Refine By
Clear all filter
About 91801 results for "*"
PRACTICE NOTES
This Practice Note introduces the general prohibition under Chapter V of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) and Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) on the transfers of personal data outside of the UK or EEA (respectively) or to international organisations. Assimilated law is the name given to retained EU law (REUL) which remains in force after the end of 2023. The re-categorisation of REUL (and associated terms) to assimilated law reflects a change in its status and treatment under UK law, in that it is generally to be interpreted according to ordinary domestic law and principles. From 1 January 2024, REUL is ‘assimilated’ into domestic law by virtue of the fact it is generally stripped of EU-derived interpretive effects (eg supremacy of EU law, directly effective rights, and general principles previously retained under the European Union (Withdrawal) Act 2018). For more information, see Practice Note: Assimilated law and News Analysis:
PRACTICE NOTES
This Practice Note tracks enforcement actions in the UK by the UK Information Commissioner’s Office (ICO) under: • the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) regime (applicable under UK law until the end of the Brexit implementation period at 11 pm UK time on 31 December 2020), and • the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) regime (applicable under UK law from the end of the Brexit implementation period on 31 December 2020) Assimilated law is the name given to retained EU law which remains in force after the end of 2023. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation. Entries may adopt common data protection abbreviations such as DPIA (for data protection impact assessment) and DSAR (data subject access request)—for an introduction to the area and to key terms, see Practice Notes: Data protection law—new starter
CHECKLISTS
The general (ie not specifically related to specialist areas like law enforcement) data protection laws applicable to the UK are: • Assimilated Regulation (EU) 2016/679, UK General Data Protection Regulation (UK GDPR) which is a version of the Regulation (EU) 2016/679, EU General Data Protection Regulation (EU GDPR) as incorporated into UK law following Brexit, and • the parts of the Data Protection Act 2018 that relate to general personal data processing, powers of the Information Commissioner and sanctions and enforcement For further reading, see Practice Note: The UK General Data Protection Regulation (UK GDPR). UK GDPR The UK GDPR imposes obligations on all those who process personal data—both data controllers and data processors. An Insolvency Practitioner (IP) may be both. They will have obligations both by virtue of their appointments and their role in an organisation. In relation to the former, they will process data controlled by the insolvent entity or person and data they collect during their appointment. For more information on how the UK GDPR affects
NEWS
MLex: UK businesses could get more clarity on post-Brexit data protection rules in the coming months as the much-awaited reform of the General Data Protection Regulation (GDPR) inherited from the EU is set to return to parliament on 20 March 2024.
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex
PRECEDENTS
STANDARD CONTRACTUAL CLAUSES SECTION I Clause 1 Purpose and scope   (a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and (ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’) have agreed to these standard contractual clauses (hereinafter: ‘Clauses’). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex
PRECEDENTS
In brief Chapter V (Transfers of personal data to third countries or international organisations) of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) restricts transfers of personal data outside the UK (and to certain ‘international organisations’). One of the most commonly relied on transfer mechanisms for compliance with those international transfer restrictions are commonly called standard contractual clauses (SCCs). This document links to a template SCC published by the UK Information Commission’s Office (ICO) in 2022. The key facts about that template SCC are: Name: International data transfer addendum to the European Commission’s standard contractual clauses for international data transfers (the Addendum) Purpose: An addendum that can be employed to utilise the SCCs issued by the European Commission in June 2021 for use under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) as an SCC transfer mechanism under the UK GDPR. We refer to those EU SCCs as the ‘2021 EU SCCs’. The 2021 EU SCCs
PRECEDENTS
In brief Chapter V (Transfers of personal data to third countries or international organisations) of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) restricts transfers of personal data outside the UK (and to certain ‘international organisations’). Assimilated law is the name given to retained EU law which remains in force after the end of 2023. For more information, see Practice Note: Assimilated law and News Analysis: Implications of the move to ‘assimilated’ law, and the Retained EU Law (Revocation and Reform) Act 2023, for data protection lawyers. One of the most commonly relied on transfer mechanisms for compliance with those international transfer restrictions are commonly called standard contractual clauses (SCCs). This document links to a template SCC published by the UK Information Commission’s Office (ICO) in 2022. The key facts about that template SCC are: Name: International Data Transfer Agreement (IDTA) Purpose: Stand-alone SCC transfer mechanism for compliance with Chapter V of the UK GDPR Validity: From 21 March 2022 Notes: Not
PRACTICE NOTES
This Practice Note tracks the status of adequacy regulations relating to transfers of personal data outside the UK or to international organisations under the United Kingdom General data Protection Regulation, Assimilated Regulation (EU) 2016/679 (the UK GDPR). For a comprehensive introduction to the UK GDPR, collating key practical guidance, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation, and the UK data protection law collection. Background Article 44 of Chapter V of the UK GDPR prohibits the transfer of personal data to a third country outside of the UK, or an ‘international organisation’ (a restricted international transfer). However, a restricted international transfer of personal data may be permitted where the transfer is: • based on an adequacy regulation further to Article 45 of the UK GDPR and related provisions of the Data Protection Act 2018 (DPA 2018) • subject to appropriate safeguards further to Article 46 of the UK GDPR, or • in accordance with specific exceptions/derogations Article 45 of the UK GDPR and DPA 2018, s 17A allow the Secretary
PRECEDENTS
1 In this [clause], UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the United Kingdom’s Information Commissioner, as amended, updated or replaced from time to time. The [insert defined term for party, eg Supplier] shall comply with the Importer’s obligations, and the [insert defined term for party, eg Customer] shall comply with the Exporter’s obligations, set out in the UK Addendum, which is hereby incorporated into and forms part of this Agreement. In such incorporated UK Addendum: 1.1 the full legal name, [trading name (where different from legal name)], main address and official registration number of the Importer and the Exporter are as set out in