Vendor Agreements and the New EU GDPR Steps to Take Now

Size: px
Start display at page:

Download "Vendor Agreements and the New EU GDPR Steps to Take Now"

Transcription

1 Presenting a live 90-minute webinar with interactive Q&A Vendor Agreements and the New EU GDPR Steps to Take Now Complying With the EU General Data Protection and Privacy Regulation TUESDAY, JANUARY 30, pm Eastern 12pm Central 11am Mountain 10am Pacific Today s faculty features: William Long, Partner, Sidley Austin, London, England Lei Shen, Partner, Mayer Brown, Chicago The audio portion of the conference may be accessed via the telephone or by using your computer's speakers. Please refer to the instructions ed to registrants for additional information. If you have any questions, please contact Customer Service at ext. 1.

2 Tips for Optimal Quality FOR LIVE EVENT ONLY Sound Quality If you are listening via your computer speakers, please note that the quality of your sound will vary depending on the speed and quality of your internet connection. If the sound quality is not satisfactory, you may listen via the phone: dial and enter your PIN when prompted. Otherwise, please send us a chat or sound@straffordpub.com immediately so we can address the problem. If you dialed in and have any difficulties during the call, press *0 for assistance. Viewing Quality To maximize your screen, press the F11 key on your keyboard. To exit full screen, press the F11 key again.

3 Continuing Education Credits FOR LIVE EVENT ONLY In order for us to process your continuing education credit, you must confirm your participation in this webinar by completing and submitting the Attendance Affirmation/Evaluation after the webinar. A link to the Attendance Affirmation/Evaluation will be in the thank you that you will receive immediately following the program. For additional information about continuing education, call us at ext. 2.

4 Program Materials FOR LIVE EVENT ONLY If you have not printed the conference materials for this program, please complete the following steps: Click on the ^ symbol next to Conference Materials in the middle of the lefthand column on your screen. Click on the tab labeled Handouts that appears, and there you will see a PDF of the slides for today's program. Double click on the PDF and a separate page will open. Print the slides by clicking on the printer icon.

5 January 30, 2018 Vendor Agreements and the New EU GDPR Steps to Take Now William Long, Partner, Sidley Austin LLP

6 1. GDPR Key Features 6

7 GDPR: Impact of the GDPR Implementation and violation 2018 GDPR adopted in 2016 and will come into force in 2018 GDPR applies to businesses in the EU and any company worldwide that holds data on Europeans Fines of up to 4% of annual worldwide turnover or 20m, whichever is greater Increase in privacy litigation by customers Damages will now be permitted for non-financial loss, e.g., for distress Claims by individuals or representative organisations 7

8 GDPR: Who does it impact? Wide scope and extra territorial effect Data controllers and data processors A data controller determines the purposes and means of the processing of personal data A data processor processes personal data on behalf of a data controller The GDPR will directly impose obligations on data controllers AND processors Extra territorial affect The GDPR will apply to almost all companies established in the EU. The GDPR will also apply to companies processing the personal data of EUbased individuals, even where the company is not established in the EU (e.g., in the U.S.) if they are offering individual in the EU goods or services or monitoring them. All industries affected All types of personal data Financial services, tech companies, life sciences, retail etc. Multinational companies and small businesses Employee data Client data Vendor data Claimant data 8

9 GDPR: A Status Update G-Day: GDPR will come into force on Friday 25 May 2018 What has been published to date? Article 29 Working Party (WP29) has now released final guidelines on: - Privacy Impact Assessments - Data Protection Officers - The Lead Supervisory Authority - Data Portability - Administrative Fines What are we waiting for? We await WP29 guidance on the following topics: Certification Data transfer tools update Implementation of the European Data Protection Board (EDPB) WP29 also released draft guidelines in October 2017 and in December 2017 on: - Profiling and automated decision making - Breach notification Consent Transparency Member State Data Protection Authorities continue to publish guidance on various GDPR topics 9

10 Consents, Notices and Policies Requirements Consents higher standards for consent under the GDPR (e.g, must be unambiguous, granular and involve a clear affirmative action) Existing consents many current consents are unlikely to be valid under the GDPR Notices the GDPR requires additional information to be provided in privacy notices AND that the notices are concise, transparent and easily accessible Actions to comply Review consents determine if other legal grounds can be relied on rather than consent and whether existing consents will be valid under the GDPR Consent mechanisms prepare new GDPR compliant consents with suitable withdrawal mechanisms Notices and policies review and amend privacy notices and related policies to indicate additional information and privacy rights Records keep adequate records of consents obtained and withdrawn 10

11 Compliance with Accountability Principles Requirements Data protection officer (DPO) must be appointed where: the processing requires regular and systematic monitoring of individuals on a large scale; or where processing sensitive personal data on a large scale DPO must advise and monitor compliance with the GDPR, and act as a contact point for the Data Protection Authority (DPA) Actions to comply Determine if required to appoint a DPO and management structure for DPO Develop procedures to ensure accountability for privacy (e.g., privacy impact assessments) under the GDPR Carry out a review of IT Systems and procedures to consider impact of privacy by design and data minimisation requirements on systems Privacy impact assessments must be carried out where data processing uses new technologies and results in high risk to individuals (e.g., profiling) Privacy by design and by default implement technical and organisational measures to ensure privacy (e.g., encryption) AND by default only the minimum amount of personal data are processed 11

