TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

Size: px
Start display at page:

Download "TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients"

Transcription

1 TECHNICAL RELEASE TECH 05/14BL Data Protection Handling information provided by clients

2 ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over 142,000 chartered accountants worldwide. We provide qualifications and professional development, share our knowledge, insight and technical expertise, and protect the quality and integrity of the accountancy and finance profession. As leaders in accountancy, finance and business our members have the knowledge, skills and commitment to maintain the highest professional standards and integrity. Together we contribute to the success of individuals, organisations, communities and economies around the world. This Technical Release reflects consultation with the ICAEW Business Law Committee which includes representatives from public practice and the business community. The Committee is responsible for ICAEW policy on business law issues and related submissions to legislators, regulators and other external bodies. ICAEW 2014 All rights reserved. If you want to reproduce or redistribute any of the material in this publication, you should first get ICAEW s permission in writing. Laws and regulations referred to in this ICAEW Technical Release are stated as at April Every effort has been made to make sure the information it contains is accurate at the time of creation. ICAEW cannot guarantee the completeness or accuracy of the information in this ICAEW Technical Release and shall not be responsible for errors or inaccuracies. Under no circumstances shall ICAEW be liable for any reliance by you on any information in this ICAEW Technical Release. Technical Release ICAEW MM/YYXXX ISBN

3

4 CONTENTS PAGE BACKGROUND Status Introduction What types of information are subject to this Technical Release? In what capacity is Client Data held?... 5 PRACTICAL GUIDANCE Contractual and professional issues Data security Client supervision of security measures Use, relevance and retention of Client Data Telling individuals how their personal data is used Overseas data transfers general principles and inter-office data transfers... 8 APPENDIX 1: DRAFT CONTRACTUAL TERMS AND CONDITIONS... 9 Example Clauses Technical Release 05/14

5 BACKGROUND 1. Status 1.1 Technical Release 05/14 supersedes Tech7/04 which is withdrawn with immediate effect. Technical Release 05/14 is intended to guide you through the specific issues faced by professional accountants in practice and practising firms when handling personal data provided by clients. The guidance should not be relied on by practitioners outside the UK as requirements elsewhere may vary. 2. Introduction 2.1 The Data Protection Act 1998 (DPA) was enacted as part of a wider European framework and all EU member states and the countries of the European Economic Area (EEA) have similar legislation. The DPA protects an individual s personal data and is based upon eight principles which are considered in more detail in Helpsheet Helpsheet 17 Data Protection is issued by ICAEW and is available free of charge to members. It covers general data protection issues including: A more detailed explanation of the data protection principles The notification obligations imposed by the DPA Other issues relevant to personal data held by accountants 2.3 Breaches of the DPA may lead to serious financial and/or reputational damage. This may be through direct fines from the Information Commissioner s Office (ICO) and/or damages payable to individuals or clients, and/or in some instances it could result in a criminal conviction. 3. What types of information are subject to this Technical Release? 3.1 This Technical Release applies to Client Data. This means personal data supplied by clients in connection with a professional engagement. It also includes personal data provided by third parties to a firm in relation to that client s affairs. 3.2 The Technical Release does not apply to Firm Data. This is personal data held by a firm in relation to their own employees or for its own management purposes, which is dealt with more fully in Helpsheet Personal data means all information that relates to a living individual who can be identified either from that information or in conjunction with other information held. 4. In what capacity is Client Data held? 4.1 Data protection laws categorise organisations into those responsible for deciding why and how personal data is used ( data controllers ) and those who simply act on the instructions of another ( data processors ). 4.2 The Information Commissioner has issued guidance 1 that suggests a firm is always a data controller - this can, however, be solely or jointly with the client. This is because the firm will usually have flexibility over the manner in which it provides services to its clients and may not be simply acting on their instructions. A firm can also act as a data processor in circumstances where the relationship suggests close control by the client. However, this categorisation depends on all the circumstances, including factors such as the nature of the services provided and the contractual relationship with the client. At one extreme, a 1 Data controllers and data processors: what the difference is and what the governance implications are, 27 May 2014 TECHINCAL RELEASE 05/14 5

