Refine By
Clear all filter
About 91801 results for "*"
PRECEDENTS
1 In this clause 1, UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the United Kingdom’s Information Commissioner, as amended, updated or replaced from time to time. The [insert defined term for party, eg Supplier] shall comply with the Importer’s obligations, and the [insert defined term for party, eg Customer] shall comply with the Exporter’s obligations, set out in the UK Addendum, which is hereby incorporated into and forms part of this Agreement. In such incorporated UK Addendum: 1.1 the full legal name, [trading name (where different from legal name)], main address and official registration number of the Importer and the Exporter are as set out in
PRECEDENTS
1 In this clause 1, UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the United Kingdom’s Information Commissioner, as amended, updated or replaced from time to time. The [insert defined term for party, eg Supplier] shall comply with the Importer’s obligations, and the [insert defined term for party, eg Customer] shall comply with the Exporter’s obligations, set out in the UK Addendum, which is hereby incorporated into and forms part of this Agreement. In such incorporated UK Addendum: 1.1 the full legal name, [trading name (where different from legal name)], main address and official registration number of the Importer and the Exporter are as set out in [insert where set out in this Agreement], and the Start Date is [insert,
PRECEDENTS
1 In this clause 1, UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the United Kingdom’s Information Commissioner, as amended, updated or replaced from time to time. The [insert defined term for party, eg Supplier] shall comply with the Importer’s obligations, and the [insert defined term for party, eg Customer] shall comply with the Exporter’s obligations, set out in the UK Addendum, which is hereby incorporated into and forms part of this Agreement. In such incorporated UK Addendum: 1.1 the full legal name, [trading name (where different from legal name)], main address and official registration number of the Importer and the Exporter are as set out in [insert where set out in this Agreement], and the Start Date is [insert,
PRACTICE NOTES
This Practice Note discusses the territorial scope of the regime established by the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). It also considers the requirement to appoint UK representatives in certain circumstances. For higher-level introductions to UK data protection law generally, see Practice Notes: Data protection law—new starter guide and The UK General Data Protection Regulation (UK GDPR). The UK data protection law collection collates further general guidance on the UK GDPR regime and is a recommended starting point for research. In brief In summary, and subject to certain exceptions, the UK GDPR may apply: • to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the UK, regardless of whether that processing takes place in the UK or not • the processing of personal data of data subjects who are in the UK by a controller or processor not established in the UK, where the processing activities are related to:
PRACTICE NOTES
This Practice Note examines the approach to sanctions and enforcement under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (the UK GDPR). It considers: • the role and powers of the Information Commissioner (acting through the Information Commissioner’s Office (ICO)) • the ICO's investigative and corrective powers, powers to fine and appeals and safeguards in relation to ICO enforcement action • compensation claims by data subjects • representative and group actions • criminal sanctions • links to guidance tracking the ICO’s enforcement activities • other compliance incentives in practice The main approach to sanctions and enforcement that has been taken under the UK GDPR (as with the EU GDPR) is to retain high penalties for non-compliance, in the hopes of producing higher levels of compliance because of the increased penalty provisions and in particular the increased levels of fines for non-compliance—up to the greater of 4% of total global annual turnover or £17.5m. The Information Commissioner (acting through the ICO) has robust powers to force organisations to act in a compliant manner. The
PRECEDENTS
This current consolidated Data Protection Addendum was published on [insert date]. For previous versions, see [insert URL]. [For details of Updated provisions, see [insert URL].] 1 Definitions 1.1 In this Data Protection Addendum defined terms shall have the same meaning, and the same rules of interpretation shall apply as in the remainder of our Agreement. In addition, in this Data Protection Addendum the following definitions have the meanings given below: Applicable Law • means the following to the extent forming part of the law of United Kingdom (or a part of the United Kingdom) as applicable and binding on either party or the Services: (a) any law, legislation, regulation, byelaw or subordinate legislation in force from time to time; (b) the common law and laws of equity as applicable to the parties from time to time; (c) any binding court order, judgment or decree; or (d) any applicable direction, policy, rule or order made or given by any regulatory body having jurisdiction over a party or any of that party’s assets, resources or business; Controller • has the meaning given to that term in Data Protection Laws; Data Protection
PRACTICE NOTES