12 Information Security Information security, breach reporting and vendors Requirements Implement appropriate technical and organisational measures, to ensure a level of security appropriate to the risk Security breaches must be reported to: (i) the DPA without undue delay and where feasible within 72 hours; and (ii) affected individuals without undue delay where high risk, unless measures taken to minimise risk, e.g., the data is encrypted Data Processors Company is responsible for ensuring processors (e.g. vendors) comply with security measures Actions to comply Review and comply with Company s: (i) information security standards; and (ii) data breach response plan and reporting procedures Conduct a review of key vendor agreements to ensure they include GDPR-compliant data processing provisions Conduct data protection due diligence on key vendors 12

13 GDPR and Data Processors Data controllers and data processors will now have joint and several liability Requirements Maintain a detailed record of processing activities Implement appropriate technical and organisational measures to safeguard data Actions to comply Review data processing agreements and ensure that appropriate data privacy provisions are included as well as provisions dealing with apportionment of liability Appoint a DPO where the threshold is met Notify the controller without undue delay after becoming aware of a data breach Comply with restrictions on international transfers Prior consent must be given by a controller where a data processor appoints a subcontractor and a subcontractor must comply with the same data privacy obligations as the data processor 13

14 Data Subject Rights Requirements Right to erasure a business must erase an individuals personal data in certain circumstances Right to data portability an individual has a right to request the transfer of their personal data from one company to another in certain circumstances Right to object to processing a data subject can object to processing based on the public interest or legitimate interest grounds Right of access individuals have a right to access and obtain copies of their personal data Actions to comply Determine how the new GDPR data privacy rights apply to the business Develop policies and procedures and, if necessary, system changes to deal with these new rights Review consents and notices (e.g., customer privacy policy) and amend to deal with new privacy rights Provide training to relevant staff on how to review and handle privacy requests Right to rectification Individuals have right to have their personal data rectified if it is inaccurate or incomplete Right to restrict processing individuals have right to restrict processing of their personal data 14

15 Big Data & Profiling Requirements Big Data, i.e., the processing of large datasets obtained from multiple sources a catalyst for economic growth, innovation and digitisation European Commission Profiling is any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person! Restrictions new restrictions on business carrying out solely automated profiling that produces legal effects or significantly affects an individual, subject to limited exceptions (e.g., credit scoring and fraud prevention may be affected) Exceptions can only take place if: (i) necessary for the performance of a contract, (ii) authorised by Union or Member State law or (iii) based on consent Actions to comply Review current profiling activities to determine where GDPR profiling restrictions apply Consider what GDPR exemptions to profiling restrictions may apply Review consents and notices to deal with profiling restrictions and the right to object to profiling Big Data Guidance: Article 29 Working Party - Opinion on Purpose Limitation (April 2013) European Data Protection Supervisor - Opinion on Privacy and Competitiveness in the Age of Big Data (March 2014) National Guidance - in July 2014 the UK s Information Commissioner s Office published guidance on the data protection issues raised by the use of Big Data Big Data and Data Protection 15

16 International Data Transfer Requirements Prohibition on transfers of personal data outside EEA to countries that do not provide adequate safeguards (e.g., U.S.) Data transfer solutions are exceptions to the prohibition on international data transfers and include: the new EU-U.S. Privacy Shield applies to transfers of personal data to U.S. companies that are Privacy Shield certified EU Standard Contractual Clauses EU-style data transfer agreements but which are under review by EU Authorities Binding Corporate Rules privacy rules adopted by a group of companies meeting EU standards and approved by EU DPA approved Codes of Conduct or Certification Mechanisms Actions to comply Determine international data flows based on reviews of processing activities and data mapping Review whether current data transfer solutions are adequate Implement data transfer solutions where required 16

17 Lei Shen, Partner, Mayer Brown LLP 2. How Will Companies in the U.S. Be Subject to the GDPR?

18 Data Controllers: Under the EU Directive U.S. companies can become subject to the EU Directive by: Processing data from EU affiliate or EU customer or other EU company Using equipment in the EU but have U.S.-only data For example, as a backup server or using cloud service provider Potential loophole Using only equipment in the U.S. (e.g., website with no cookies) but targeting EU and collecting EU personal data 18

19 Data Controllers: Under the GDPR U.S. companies can become subject to the GDPR by: Processing data from EU affiliate or EU customer or other EU company Offering goods or services to the EU or monitoring the behavior of people in the EU (even if using equipment in the U.S.) Fixes loophole and illogical jurisdiction scenarios 19

20 Data Processors: Under the EU Directive No direct processor obligations under EU Directive Only contractual obligations to the data controller Follow controller s instructions Have appropriate technical and organizational measures in place to protect personal data 20

21 Data Processors: Under the GDPR U.S. companies (data processors) can become subject to the GDPR by processing EU personal data New contractual obligations to the data controller Adds several direct processor obligations, including: Having a DPO if required Recordkeeping requirements Data breach notification obligations Having appropriate data transfer mechanism in place 21

22 3. Performing due diligence on existing technology vendor agreements for GDPR compliance 22