6 firm will be a data controller where it determines both the purpose and means of the processing. Whereas at the other, a firm which relies on the processing instructions as set out in the scope of the engagement terms will more likely be a data processor. Additional considerations apply to insolvency practioners that is beyond the scope of this guidance, but further information can be found on the ICAEW website. 4.3 In practice, these considerations should make little difference to the way Client Data is handled. So long as the rights of individuals are respected, the question of whether the firm acts as data processor or data controller may be less important. Practical steps all firms should take when handing Client Data are set out below and the core requirements for professional confidentiality and integrity will apply in all cases. 4.4 The remainder of this Technical Release is intended to apply regardless of whether or not the firm is a data controller, joint data controller or data processor. However, the distinction does have a number of legal consequences. The most important of these is that only data controllers (including joint data controllers) are subject to the DPA. Therefore, regulatory sanctions cannot be imposed on a firm by the Information Commissioners Office if it acts as data processor, though data processors might still be subject to reputational damage, professional disciplinary action and be liable for damages to clients. Therefore, in some cases, firms may wish to seek legal advice on this topic in light of the Information Commissioner s guidance and based on their own particular circumstances. PRACTICAL GUIDANCE 5. Contractual and professional issues 5.1 Firms should structure engagements in a way that: Accurately records the contractual relationship between the parties Apportions the responsibilities for dealing with individuals Complies with the DPA and all applicable professional ethics and standards Keeps the information secure 5.2 Suggested terms and conditions for engagement letters are contained in Appendix 1. The wording can be used regardless of whether the firm is a data controller or data processor. 5.3 Where a firm provides Client Data to third parties as part of an engagement, it should ensure such disclosures are authorised by the client and that the information will be subject to appropriate protections once it is in the hands of the third party. 6. Data security 6.1 A firm must ensure Client Data is held securely. This is as much a matter of professional conduct as it is a necessary part of DPA compliance. 6.2 A firm should implement technical and procedural measures. In establishing those measures, a firm may consider what is proportionate and appropriate to its circumstances, such as the nature of the personal data held and the harm that may result from a security breach. 6.3 The examples below describe some technical measures firms should consider to comply with the security obligations under the DPA: Encrypt electronic data on laptops and memory sticks; Encrypt attachments if they contain substantial amounts of personal data; 6 Technical Release 05/14

7 DATA PROTECTION- HANDLING INFORMATION PROVIDED BY CLIENTS Shred and dispose of hard copy documents appropriately; Store backup copies of data securely and separately from live files; Destroy backup data once it is unnecessary to retain it; Ensure passwords are changed regularly and are only known to personnel authorised to access the personal data. 6.4 The examples below describe some of the other measures firms should consider to comply with the security obligations under the DPA: Provide training to employees regarding their specific responsibilities and the firm s wider responsibilities under the DPA; Designate an information security officer with responsible for information security; Ensure that the firm s sub-contractors and suppliers also keep personal data secure; Control physical access to buildings and rooms to ensure that only authorised personnel may enter; Ensure sufficient protections against burglary, fire and natural disaster; Protect data from casual passers-by (ie, offices with visibility through windows, presentations at client offices); Enforce a clear desk policy. 6.5 Firms should review these measures on a regular basis. 7. Client supervision of security measures 7.1 Where the firm acts as data processor, the client has regulatory responsibility for the firm s actions. In particular, the client must ensure the firm keeps Client Data secure. 7.2 To satisfy this obligation, the client will need a written contract with the firm that obliges the firm to act only on the client s instructions and keep Client Data secure. Appendix 1 contains suitable wording. 7.3 Clients may also try to impose additional obligations on firms, such as requiring a firm to encrypt Client Data. Firms will need to consider if they are in a position to comply with those obligations. One particular problem is where the client asks to audit the firm s technical and organisational security measures. There is no strict requirement on the client to carry out an audit so it may be more appropriate for a firm to provide information about its security measures instead. Where a firm agrees to an audit request it must comply with the confidentiality duties owed to other clients as a matter of professional conduct and ensure that those duties are not breached. 8. Use, relevance and retention of Client Data 8.1 The firm should only use the Client Data for the provision of services to the client and not for its own purposes. For example, it would almost certainly be professionally inappropriate and a breach of the DPA to use a client s customer data for the firm s own marketing purposes. 8.2 The firm should ensure the Client Data it accesses or uses to provide services is appropriate. If the client provides Client Data that is clearly inappropriate or not relevant to the services provided by that firm, the firm should discuss the matter with the client with a view to limiting the amount of Client Data provided in the future. This is particularly the case if the Client Data contains sensitive personal data, for example medical information, criminal records or information about an individual s sexual preferences. Technical Release 05/14 7

