Refine By
Clear all filter
About 91501 results for "*"
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note explains the lawful bases for processing personal data under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). It assumes a degree of knowledge about EU data protection law. For a general introduction to EU GDPR, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR) and the EU data protection law collection. Note that: • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction • in certain circumstances the EU GDPR has extra-territorial reach which means that it may apply alongside
PRACTICE NOTES
In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on controllers of such processing). ‘Processing’ is broadly defined to include doing most things with data, including storing, deleting, collecting, disclosing or using it. One of the key protections under EEA data protection laws is the set of obligations placed on ‘controllers’ (usually meaning those that decide the purposes and means of processing) and ‘processors’ (those that process personal data on behalf of a controller further to the controller’s instructions). Among other things, EEA data protection laws usually require controllers and processors to put in place contracts containing certain minimum provisions and ensure any processor(s) they engage are suitable. In an outsourcing arrangement, the customer will often act as controller and the supplier as its processor. This Practice Note introduces the requirements
FLOWCHARTS
The EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) is directly applicable and fully enforceable in EU and EEA states. This Flowchart focuses on personal data breach notification under the EU GDPR. It covers: • a summary of the overarching obligations • key guidance • types of personal data breaches • the flowchart of notification requirements • general examples of personal data breaches and who to notify • detailed examples of personal data breaches and who to notify The EU GDPR includes the following definition of a personal data breach: ‘…a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.’ Overarching obligations In summary, among other things, the EU GDPR provides that: • data processors must notify the data controller without undue delay after becoming aware of a personal data breach • unless the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals, the data controller must notify the appropriate supervisory
PRACTICE NOTES
This Practice Note explores issues and best practice relating to the sharing of personal data between controllers (including joint controllers and independent controllers) in general business-to-business commercial situations under the requirements of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). It assumes a degree of familiarity with key data protection concepts and terms and the role of key supervisory organisations. For a general introduction to the EU GDPR and related issues, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief—summary of steps controllers should often take before data sharing The EU GDPR seeks to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. One of the key protections under the EU GDPR is the obligations placed on ‘controllers’ (usually meaning those that decide the purposes and means of processing). ‘Processing’ is broadly defined to include doing most things with data, including storing, deleting, collecting, disclosing or using it. In summary, commercial organisations should generally do the following before the
PRACTICE NOTES
This Practice Note considers the ‘legitimate interests’ lawful basis for processing personal data under Article 6(1)(f) of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), including key guidance on this lawful basis from the European Data Protection Board (EDPB). It assumes a degree of knowledge about EU data protection law. For a general introduction to EU GDPR, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR) and the EU data protection law collection. Note that: • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction • in certain circumstances the EU GDPR has extra-territorial reach, which means that it may apply alongside the requirements of a third country’s data protection laws, see Practice Note: EU GDPR—extra-territorial reach This Practice Note is informed by
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025, pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on the controllers of such processing). Key protections under EEA data protection laws include restrictions on automated individual decision-making (in summary, decision making by automated means, with those data protection laws imposing significant additional protections for data subjects where the decision making occurs in the absence of any meaningful human intervention) and profiling (in summary, automated processing of personal data to evaluate things about a person (which may or may not feature human intervention)). This Practice Note
PRACTICE NOTES
FORTHCOMING CHANGE: This Practice Note reflects the current legislative position, however, note that certain elements will be impacted by the Digital Omnibus proposals published on 19 November 2025 pursuant to the EU Commission’s ‘simplification’ agenda. For more information, see Practice Note: EU Digital Omnibus—tracker. This Practice Note explores the rights provided to individuals whose personal data is processed under the EU’s General Data Protection Regulation (EU GDPR) regime. It assumes a degree of knowledge about EU data protection laws. For a general introduction to those data protection laws, including guidance on key data protection concepts and terminology, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that: • the EU GDPR permits a number of national derogations to the rights of data subjects • this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction This Practice Note explores each