23 Vendor Management Requirements Mandatory terms contracts with data processors must contain the contract terms specified in Article 28 of the GDPR Article 28 provisions include the processor s obligation to: assist the controller with data subjects rights requests; notify the controller of data breaches; assist the controller with privacy impact assessments; flow down data processing obligations to subcontractors; and at the controller s request delete or return all personal data processed on the controller s behalf at the end of the processing activities Actions to comply Scope identify the universe of in-scope GDPR contracts and prioritise Key vendor contracts Templates prepare GDPR compliant data processing provisions Propose appropriate templates to vendors and negotiate GDPR compliant amendments favourable to your business by May 2018 Flow down data processors must flow down the obligations to sub-data processors 23

24 Vendor Due Diligence Requirements Implement appropriate technical and organizational measures to protect personal data Bound by written GDPR-compliant data processing provisions Actions to comply Implement a business-wide vendor management program and incorporate into it a requirement to implement appropriate data processing agreements with the vendors and the development and implementation of a minimum set of vendor security requirements Ensure vendor risk assessment questionnaires have been completed by the vendor Ensure contract contains a detailed description of data processing Review vendor s process to ensure it is in compliance with GDPR obligations Ensure the vendor will allow audits of the processors compliance Review vendor s information security measures and what standards are used 24

25 Vendor Management Information Security Requirements No formal security standard specified by GDPR Actions to comply Ensure vendor has the ability to restore access to data in a timely manner after a security breach Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk Ensure vendor has the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services ISO 27001, ISO or the US NIST framework may be good indicators of appropriate information security measures Ensure vendor conducts a regular testing of technical and organisational measures 25

26 Key Steps with Vendor Management Use of templates and prioritizing vendor contracts Step 1: Prepare vendor contract templates GDPR: Pro-controller, pro-processor, and middle of the road templates Other regulatory laws: e.g., financial services outsourcing rules IP and contracts: e.g., ownership of resultant data Liability: indemnities, exclusions and limits on liability Step 2: Identify universe of inscope vendor contracts Does contract involve the processing of EU-originating personal data? Will it be in effect after May 2018? Step 3: Prioritize certain legacy vendor contracts: Deadline for compliance May 2018; no grandfathering All new in-scope vendor contracts to be GDPR-compliant Determine which legacy contracts get priority 26

27 Key Steps with Vendor Management Vendor contract amendment mechanisms Step 4: Determine the appropriate amendment mechanism Contract-by-contract vs. global approach to amendment? Will amendment be effectively incorporated into contract? Step 5: Propose correct amendment template to vendor Determine whether you are a controller or processor E.g., if a controller, then propose pro-controller template Step 6: Negotiate amendments with vendors Develop negotiation cheat sheets for the legal or procurement team Ensure other contract terms are consistent with amendment (e.g., general confidentiality terms) Ensure contracts assigns responsibility for costs of compliance (e.g., for changes in law, data portability) 27

28 Key Steps with Vendor Management Vendor management as part of a wider GDPR compliance strategy Step 7: Ensure vendor management part of wider GDPR compliance strategy Vendor contracts only a portion of GDPR compliance In turn, consider GDPR within a broader data legal ecosystem regulatory and commercialization -- project 28

29 4. Updating Your Vendor Contracts for the GDPR

30 Key Changes for Using Processors / Vendors Controllers should only select processors who provide sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organizational measures that will meet the requirements of the GDPR Adherence to codes of conduct or approved certification mechanisms may be used as an element to demonstrate compliance Parties must ensure that an adequate transfer mechanism is in place if transferring data out of the EU Contracts with processors must meet the requirements of the GDPR, which contain certain provisions not required by the EU Data Protection Directive 30

31 Key Changes for Processor / Vendor Agreements EU Directive (current requirements) Two contractual requirements: Only act on controller s instructions Implement appropriate technical and organisational security measures EU GDPR Retains and strengthens Directive s contractual requirements: Only act on controller s documented instructions Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk Also adds several new contractual requirements, including but not limited to: Recordkeeping and audits Subcontracting 31

32 Updating Your Vendor Agreements: Required Provisions Contract must set out: Subject matter and duration of processing Nature and purpose of processing Type of personal data and categories of data subjects Obligations and rights of controller Contract must include the following terms: Process only on documented instructions from controller Duty of confidentiality Implementation of appropriate technical and organisational security measures Sub-processing restrictions 32

33 Updating Your Vendor Agreements: Required Provisions (cont.) Contract must include the following terms (cont.): Assistance to enable controller to comply with data subject requests (e.g., right to data portability, right to erasure, etc.) Assistance to enable controller to comply with its obligations in Articles 32 to 36 (i.e., security, notification of data breaches, DPIAs, consultation) Deletion or return of data at end of contract Information to demonstrate compliance Audits and inspections Notification of infringing instructions 33

34 Updating Your Vendor Agreements: Other Provisions to Consider Definitions Recordkeeping Maintain record of categories of processing activities carried out on controller s behalf Comply with cross-border data transfer requirements DPO requirement Data protection by design If applicable, Privacy Shield onward transfer requirements Consider indemnities, limits of liability and other similar clauses to address new risks 34

35 Updating Your Vendor Agreements: Recent Guidance from DPAs Recent Guidance from DPAs: UK s ICO: guidance takes point of view of controller France s CNIL: guidance takes point of view of processor Still a number of unanswered questions For example, how far down the subprocessor chain must a processor flow down obligations? 35