8 8.3 The firm should consider how long it keeps copies of Client Data. Client Data should be destroyed or returned to the client once it is no longer needed, subject to any other legal or professional duties to keep copies of that data. 9. Telling individuals how their personal data is used 9.1 The DPA imposes a general obligation to tell individuals who holds their personal data and what it is being used for. This is often done by means of a privacy notice which can be provided to individuals in hardcopy or electronic form or published on the firm s or its client s website. No prescribed form exists for an accountancy firm, but it should correspond with the purposes noted in the firm s registration with the ICO and the engagement terms. 9.2 For Client Data, it will normally be more appropriate for the client to be responsible for this obligation as it has the relationship with the underlying individuals. 9.3 This obligation is also relevant for Firm Data, for example advising staff on how and why personal data is collected and processed; further guidance is in Helpsheet Individuals also have a legal right to access copies of their personal data. Where such a request is made to a firm in respect of Client Data, the firm should normally inform the client. Responding to requests can be complex so the firm should consult with the client and may also wish to obtain legal advice. It is also important to deal with the request in a timely manner as a response must be provided to the individual promptly and, in any event, within 40 days. Accordingly, firms may wish to clarify with their clients in advance each party s responsibilities and expectations in order to comply with such a request. 10. Overseas data transfers general principles and inter-office data transfers 10.1 The DPA allows overseas data transfers in certain circumstances, the most common of which are: To a country within the EEA 2 ; To a country deemed by the European Commission to have an adequate level of data protection requirements 3 ; Made using European Commission approved model clauses or Binding Corporate Rules; or To a US organisation which is certified with the US Safe Harbor 4 scheme If these do not apply, the transfer may still be made if the firm is able to rely on another justification such as satisfying one of the conditions in Schedule 4 of the DPA. This is a complex area of law and the solution adopted varies depending on whether the firm acts as data controller or data processor. In many circumstances firms will need to seek specialist legal advice where looking to transfer personal data outside of the UK, for their own protection. For example, where firms are subcontracting book-keeping functions abroad, they will need to ensure that appropriate due diligence has been undertaken to check that the subcontractor has appropriate standards of integrity and adequate systems for data protection, as well as that there are appropriate contractual terms in place. 2 List available at 3 List available at 4 List available at 8 Technical Release 05/14

9 DATA PROTECTION- HANDLING INFORMATION PROVIDED BY CLIENTS APPENDIX 1: DRAFT CONTRACTUAL TERMS AND CONDITIONS Note: These clauses are examples rather than ICAEW requirements. They do not specify whether the firm acts as data controller or data processor. Firms with a particular desire to act in one or other capacity may wish to amend these clauses accordingly. These clauses also assume that there is a separate confidentiality clause under which the firm undertakes to use the client s information only for the purpose of providing services to that client or as otherwise required by law. Example Clauses This clause applies to personal data provided by, or on behalf of, [CLIENT] in connection with this Agreement or any Engagement Letter. Each party shall comply with the Data Protection Act 1998 (DPA) when processing such personal data. In particular, [CLIENT] shall ensure that any disclosure of personal data to [ACCOUNTANT] complies with the DPA. [ACCOUNTANT] shall use appropriate technical and organisational measures to protect against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data. [ACCOUNTANT] shall not sub-contract any processing of personal data unless that personal data continues to be subject to an appropriate level of protection. To the extent [ACCOUNTANT] acts as data processor for [CLIENT], it shall only process personal data in accordance with [CLIENT S] instructions. [ACCOUNTANT] shall notify [CLIENT] in [X] working days in the event of an individual asking for copies of their personal data, a complaint about processing of personal data or a notice from a relevant Data Protection Authority. [CLIENT] and [ACCOUNTANT] shall consult and co-operate with each other when responding to any such request, complaint or notice. [ACCOUNTANT] shall answer [CLIENT] reasonable enquiries to enable [CLIENT] to monitor compliance with this clause. Technical Release 05/14 9

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

Data Protection Policy

Data Protection Policy Reference: Date Approved: April 2015 Approving Body: Board of Trustees Implementation Date: August 2015 Supersedes: 2.0 Stakeholder groups Governance Committee, Board of Trustees consulted: Target Audience:

More information

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018

Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Breakthrough Data Protection Policy Approved by Lead Organisation: November 2017 Next Review Date: November 2018 Introduction The Partner organisations within the Breakthrough Programme need to collect

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

Data Protection Policy

Data Protection Policy THE CIPPENHAM SCHOOLS TRUST Data Protection Policy *Date for revision: Summer Term 2018 Responsibility for policy: Responsibility for operational: Trustees Trustees Reviewed by Directors: *subject to any

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

General Personal Data Protection Policy

General Personal Data Protection Policy General Personal Data Protection Policy Contents 1. Scope, Purpose and Users...4 2. Reference Documents...4 3. Definitions...5 4. Basic Principles Regarding Personal Data Processing...6 4.1 Lawfulness,

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY LEEDS BECKETT U NIVERSI T Y DATA PROTECTION POLICY 1. INTRODUCTION 1.1 This policy document explains the framework through which the University ensures compliance with the Data Protection Act 1998 (DPA).

