDENTS
Dear [insert name] We have received various requests for documents from [Regulators and/or other agencies] in relation to [Project X]. It is therefore essential that no relevant documents or data are altered, destroyed, concealed or
GLOSSARY
As part of the due diligence and disclosure process in a share or asset sale, a physical or virtual space set up by the seller to make available legal, commercial and financial information relating to the target company/target business for review by prospective buyers. It is commonly used in an auction process where there will be a number of interested parties, but it is now used in a broad variety of transactions (especially because of the convenience of a virtual data room). A physical data room (PDR) is a room filled with documents and files. It would typically be set up in a room at the offices of the seller’s solicitors or financial advisers, rather than at the seller's offices. This is to avoid disruption to the seller's business on a day-to-day basis and to keep the transaction confidential from employees. Where a transaction has a multi-jurisdictional element, a number of PDRs can be set up at any one time in each local jurisdiction. A virtual data room (VDR) is an online (often cloud-based) repository and document sharing platform which is set up by the seller to give potential buyers and their advisers access to the documents and information that they need to conduct their due diligence exercise in relation to the target company/target business.
GLOSSARY
These rules, which are drawn up by the seller's solicitors, will govern access to the data room and are, in addition to the confidentiality agreement, a further protection for the seller. Potential buyers will either sign a hard copy of the rules or agree to them via a 'click through' on the platform hosting the VDR. The rules can be amended from time to time by the seller giving notice to the users.