36 Data Breach Notification Data breach notification (for data controllers): Report to the competent Supervisory Authority without undue delay and where feasible not later than 72 hours unless the breach is unlikely to result in a risk to data subjects Describe nature of breach (e.g., categories and number of data subjects, categories of personal data) Name and contact information of the DPO or other contact point Describe consequences of the breach Describe mitigating measures taken or proposed Report to data subjects without undue delay if breach is likely to result in high risk to data subjects May be able to avoid notice to individuals if the controller satisfies the SA that, for example, data are unintelligible or risks have otherwise been mitigated 36

37 Data Breach Notification (cont.) Data breach notification (for data processors): Report to data controller without undue delay after becoming aware of a breach Very broad obligation No risk analysis is given, unlike for data controllers notification obligations Recent guidance from Article 29 Working Party: Awareness of breach Controller Processor Notification of availability breaches 37

38 Comparison of U.S. vs EU Data Breach Obligations Scope Definition of Breach Notification Timeframes U.S. State Data Breach Laws Mostly limited to personal information that could put person at risk for identity theft Typically requires unauthorized access or acquisition of covered information Controller: fastest is 30 days Processor: fastest is 24 hours 38 EU GDPR Covers all personal data, subject to risk analysis accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed Controller: 72 hours to supervisory authority; without undue delay to individuals Processor: without undue delay

39 Comparison of U.S. vs EU Data Breach Obligations Whom to Notify Liability and Fines U.S. State Data Breach Laws Notify affected individuals Notify a variety of state and other agencies (e.g., law enforcement, state attorneys general, credit reporting agencies, etc.) Mostly class action lawsuits Some government enforcement actions EU GDPR Notify affected individuals Notify supervisory authority Fines for not notifying of a data breach can reach 2% of global turnover or 10 million, whichever is higher 39

40 Assess Your International Transfers Data transfer restrictions apply to controllers and processors Current legal instruments to ensure legality of transferring data outside the EU are generally maintained under GDPR Transfer to country with Adequate Protection (same as Directive) OR use of approved means: EU Model Clauses (but with caution Schrems challenge) Binding Corporate Rules (BCRs) Privacy Shield NOT Safe Harbor Derogations (EU Directive derogations continue to apply) Data Subject Consent Approval from Data Protection Authority (DPA) Data Protection Seals 40

41 Assess Your International Transfers: Privacy Shield Replacement mechanism to Safe Harbor that permits transfers of EU personal information to the US Must be subject to jurisdiction of FTC or DOT to self-certify Privacy Shield Principles: Notice; Choice; Accountability for Onward Transfer; Security; Data Integrity and Purpose Limitation; Access; and Recourse, Enforcement and Liability (plus 16 Supplemental Principles) The Onward Transfer principle addresses how Privacy Shield-certified companies must protect personal information that they transfer onto other data controllers or to third-party agents Will need to modify agreements of third parties that receive such data Not easy compliance often requires certain operational, policy and contractual changes 41

42 Questions? 42

Preparing Your Vendor Agreements for the General Data Protection Regulation

Preparing Your Vendor Agreements for the General Data Protection Regulation Preparing Your Vendor Agreements for the General Data Protection Regulation Oliver Yaros Partner - London +44 (0)203 130 3698 oyaros@mayerbrown.com Lei Shen Senior Associate - Chicago +1 312 701 8852 lshen@mayerbrown.com

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Compliance With New EU GDPR: Steps Investment Funds, Banks, Advisers and Financial Intermediaries Should Take Now Revising Service Agreements and

More information

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016 Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016 Do you need to comply? The Regulation will apply to a business processing personal data:

More information

GDPR: What Every MSP Needs to Know

GDPR: What Every MSP Needs to Know Robert J. Scott GDPR: What Every MSP Needs to Know Speaker Robert J. Scott Agenda Purpose GDPR Intent & Obligations Applicability Subject-matter and objectives Material scope Territorial scope New Rights

More information

General Data Privacy Regulation: It s Coming Are You Ready?

General Data Privacy Regulation: It s Coming Are You Ready? General Data Privacy Regulation: It s Coming Are You Ready? Presenters Tristan North Worldwide ERC Government Affairs Adviser, Moderator William R. Tehan General Counsel, Graebel Companies, Inc. Hank A.

More information

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT

INTERNATIONAL WHAT GDPR MEANS FOR RECORDS MANAGEMENT WHAT GDPR MEANS FOR RECORDS MANAGEMENT Presented by: Sabrina Guenther Frigo Overview Background Basic Principles Scope Lawful Processing Data Subjects Rights Accountability & Governance Data Transfers

More information

GDPR is coming in 108 days: Are you ready?