More information

The (Scheme) Actuary as a Data Controller

The (Scheme) Actuary as a Data Controller The (Scheme) Actuary as a Data Controller Keith Webster and Ian Stevens Partners, CMS Cameron McKenna LLP June 2014 Discussion Areas New IFOA guidance Data Protection Act refresher Compliance obligations

More information

General Data Protection Regulation (GDPR) Frequently Asked Questions

General Data Protection Regulation (GDPR) Frequently Asked Questions General Data Protection Regulation (GDPR) Frequently Asked Questions 26 March 2018 0 Contents Introduction... 3 What is GDPR?... 3 Who does the GDPR apply to?... 3 Are tax advisers data controllers or

More information

Data Protection/ Information Security Policy

Data Protection/ Information Security Policy Data Protection/ Information Security Policy Date Policy Reviewed 27 th April 2016 Date Passed to Governors: 27 th April 2016 Approved by Governors: 7 th June 2016 Date of Next Review: June 2018 Data Protection

More information

APM Code of. Professional Conduct

APM Code of. Professional Conduct APM Code of Professional Conduct APM Code of Professional Conduct All leading professional bodies, such as APM, have a code of conduct to set standards, guide the member and raise the level of trust and

More information

Data Protection. Policy

Data Protection. Policy Data Protection Policy Why do we need this policy? What does the policy apply to? Which parts of SQA are affected? SQA is committed to adopting best practice in protecting the personal information of all

More information

Data Protection Policy & Procedures

Data Protection Policy & Procedures Data Protection Policy & Procedures Scope In this document, the terms we, us, our and/or Clear Sky refer to Clear Sky Children s Charity. The term you and/or your refer to all employees of Clear Sky, who

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Name of Chair: Mr David Mann Name of Headteacher: Mrs Eileen Bissell Name of person Responsible: Mrs Eileen Bissell Adopted and Agreed on: October 2015 Date of Review: October 2018

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

British Computer Society. Code of Conduct. Code of Conduct 5 SEPTEMBER 2001 VERSION 2.0

British Computer Society. Code of Conduct. Code of Conduct 5 SEPTEMBER 2001 VERSION 2.0 British Computer Society British Computer Society INTRODUCTION This Code sets out the professional standards required by the Society as a condition of membership. It applies to members of all grades, including

More information

Data Protection Policy

Data Protection Policy Data Protection Policy University of London Data Protection UoL website link: http://www.london.ac.uk/238.html Email: records.managament@london.ac.uk Contents 1 Policy statement... 3 2 Introduction and

More information

Code of Ethics for Financial Advisers

Code of Ethics for Financial Advisers Financial Adviser Standards and Ethics Authority Code of Ethics for Financial Advisers Exposure Draft of Proposed Standard CONSULTATION OPEN Exposure Draft issued March 2018 Consultation closes 1 June

More information

Auditing of Swedish Enterprises and Organisations

Auditing of Swedish Enterprises and Organisations Auditing of Swedish Enterprises and Organisations March 1st 2018 version 2018:1 1 General Application 1.1 These General Terms govern the relationship between the auditor ( the Auditor ) and the client

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY 1. Introduction This policy sets out how The Robert Gordon University shall comply with the requirements of the Data Protection Act 1998 and was created with reference to the JISC

More information

Board Charter Z Energy Limited

Board Charter Z Energy Limited Board Charter Z Energy Limited Z Energy Limited ( Z Energy ) is committed to the highest standards of corporate governance. This Board Charter ( Charter ) is the foundation document which sets out the

More information

General Data Protection Regulation. The changes in data protection law and what this means for your church.

General Data Protection Regulation. The changes in data protection law and what this means for your church. General Data Protection Regulation The changes in data protection law and what this means for your church. 1 Contents Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 18 Page 20 Page 23

More information

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery

Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Data Protection Act Policy And Operational Procedures For the Trust, Its Academies, And Essa Nursery Date approved by the Board of Directors: 7 July 2017 Date adopted by Essa Academy Local Governing Body:

More information

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent

Policy Document for: Data Protection (GDPR) Approved by Directors: September Due for Review: September Statement of intent Policy Document for: Data Protection (GDPR) Approved by Directors: September 2017 Due for Review: September 2020 1. Statement of intent Timu Academy Trust is required to keep and process certain information

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 13 INFORMATION GOVERNANCE POLICY EXECUTIVE SUMMARY Key Messages Principles of Information Governance Openness Confidentiality and Legal Compliance Information Security