PRACTICE NOTES
The EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) became directly applicable and fully enforceable in EU Member States on 25 May 2018. As the EU GDPR is incorporated into the EEA Agreement and in force in each EEA state, references to EU Member States in the EU GDPR can generally be read to also include EEA members. The main approach to sanctions and enforcement that has been taken under the EU GDPR is to introduce higher penalties for non-compliance in the hopes of producing higher levels of compliance because of the increased penalty provisions and in particular the increased levels of fines for non-compliance—up to the greater of 4% of total global annual turnover or €20m. The EU GDPR also created the European Data Protection Board (EDPB) in an attempt to impose a more consistent application of the EU GDPR and penalties under it. This Practice Note examines: • the approach to sanctions and enforcement under the EU GDPR, including the role of the lead supervisory authority • the role of the
PRECEDENTS
This is a set of Standard Contractual Clauses (SCCs) for compliance with Article 28(3) of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR), governing relationships between controllers and processors and published by the Danish data protection supervisory authority (the Danish SCCs). It was published following an opinion by the European Data Protection Board (EDPB). The Danish SCCs should not be confused with SCCs relating to international personal data transfers under Chapter V of the EU GDPR. Access the Danish SCCs Click the link below to download the agreement from the EDPB’s website: Standard Contractual Clauses for compliance with Article 28(3) of the EU GDPR published by the Danish supervisory authority (the Danish SCCs) Background As detailed in Practice Note: Supply chains under EU GDPR—arrangements between controllers and processors, Article 28(3) of the EU GDPR requires that controllers and processors
PRACTICE NOTES
ARCHIVED: This archived Practice Note introduces the 2001 and 2004 controller to controller and 2010 controller to processor standard contractual clauses (also called Model Clauses or SCCs) approved by the European Commission as applicable under Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). Collectively those SCCs are referred to as the pre-2021 SCCs in this Practice Note. A decision of the Commission published in the Official Journal of the EU on 7 June 2021 had the effect of: • introducing new SCCs approved by the Commission (the 2021 SCCs), which may be used from 27 June 2021 • repealing all the pre-2021 SCCs referred to in this Practice Note with effect from 27 September 2021 (thereby revoking the ability of organisations to use the pre-2021 SCCs in new contracts from that revocation), and • permitting contracts concluded before 27 September 2021 on the basis of the pre-2021 SCCs to continue to be used to provide appropriate safeguards for international transfers under the EU’s General Data Protection
PRACTICE NOTES
This Practice Note explores the origins and practical implications of the requirements to assess levels of protection for data subjects and to implement appropriate supplementary measures, in the context of making a restricted international transfer of personal data relying on Article 46 of Regulation (EU) 2016/679, the EU’s General Data Protection Regulation (EU GDPR). This Practice Note assumes a degree of familiarity with key data protection concepts and terms such as ‘processing’, ‘personal data’, ‘controller’/‘processor’ and ‘data subject’—as well as the role of key supervisory organisations and the international transfer regime under the EU GDPR. For a general introduction to EU data protection law and key terms, see Practice Notes: • Key definitions under EU data protection law • The EU’s General Data Protection Regulation (EU GDPR) • EU GDPR—transfers of personal data internationally and to international organisations Transfer impact assessments (TIAs) are one of the most complex and uncertain aspects of data protection. This Practice Note is therefore layered, with an introductory ‘In brief’ section which gives an overview of TIAs,
PRACTICE NOTES
This Practice Note considers the general prohibition under Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) on the cross-border transfer of personal data outside of the EEA or to an international organisation. Among other things, it considers how to identify a restricted international transfer, onward transfers, data export restrictions, adequacy decisions, standard contractual clauses (Model Clauses or SCCs), Binding Corporate Rules (BCRs) and other appropriate safeguards (ie using Article 46 tools) and derogations. It also includes guidance on amending SCCs and links to further practical guidance on how to use SCCs. In brief Data protection law in the EEA seeks to ensure information about living individuals (ie within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR imposes a large number of obligations on those undertaking or controlling the ‘processing’ of personal data. In summary, ‘processing’ includes doing almost anything with personal data, including storing, sharing, deleting, using or transferring it. One of the key protections under