GDPR is coming in 108 days: Are you ready? Charles-Albert Helleputte Partner, Brussels GDPR is coming in 108 days: Are you ready? Diletta De Cicco Legal Consultant, Brussels 6 February 2018 +32 2 551 5982 chelleputte@mayerbrown.com +32 2 551 5974

More information

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond

Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond Data Privacy, Protection and Compliance From the U.S. to Europe and Beyond InsideNGO's 2017 Annual Conference Washington, DC July 20, 2017 Shannon Yavorsky Partner, Venable LLP David Goodman Global Non-

More information

EU GENERAL DATA PROTECTION REGULATION

EU GENERAL DATA PROTECTION REGULATION EU GENERAL DATA PROTECTION REGULATION GENERAL INFORMATION DOCUMENT This resource aims to provide a general factsheet to Asia Pacific Privacy Authorities (APPA) members, in order to understand the basic

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

The New EU General Data Protection Regulation 1

The New EU General Data Protection Regulation 1 The New EU General Data Protection Regulation 1 Dear clients and friends, On 14 April 2016 the EU Parliament formally approved the General Data Protection Regulation ( the Regulation ). The Regulation

More information

International Trademarks: Monitoring, Policing Third-Party Marks, Evaluating Infringements, Pursuing Enforcement

International Trademarks: Monitoring, Policing Third-Party Marks, Evaluating Infringements, Pursuing Enforcement Presenting a live 90-minute webinar with interactive Q&A International Trademarks: Monitoring, Policing Third-Party Marks, Evaluating Infringements, Pursuing Enforcement TUESDAY, NOVEMBER 21, 2017 1pm

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 17/EN WP264 rev.01 Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data Adopted on 11

More information

CNPD Training: Data Protection Basics

CNPD Training: Data Protection Basics CNPD Training: Data Protection Basics The obligations of controllers and processors Esch-sur-Alzette Mathilde Stenersen 7-8 February 2018 Legal service Outline 1. Introduction 2. Basic elements 3. The

More information

SAP and SAP Ariba Solution Support for GDPR Compliance

SAP and SAP Ariba Solution Support for GDPR Compliance Frequently Asked Questions EXTERNAL The General Data Protection Regulation (GDPR) SAP Ariba Source-to-Settle Solutions SAP and SAP Ariba Solution Support for GDPR Compliance The European Union s General

More information

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1

EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 EU General Data Protection Regulation: What Impact for Businesses Established Outside the EU and EEA Francoise Gilbert 1 The EU General Data Protection Regulation (GDPR), which replaces Directive 95/46/EC

More information

GDPR is coming soon. Are you ready. Steven Ringelberg.

GDPR is coming soon. Are you ready. Steven Ringelberg. GDPR is coming soon. Are you ready. Steven Ringelberg steven@ringelberglaw.com 616 227 6403 Agenda Who am I Overview What data do you have that is covered and where is it? What rights do individual data

More information

Preparing for the GDPR

Preparing for the GDPR Preparing for the GDPR Note: These slides and the accompanying presentation contain a general summary and are not legal advice. Niall Rooney 03/11/2017 (1) Data Protection The Right to Data Protection

More information

Introduction to the General Data Protection Regulation (GDPR)

Introduction to the General Data Protection Regulation (GDPR) Introduction to the General Data Protection Regulation (GDPR) #CIPR / @CIPR_UK This guide is worth 5 CPD points Introduction to the General Data Protection Regulation (GDPR) / 2 Contents 1 Introduction

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018

A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 A PRACTICAL GUIDE FOR HOW AN ADVERTISER CAN PREPARE FOR GDPR JANUARY 2018 1 PURPOSE OF THIS DOCUMENT 2 This document is to be used as a guide for advertisers on how they should work with their agencies,

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02]

CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR. Legal02# v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Legal02#67236978v1[RXD02] CHECKLIST FOR TASKS NEEDED IN ORDER TO COMPLY WITH GDPR Notes: We recommend that any business looking to comply with the

More information

Hybrid Corporations: Emerging Business Structures

Hybrid Corporations: Emerging Business Structures Presenting a live 90-minute webinar with interactive Q&A Hybrid Corporations: Emerging Business Structures Evaluating Flexible Purpose, Social Purpose and Benefit Corporations; Legal Considerations for

More information

GDPR Factsheet - Key Provisions and steps for Compliance

GDPR Factsheet - Key Provisions and steps for Compliance GDPR Factsheet - Key Provisions and steps for Compliance Organisations in the Leisure & Hospitality industry hold vast amounts of personal data relating to customers, employees, and suppliers as well as

More information

GDPR & SMART PIA. Wageningen University Feb 2017

GDPR & SMART PIA. Wageningen University Feb 2017 GDPR & SMART PIA Wageningen University Feb 2017 Tips for Action: Anticipate on the new EU General Data Protection Regulation (GDPR) to determine the privacy standards GDPR has been adopted by EU Parliament

More information

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop.

GDPR Webinar 1: Overview of Preparing for the GDPR. T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop. Webinar 1: Overview of Preparing for the T-Minus 441 Days (March 9, 2017) Presenter: Peter Blenkinsop peter.blenkinsop@dbr.com Agenda Introduction (5 mins) Level setting: Brief overview of main provisions

More information

GDPR factsheet Key provisions and steps for compliance

GDPR factsheet Key provisions and steps for compliance GDPR factsheet Key provisions and steps for compliance Organisations hold vast amounts of personal data relating to customers, employees, and suppliers as well as within marketing databases. Compliance

More information

GDPR for Charities. Tuesday 17 October 2017

GDPR for Charities. Tuesday 17 October 2017 GDPR for Charities Tuesday 17 October 2017 Welcome Edward Gleeson, Head of Charities GDPR for the Charity Sector Robert Haniver, Senior Associate Data protection reform General Data Protection Regulation

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

GENERAL DATA PROTECTION REGULATION Guidance Notes

GENERAL DATA PROTECTION REGULATION Guidance Notes GENERAL DATA PROTECTION REGULATION Guidance Notes What is the GDPR? Currently, the law on data protection requiring the handling of data which identifies people to be done in a fair way, is contained in

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

Genera Data Protection Regulation and the Public Sector

Genera Data Protection Regulation and the Public Sector Genera Data Protection Regulation and the Public Sector Tuesday 30 May 2017 @mhclawyers Welcome Edward Gleeson Partner & Head of Public & Administrative Law Mason Hayes & Curran GDPR for Public Bodies

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

EU General Data Protection Regulation in the digital age: Are you ready?