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

The Sage quick start guide for businesses

The Sage quick start guide for businesses General Data Protection Regulation (GDPR): The Sage quick start guide for businesses Contents Introduction 3 Infographic: GDPR at a Glance 4 The basics 5 The GDPR in summary 5 Individual rights and informing

More information

Section 22. Scope of section. Accreditation. Eligibility Criteria

Section 22. Scope of section. Accreditation. Eligibility Criteria Section 22 Accreditation of Audit Firms, Reporting Accountants, Reporting Accountant Specialists and IFRS Advisers to provide accounting and/or advisory services to applicant issuers Scope of section The

More information

Auditing data protection

Auditing data protection Data protection Auditing data protection a guide to ICO data protection audits 1 Contents Executive summary 3 1. Audit programme development 5 Audit planning and risk assessment 2. Audit approach 6 Gathering

More information

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?...

Introduction Why is data protection important? How does it apply to volunteers? What volunteers need to do?... Data Protection Guidance for Volunteers Last update 26/11/17 Contents Introduction... 2 1. Why is data protection important?... 2 2. How does it apply to volunteers?... 2 3. What volunteers need to do?...

More information

Annexure B Section 22

Annexure B Section 22 Annexure B Section 22 Accreditation of Audit Firms, Reporting Accountants, Reporting Accountant Specialists and IFRS Advisers to provide accounting and/or advisory services to applicant issuers Scope of

More information

Practice Note 8 Engineers and Ethical Obligations

Practice Note 8 Engineers and Ethical Obligations www.ipenz.nz Practice Note 8 Engineers and Ethical Obligations Engineering Practice ISSN 1176-0907 Version 2, October 2016 Preface The purpose of the Practice Note Engineers and Ethical Obligations is

More information

Data Protection Audit Self-assessment toolkit

Data Protection Audit Self-assessment toolkit Data Protection Audit Self-assessment toolkit online preferences security passport details emergency contact details blood group email account number accuracy CCTV images tax records rights payroll number

More information

Kyte Broking Ltd. Conflicts of Interest Policy Summary Statement. Page 1 of 9

Kyte Broking Ltd. Conflicts of Interest Policy Summary Statement. Page 1 of 9 Kyte Broking Ltd Conflicts of Interest Policy Summary Statement Page 1 of 9 Table of Contents Page 1. Introduction... 3 2. Purpose and Summary of Policy... 3 3. Clients and counterparties... 4 4. What

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title: Data Protection Policy Ref:CP005 Version:2 Approval Body: Corporation via Audit & Risk Committee Date:24th March 2015 Review Date: 24th March 2018 Lead Person: Director, Institutional Effectiveness

More information

BOARD CHARTER Introduction Company Board Responsibilities

BOARD CHARTER Introduction Company Board Responsibilities BOARD CHARTER Introduction The directors are accountable to the shareholders and must ensure that Ausdrill Limited ( Company ) is appropriately managed to protect and enhance the interests and wealth of

More information

Terms of Reference. Quality and Value Audits

Terms of Reference. Quality and Value Audits Terms of Reference Quality and Value Audits Table of Contents SECTION 1 General 3 1.1 Introduction 3 1.2 Statutory authority 3 1.3 Purpose and Scope 4 SECTION 2 Methodology 6 2.1 The audit programme 6

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 17/EN WP264 rev.01 Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data Adopted on 11

More information

Regulates the way data controllers process personal data

Regulates the way data controllers process personal data GUIDANCE NOTE ON THE DATA PROTECTION ACT 1998 This guidance note gives an overview of how the Data Protection Act 1998 (the Act ) applies to clubs (including class associations) and recognised training

More information

Qualified Persons in the Pharmaceutical Industry. Code of Practice. March 2008

Qualified Persons in the Pharmaceutical Industry. Code of Practice. March 2008 Qualified Persons in the Pharmaceutical Industry Code of Practice March 2008 Updated October 2009 Code of Practice for Qualified Persons 1. INTRODUCTION... 1 2. REGULATORY BASIS FOR THE QUALIFIED PERSON...

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice ICO lo Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 About this code... 3 Chapter 1 - Introduction to PIAs... 5 What the ICO means by PIA...