This Practice Note explains, in simple terms, the key features of the UK General Data Protection Regulation (UK GDPR). See also Precedent: Data protection quick reference guide—for staff. This Practice Note is intended for non-privacy specialists and there are separate, more detailed, Practice Notes on the UK GDPR, eg: • How to manage data protection compliance • How to process personal data lawfully • How to identify and manage special category personal data • How to manage consent—personal data • Data protection officer (or for law firms: Data protection officer—law firms) • How to undertake data mapping • How to handle data subject requests • How to manage international personal data transfers • How to handle data protection complaints • How to formulate a privacy risk register • How to handle personal data for direct marketing • How to implement data protection by design and default (DPbDD) • How to complete a data protection impact assessment—DPIA • How to manage a personal data breach • How to manage the risks of artificial intelligence in your business The
PRACTICE NOTES
This Practice Note provides a summary of how the application of the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR) regime differs for ‘public bodies’ (as defined in the UK GDPR and also called ‘public authorities’) and other public sector organisations as compared with private sector organisations. Assimilated law is the name given to retained EU law (REUL) which remains in force after the end of 2023. The re-categorisation of REUL (and associated terms) to assimilated law reflects a change in its status and treatment under UK law, in that it is generally to be interpreted according to ordinary domestic law and principles. From 1 January 2024, REUL is ‘assimilated’ into domestic law by virtue of the fact it is generally stripped of EU-derived interpretive effects (eg supremacy of EU law, directly effective rights, and general principles previously retained under the European Union (Withdrawal) Act 2018). For more information, see Practice Note: Assimilated law and News Analysis: Implications of the move to ‘assimilated’ law, and the Assimilated EU Law (Revocation and
PRECEDENTS
These training materials consist of template PowerPoint slides that can be used as the basis of one or more training seminars on the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (the UK GDPR). It is anticipated that those providing training will use these slides as a helpful starting point for their presentations and then amend them accordingly to reflect their particular circumstances. The training materials are customisable. Click the links below to download the training presentation and speaker notes. Contents • What is the UK GDPR? • Terminology • Data protection principles • Material scope • Key exclusions • Territorial scope • Processors • Lawfulness of processing—personal data • Lawfulness of processing—standard of consent • Lawfulness of processing—children • Special categories of personal data • Lawfulness of processing—special
PRACTICE NOTES
This Practice Note provides an in-depth analysis of international transfers under the United Kingdom General Data Protection Regulation, Assimilated Regulation (EU) 2016/679 (UK GDPR). In relation to the subject matter of this Practice Note there are significant similarities between the UK GDPR and the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) and this Practice Note focuses on the position under the UK GDPR. For information about the background to the UK GDPR and its relationship with the EU GDPR, see Practice Note: The UK General Data Protection Regulation (UK GDPR)—Summary of key legislation. For information on similar issues under the EU GDPR, see Practice Note: EU GDPR—transfers of personal data internationally and to international organisations. Note that the rules on international transfers under Chapter V of the UK GDPR regime have been adapted most recently by the Data (Use and Access) Act 2025 (see Practice Note: The Data (Use and Access) Act 2025—Reforms to support international transfers of personal data). For guidance on whether judgments of
NEWS
The UK Government and European Commission have issued a joint statement following a Specialised Committee meeting on Windsor Framework implementation. Key developments include a reduction in sanitary and phytosanitary identity checks from 10% to 8% for the Northern Ireland Retail Movement Scheme, progress on EU access to UK customs IT systems and confirmation that veterinary medicines rules will apply in full from 1 January 2026.
NEWS
The UK Government has announced a Local Growth Fund for Wales worth more than £500m, launching in April 2026 for a three-year period to replace funding previously provided by the European Union. The Welsh and UK Governments have agreed a framework setting priorities and processes for allocating the funds, with decision-making powers transferred to the Welsh Government in accordance with the UK Government's manifesto commitment to restore control over money that previously came from the EU. The Welsh Government will lead development of a delivery plan and Investment Plan for Wales, to be published next year before the fund begins. Local authorities and other partners will have a key role in deciding fund allocation, with the Welsh Government conducting a consultation later this month on optimal fund usage. The fund aims to support employment, skills development, business growth in sectors including health and bio-tech, financial technology, low carbon energy and artificial intelligence, and address growth barriers through investment in key sites, renewable energy generation, energy efficiency and low-carbon transport.