EU General Data Protection Regulation in the digital age: Are you ready? EU General Data Protection Regulation in the digital age: Are you ready? What do you need to know about the new EU General Data Protection Regulation? Data protection has entered a period of unprecedented

More information

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations

Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Getting ready for the new data protection laws A guide for small businesses, charities and voluntary organisations Page 1 of 22 Your business and the new data protection laws Data protection and privacy

More information

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018

EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 EU General Data Protection Regulation ( GDPR ) FAQs External Version - 16 March 2018 This document is a broad overview of the GDPR and does not provide legal advice. We urge you to consult with your own

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) ServiceNow Governance, Risk, and Compliance Table of Contents What is the GDPR?...3 Key Requirements for the GDPR...4 Accountability, Policies,

More information

General Data Protection Regulation Guide

General Data Protection Regulation Guide General Data Protection Regulation Guide TABLE OF CONTENTS Introduction 1 Scope 2 Legal Bases for Data Processing 3 Rights of Individuals 5 Accountability and Governance Mechanisms 7 Data Processor Obligations

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

ACCENTURE BINDING CORPORATE RULES ( BCR )

ACCENTURE BINDING CORPORATE RULES ( BCR ) ACCENTURE BINDING CORPORATE RULES ( BCR ) EXECUTIVE SUMMARY INTRODUCTION Complying with data privacy laws is part of Accenture s Code of Business Ethics (COBE). In line with our COBE, we implement recognized

More information

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR

General Data Protection Regulation Philippe Roggeband. Business Development, Manager, GSSO EMEAR General Data Protection Regulation Philippe Roggeband Business Development, Manager, GSSO EMEAR Why should you care? Data Protection, and compliance with the General Data Protection regulation, is NOT

More information

GDPR Webinar : Overview & practical compliance steps. 23 October 2017

GDPR Webinar : Overview & practical compliance steps. 23 October 2017 GDPR Webinar : Overview & practical compliance steps 23 October 2017 1 Dr Michelle Goddard Director Policy & Communication, EFAMRO Mattias Strandberg Skribent, dagensanalys.se copyright efamro 2010 2 About

More information

GDPR A guide to key articles for security & privacy professionals

GDPR A guide to key articles for security & privacy professionals GDPR A guide to key articles for security & privacy professionals SPONSORED BY TABLE OF CONTENTS 1 5. Introduction 6. Data Protection Principles (Article 5) 7. Transparency and Notice (Article 12) 8. Security

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) 10 Steps For Schools... Introduction The new EU General Data Protection Regulation (GDPR) comes into force in the UK on 25th May 2018. This regulation

More information

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools

SCHOOLS DATA PROTECTION POLICY. Guidance Notes for Schools SCHOOLS DATA PROTECTION POLICY Guidance Notes for Schools Please read this policy carefully and ensure that all spaces highlighted in the document are completed prior to publication. Please ensure that

More information

A guide to GDPR the effect on all UK organisations

A guide to GDPR the effect on all UK organisations A guide to GDPR the effect on all UK organisations Personal Data Penalties Consent Data Breach Notification GDPR Right to Object Data Portability Right to be Forgotten A white paper from Eazipay Ltd October

More information

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018

GDPR: Are You Ready? Mapping the Road to GDPR Compliance. March 2018 GDPR: Are You Ready? Mapping the Road to GDPR Compliance March 2018 Agenda GDPR Overview Should you appoint a DPO? Accountability checklist/documentation required When is consent appropriate and how do

More information

Nissa Consultancy Ltd Data Protection Policy

Nissa Consultancy Ltd Data Protection Policy Nissa Consultancy Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments (DPIA)

More information

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents

TimePlan Education Group Ltd ( the Company ) Data Protection. Date: April Version: 001. Contents Company Name: Document DP3 Topic: ( the Company ) Data Protection Policy Data Protection Date: April 2018 Version: 001 Contents Introduction Definitions Data processing under the Data Protection Laws 1.

More information

Joint Bidding Arrangements With Competitors: Evaluating and Minimizing Antitrust Risks

Joint Bidding Arrangements With Competitors: Evaluating and Minimizing Antitrust Risks Presenting a live 90-minute webinar with interactive Q&A Joint Bidding Arrangements With Competitors: Evaluating and Minimizing Antitrust Risks Avoiding Bid Rigging Allegations and Violations Arising From

More information

GENERAL DATA PROTECTION REGULATION.