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Insert here the logo of the signatory organisation Review date November 2016 Version No. V07 Internal Ref: ERYC CFS ILS 02 Humber Information Sharing Charter This Charter may be an

More information

POLICY. Descriptors : 1) Conduct 2) Behaviour 3) Ethics 4) Rules

POLICY. Descriptors : 1) Conduct 2) Behaviour 3) Ethics 4) Rules POLICY Policy Title: Code of Conduct Descriptors : 1) Conduct 2) Behaviour 3) Ethics 4) Rules Category : Human Resources Intent Organisational Scope Definitions Policy Content References Contact Information

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 05/EN WP108 Working Document Establishing a Model Checklist Application for Approval of Binding Corporate Rules Adopted on April 14 th, 2005 This Working Party

More information

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION

WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) WHAT PAYROLL PROFESSIONALS NEED TO KNOW ABOUT THE GENERAL DATA PROTECTION REGULATION (GDPR) Published by: The

More information

Review of agreed-upon procedures engagements questionnaire

Review of agreed-upon procedures engagements questionnaire Review of agreed-upon procedures engagements questionnaire Review code Reviewer Review date Introduction Standards on Related Services (ASRSs) detail the responsibilities of an assurance practitioner,

More information

General Data Protection Regulation (GDPR) A brief guide

General Data Protection Regulation (GDPR) A brief guide General Data Protection Regulation (GDPR) A brief guide Document compiled by: Terence Clark & Dr. Nathan Matthews June 2017 Acknowledgements This document contains material from the Information Commissioner

More information

PostNL group procedure

PostNL group procedure 1 January 2017 PostNL Holding B.V. Audit & Security PostNL group procedure on fraud prevention guidance on bribery and corruption Author Director Audit & Security Title PostNL group procedure on Fraud

More information

Amended Sections (Clean)

Amended Sections (Clean) Amended Sections (Clean) Section 1 Censure and penalties 1.20 Where the JSE finds that an applicant issuer or any of an applicant issuer s director(s), officer(s) and/or depository, as defined, has contravened

More information

Discipline Policy and Procedure. Adopted by the Trust Board on 6 December 2016

Discipline Policy and Procedure. Adopted by the Trust Board on 6 December 2016 Discipline Policy and Procedure Adopted by the Trust Board on 6 December 2016 1 P a g e Whole Trust Discipline Policy and Procedure Contents 1. Purpose... 2 2. General Principles... 2 3. Acceptable Behaviour

More information

Data Protection Policy

Data Protection Policy HOLY TRINITY CE (VA) PRIMARY SCHOOL Data Protection Policy Learning and caring together, building a firm foundation for the future. FOUNDED 1865 Date of Last Review: July 2015 Date to be Revisited: July

More information

Privacy Policy PURPOSE SCOPE POLICY. Data Collection

Privacy Policy PURPOSE SCOPE POLICY. Data Collection Privacy Policy PURPOSE 1. To ensure Training & Assessment Mentor maintains the privacy of personal information provided to Training & Assessment Mentor from Staff and Students. SCOPE 2. This document describes

More information

Field/Mobile Working Policy

Field/Mobile Working Policy Field/Mobile Working Policy Management Guidance This document sets out UKRI Field/Mobile Working Policy, which is contractual. It also provides additional guidance for managers, employees and HR in the

More information

Casework Technical Support (Social Welfare - Project Management)

Casework Technical Support (Social Welfare - Project Management) Casework Technical Support (Social Welfare - Project Management) Request for Tenders for Services to MABS NATIONAL DEVELOPMENT The latest date for receipt of tenders is 09 June 2017 Commercial House Westend

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY APRIL 2018 Attendance Policy and Procedures (Pupils) (P3/Policies) Updated January 2018 Page 1 of 11 Title Summary Purpose Operational Date April 2018 Next Review Date April 2019

More information

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry 1 Contents Introduction 5 Brexit: GDPR or New UK Law? 8 The eprivacy Directive 10 The GDPR: 10 Key Areas

More information

How employers should comply with GDPR

How employers should comply with GDPR 02 Mind your business Prepare for GDPR How employers should comply with GDPR Recommendations for employer compliance with GDPR The scope of the impact of the GDPR cannot be overstated. The GDPR will impact

More information

Guidance on the Application. of ISO / IEC Accreditation International Association for Certifying Bodies

Guidance on the Application. of ISO / IEC Accreditation International Association for Certifying Bodies Accreditation International Association for Certifying Bodies Guidance on the Application of ISO / IEC 17020 Guidance on the Application of ISO/IEC 17020 Page 1 of 16 Introduction This guidance document

More information

Vendor Agreements and the New EU GDPR Steps to Take Now

Vendor Agreements and the New EU GDPR Steps to Take Now Presenting a live 90-minute webinar with interactive Q&A Vendor Agreements and the New EU GDPR Steps to Take Now Complying With the EU General Data Protection and Privacy Regulation TUESDAY, JANUARY 30,