GENERAL DATA PROTECTION REGULATION. For the use of mortgage intermediaries and other professionals only. GENERAL DATA HALIFAX INTERMEDIARIES KEY CHANGES GUIDE MAY 2018 REGULATION >SELECT A TILE FOR MORE INFORMATION WHAT IS THE GDPR? KEY

More information

General Data Protection Regulation (GDPR) Key considerations and implications for brokers

General Data Protection Regulation (GDPR) Key considerations and implications for brokers General Data Protection Regulation () Key and implications for brokers Contents at at 03 - did you know? 05 How to handle 07 Considerations for Broker Directors 08 General Data Protection Regulation ()

More information

Data Protection (internal) Audit prior to May (In preparation for that date)

Data Protection (internal) Audit prior to May (In preparation for that date) Data Protection (internal) Audit prior to May 2018. (In preparation for that date) For employers without a dedicated data protection or compliance function, a Data Protection Audit can seem like an overwhelming

More information

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*)

THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) THE GENERAL DATA PROTECTION REGULATION: A BRIEF OVERVIEW (*) The first IBM Personal Computer was introduced just over 35 years ago, on August 12, 1981. The first-generation iphone was introduced in the

More information

December 28, 2018, New Delhi, INDIA

December 28, 2018, New Delhi, INDIA LexArticle December 28, 2018, New Delhi, INDIA GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW GDPR COMPLIANCES BY INDIAN COMPANIES A BRIEF OVERVIEW If you have questions or would like additional

More information

Personal Injury Claims for Uber and Lyft Accidents: Navigating Complex Liability and Insurance Coverage Issues

Personal Injury Claims for Uber and Lyft Accidents: Navigating Complex Liability and Insurance Coverage Issues Presenting a live 90-minute webinar with interactive Q&A Personal Injury Claims for Uber and Lyft Accidents: Navigating Complex Liability and Insurance Coverage Issues WEDNESDAY, JULY 26, 2017 1pm Eastern

More information

Agenda. What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance

Agenda. What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance Agenda What is the GDPR? Who does GDPR apply to? Implications of Non-Compliance The Road to GDPR Compliance What is the GDPR? The General Data Protection Regulation(GDPR) is a European-wide regulation

More information

The General Data Protection Regulation in health & social care. 6 October 2016 Leeds

The General Data Protection Regulation in health & social care. 6 October 2016 Leeds The General Data Protection Regulation in health & social care 6 October 2016 Leeds Session outline 09.05am: Roadmap of the GDPR 10.15am: Coffee break 10.30: GDPR impact: Streetview Employment Rights of

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Energy Benchmarking and Disclosure for Commercial Property: New State and Local Mandates Implications for Construction, Sale, Leasing and Operation

More information

A summary of the implications of the General Data Protection Regulations (GDPR)

A summary of the implications of the General Data Protection Regulations (GDPR) Introduction A summary of the implications of the General Data Protection Regulations (GDPR) 1. The General Data Protection Regulation (GDPR) will apply in the UK from 25 May 2018. Various implications

More information

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems

LAST UPDATED June 11, 2018 DATA PROTECTION POLICY. International Foundation for Electoral Systems LAST UPDATED June 11, 2018 DATA PROTECTION POLICY International Foundation for Electoral Systems 1. Purpose 1.1. International Foundation for Electoral Systems is committed to complying with privacy and

More information

What is GDPR and Should You Care?

What is GDPR and Should You Care? What is GDPR and Should You Care? Ingram Micro Inc. 1 Overview of Privacy Climate & Concerns 2 2 Today We Live In A World Where Advertisers read key words in your Facebook posts and emails and decide what

More information

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company )

RSD Technology Limited - Data protection policy: RSD Technology Limited ( the Company ) RSD Technology Limited - Data protection policy: Introduction Company Name: Document DP3 Topic: RSD Technology Limited ( the Company ) Data Protection Policy Data protection Date: 25 th May 2018 Version:

More information

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you:

Privacy Policy. To invest significant resources in order to respect your rights in connection with Personal Data about you: Privacy Policy Last updated: May 17, 2018 This is the privacy policy (the Policy ) of the website www.experitest.com (the "Website") operated by Experitest Ltd., of 10 HaGavish St, 4250708 Poleg, Israel

More information

BROOKS PERSONAL TRAINING

BROOKS PERSONAL TRAINING BROOKS PERSONAL TRAINING Data Protection Policy Data Protection Policy Lent 2017 0 DATA PROTECTION POLICY Table of Contents: 1. Document Control... 2 2. Introduction... 3 3. General Statement of Scope...

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

Data Privacy Bootcamp: GDPR

Data Privacy Bootcamp: GDPR Data Privacy Bootcamp: GDPR preparing for the general data protection regulation Data Privacy Bootcamp: GDPR Preparing for the General Data Protection Regulation Rebecca Eisner Partner Mayer Brown Oliver

More information

The (Scheme) Actuary as a Data Controller

The (Scheme) Actuary as a Data Controller The (Scheme) Actuary as a Data Controller Keith Webster and Ian Stevens Partners, CMS Cameron McKenna LLP June 2014 Discussion Areas New IFOA guidance Data Protection Act refresher Compliance obligations

More information

Accountability under the GDPR: What does it mean for Boards & Senior Management?

Accountability under the GDPR: What does it mean for Boards & Senior Management? Accountability under the GDPR: What does it mean for Boards & Senior Management? Alan Calder Founder & Executive Chairman IT Governance Ltd 19 January 2017 www.itgovernance.co.uk Introduction Alan Calder

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes

Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes Pensions Authority Data Protection Considerations for Trustees of Occupational Pension Schemes 1 INTRODUCTION The General Data Protection Regulation (GDPR) comes into force in all EU Member States on 25.