More information

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016

Dealing with the EU Data Protection Regulation in Practice. William Long, Partner Sidley Austin LLP February 11, 2016 Dealing with the EU Data Protection Regulation in Practice William Long, Partner Sidley Austin LLP February 11, 2016 Do you need to comply? The Regulation will apply to a business processing personal data:

More information

Cloud Computing Policy and Guidelines Release: 1.51

Cloud Computing Policy and Guidelines Release: 1.51 Cloud Computing Policy and Guidelines Release: 1.51 1. Introduction This document sets out the College s policy for the use of cloud computing services, also known as cloud computing, cloud services or

More information

International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation

International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation International Standard on Auditing (Ireland) 402 Audit Considerations Relating to an Entity using a Service Organisation MISSION To contribute to Ireland having a strong regulatory environment in which

More information

SIGBI DATA PROTECTION PROTOCOLS 2018

SIGBI DATA PROTECTION PROTOCOLS 2018 SIGBI DATA PROTECTION PROTOCOLS 2018 For the purpose of this document, references to Soroptimist International Great Britain and Ireland (SIGBI) Limited and Soroptimist International may be written as

More information

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey

GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey www.nascenta.com GDPR readiness for start-ups, technology businesses and professional practices Martin Cassey Introduction GDPR Key Points GDPR/DPA Differences Start Up, Tech Business Professional Practice?

More information

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER

PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER PREPARING YOUR ORGANISATION FOR THE GENERAL DATA PROTECTION REGULATION YOUR READINESS CHECKLIST DATA PROTECTION COMMISSIONER 1 What will the GDPR mean for your business/organisation? On the 25 th May 2018,

More information

THE UNIVERSITY OF NEWCASTLE TERMS AND CONDITIONS FOR CONSTRUCTION TENDERING

THE UNIVERSITY OF NEWCASTLE TERMS AND CONDITIONS FOR CONSTRUCTION TENDERING THE UNIVERSITY OF NEWCASTLE TERMS AND CONDITIONS FOR CONSTRUCTION TENDERING Instructions for the Tenderer: It is mandatory for the Tenderer to provide and/or perform the following in relation to the compilation

More information

Dated July 2017 ALTUS STRATEGIES PLC. ( Company ) SOCIAL MEDIA POLICY

Dated July 2017 ALTUS STRATEGIES PLC. ( Company ) SOCIAL MEDIA POLICY Dated July 2017 ALTUS STRATEGIES PLC ( Company ) SOCIAL MEDIA POLICY Tel +44 (0)370 903 1000 Fax +44 (0)370 904 1099 mail@gowlingwlg.com www.gowlingwlg.com CONTENTS Clause Heading Page 1 ABOUT THIS POLICY...

More information

CANDIDATE DATA PROTECTION STANDARDS

CANDIDATE DATA PROTECTION STANDARDS CANDIDATE DATA PROTECTION STANDARDS I. OBJECTIVE The aim of these Candidate Data Protection Standards ( Standards ) is to provide adequate and consistent safeguards for the handling of candidate data by

More information

General Data Privacy Regulation: It s Coming Are You Ready?

General Data Privacy Regulation: It s Coming Are You Ready? General Data Privacy Regulation: It s Coming Are You Ready? Presenters Tristan North Worldwide ERC Government Affairs Adviser, Moderator William R. Tehan General Counsel, Graebel Companies, Inc. Hank A.

More information

... FOR IN-HOUSE LAWYERS. Law Society of New South Wales In-House Lawyers Committee Handy hints for in-house lawyers 1

... FOR IN-HOUSE LAWYERS. Law Society of New South Wales In-House Lawyers Committee Handy hints for in-house lawyers 1 ... FOR IN-HOUSE LAWYERS Law Society of New South Wales In-House Lawyers Committee 1 AIM In-house lawyers are subject to the same ethical rules as private practitioners. However, in-house lawyers face

More information

A Firm s System of Quality Control

A Firm s System of Quality Control A Firm s System of Quality Control 2759 QC Section 10 A Firm s System of Quality Control (Supersedes SQCS No. 7.) Source: SQCS No. 8; SAS No. 122; SAS No. 128. Effective date: Applicable to a CPA firm's

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY APPENDIX. DATA PROTECTION POLICY Document Status Author Director of Registry Services (Data) Date of Origin 27 th July 2011 This Version July 2014 Review requirements Date of next review July 2016 Approval

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

Whistle Blowing (Draft)

Whistle Blowing (Draft) Whistle Blowing (Draft) Document Detail Type of Document (Stat Policy/Policy/Procedure) Policy Category of Document (Trust HR-Fin-FM-Gen/Academy) HR Index reference number Approved 30/03/17 Approved by