More information

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction

1 Privacy by Design: The Impact of the new European Regulation on Data protection. Introduction Introduction On April 2016 the European Parliament approved the General Data Protection Regulation (GDPR). This new regulation, with mandatory implementation by Member States (MS) and businesses that have

More information

What do companies need to do?

What do companies need to do? Briefing GDPR The General Data Protection Regulation ( GDPR ) will come into effect on 25 May 2018. The GDPR will replace the existing data protection laws in all EU member states and is designed to result

More information

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law.

b. by a controller not established in EU, but in a place where Member State law applies by virtue of public international law. Buzescu Ca>Romanian Business Law>Romanian Data Protection Laws 12. ROMANIAN DATA PROTECTION LEGAL REGIME Updated October 2018 The relevant Romanian data protection laws are: European Regulation no. 679

More information

GDPR. Guidance on Employee Personal Data

GDPR. Guidance on Employee Personal Data GDPR Guidance on Employee Personal Data Introduction The General Data Protection Regulation (GDPR), due to come into force on 25 May 2018, will impose significant new burdens on organisations across Europe

More information

The EU GDPR: How Can Information. Governance Policies Help? The EU GDPR:

The EU GDPR: How Can Information. Governance Policies Help? The EU GDPR: The EU GDPR: How Can The EU GDPR: How Can Information Governance Policies Help? Information Governance Policies Help? ACC/IG Committee Webinar Jason R. Baron Peter Blenkinsop Daniel Miller Amie Taal June

More information

Technical factsheet: General Data Protection Regulation (GDPR) April 2018

Technical factsheet: General Data Protection Regulation (GDPR) April 2018 Technical factsheet: General Data Protection Regulation (GDPR) April 2018 1 1 CONTENTS 1. What is GDPR? 2. How is GDPR different to the old Data Protection Act? 3. Why does it apply to members? 4. What

More information

PMI CONSUMER PRIVACY NOTICE

PMI CONSUMER PRIVACY NOTICE PMI CONSUMER PRIVACY NOTICE We take privacy seriously. This notice tells you who we are, what information about you we collect, and what we do with it. Please also read our terms of use relating to the

More information

GDPR Webinar 4: Data Protection Impact Assessments

GDPR Webinar 4: Data Protection Impact Assessments Webinar 4: Data Protection Impact Assessments T-Minus 365 Days (May 25, 2017) Presenters: Peter Blenkinsop peter.blenkinsop@dbr.com Hilary Wandall General Counsel & Chief Data Governance Officer, TRUSTe

More information

GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES

GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES GDPR-CERTIFIED ASSURANCE REPORT BASED PROCESSING ACTIVITIES CERTIFICATION CRITERIA Working draft for public consultation - 29 May 2018 Abstract Document to the attention of organizations that want to obtain

More information

SAFECAP PRIVACY POLICY STATEMENT

SAFECAP PRIVACY POLICY STATEMENT SAFECAP Safecap Investments Limited PRIVACY POLICY STATEMENT This Document on Privacy Policy Statement and Regulatory Protections is effective from 29 January, 2017 and shall remain effective until a more

More information

What you need to know. about GDPR. as a Financial Broker. Sponsored by

What you need to know. about GDPR. as a Financial Broker. Sponsored by What you need to know about GDPR as a Financial Broker Dear Partner The regulatory and compliance environment is ever changing and the burden and requirements on financial services professionals continues

More information

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent

Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: Statement of Intent Data Protection Policy Approved by: COG Approved: 9 August 2017 Review date: August 2019 Version: 4 1. Statement of Intent 1.1 Radian 1 must collect, store and process information about its customers,

More information

NEPA and the Impact of the FAST Act: Navigating the New Permitting and Review Process

NEPA and the Impact of the FAST Act: Navigating the New Permitting and Review Process Presenting a live 90-minute webinar with interactive Q&A NEPA and the Impact of the FAST Act: Navigating the New Permitting and Review Process Leveraging Opportunities Under the National Environmental

More information

GDPR General Data Protection Regulation

GDPR General Data Protection Regulation GDPR General Data Protection Regulation Compliance Information Guide - May 2018 About this document Ticket Arena & Event Genius Disclaimer DISCLAIMER: This is a brief presentation for information purposes

More information

The European Union s General Data

The European Union s General Data The European Union s General Data Protection Regulation Webinar 2 in a series November 14, 2017 Presenters Bret Cohen Partner, Hogan Lovells Julia Funaki Associate Director, AACRAO International Mark McConahay

More information

GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO

GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO GDPR for Employers DUBLIN / BELFAST / LONDON / NEW YORK / SAN FRANCISCO / PALO ALTO 1 Consent Things you need to know about consent and the processing of employees data The EU General Data Protection Regulation

More information

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents

Data Protection Policy. Data protection. Date: 28/4/2018. Version: 1. Contents Company Name: Document: Topic: System People ( the Company ) Data Protection Policy Data protection Date: 28/4/2018 Version: 1 Contents Introduction Definitions Data processing under the Data Protection

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP265 Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data Adopted on 11 April

More information