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

CODE OF PRACTICE Emergency Short-Term Appointments to Positions in the Health Service Executive

CODE OF PRACTICE Emergency Short-Term Appointments to Positions in the Health Service Executive CODE OF PRACTICE Emergency Short-Term Appointments to Positions in the Health Service Executive PUBLISHED IN 2017 BY THE COMMISSION FOR PUBLIC SERVICE APPOINTMENTS, 18 LOWER LEESON STREET, DUBLIN 2, D02

More information

GENERAL ORDER NO 23 MANAGEMENT OF PERSONNEL RECORDS

GENERAL ORDER NO 23 MANAGEMENT OF PERSONNEL RECORDS Independent State of Papua New Guinea GENERAL ORDER NO 23 MANAGEMENT OF PERSONNEL RECORDS Being a General Order for the purpose of requiring agency heads to maintain organised and systematic personnel

More information

Getting Ready for the GDPR

Getting Ready for the GDPR Getting Ready for the GDPR Ann Cartwright Information Governance Lead Sefton Council for Voluntary Service (CVS) Registered Charity No. 1024546. Company Limited by Guarantee No. 2832920. Suite 3B, 3rd

More information

TruckSafe Operator Business Rules and Code of Conduct

TruckSafe Operator Business Rules and Code of Conduct Operator Business Rules and Code of Conduct Contents 1.0 Business Rules and Code of Conduct 3 2.0 Decision Making Bodies 4-6 3.0 Purpose 6 4.0 How the Rules will be amended 6 5.0 Introduction 6 6.0 Entry

More information

SAI Global Full Service Team

SAI Global Full Service Team General information regarding elements of the certification process is described below. A degree of flexibility and options in the certification process are available so please feel free to contact us

More information

Standards for Investment Reporting

Standards for Investment Reporting January 2006 Standards for Investment Reporting 4000 INVESTMENT REPORTING STANDARDS APPLICABLE TO PUBLIC REPORTING ENGAGEMENTS ON PRO FORMA FINANCIAL INFORMATION LIMITED The Auditing Practices Board Limited,

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 Information Commissioner s foreword... 2 About this code... 3 Chapter 1 Introduction to PIAs...

More information

SME guide to the personal data protection act 2012

SME guide to the personal data protection act 2012 SME guide to the personal data protection act 2012 All enquiries may be addressed to: Lim Chong Kin Director Head, Telecommunications, Media and Technology Practice Group Head, Competition & Regulatory

More information

INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified)

INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified) Disciplinary Policy INSERT TITLE AND BRANDING Dr A Gill s signature and front cover to be placed on policy when received from Communications. (Policy fully ratified) Consultation Staff Forum August 2014

More information

Approved by Board: 22/06/2016. Records Management Policy

Approved by Board: 22/06/2016. Records Management Policy Approved by Board: 22/06/2016 Records Management Policy 1. Introduction 1.1 The information that University records contain serves as evidence of functions executed and activities performed. University

More information

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved

Gwybodaeth Dan Reolaeth. Gwynedd Council DATA PROTECTION POLICY FINAL 2.0. September Information Management Service. Approved Gwybodaeth Dan Reolaeth Gwynedd Council DATA PROTECTION POLICY FINAL 2.0 September 2015 Information Management Service 1. Introduction The Council makes considerable use of personal information in all

More information

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation EU General Data Protection Regulation (GDPR) Tieto s approach and implementation GDPR roles and positions Data subjects Information on processing Consent or other basis for processing Right requests High

More information

12 STEPS TO PREPARE FOR THE GDPR

12 STEPS TO PREPARE FOR THE GDPR 12 STEPS TO PREPARE FOR THE GDPR Presented by Henshalls Insurance Brokers On 25 May 2018, the General Data Protection Regulation (GDPR) comes into effect in the EU and across the United Kingdom. The GDPR

More information

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector

GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector GUIDELINES FOR IMPLEMENTING A PRIVACY MANAGEMENT PROGRAM For Privacy Accountability in Manitoba s Public Sector TABLE OF CONTENTS INTRODUCTION... 2 Accountable privacy management 2 Getting started 3 A.

More information

ICAEW Technical Release

ICAEW Technical Release Technical Release ICAEW Technical Release TECH13/14AAF ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over 147,000 chartered accountants

More information

Data Protection Policy

Data Protection Policy Preston and District Data Protection Policy The University of the Third Age Scope of the policy This policy applies to the work of Preston & District U3A (hereafter the U3A ). The policy sets out the requirements

More information

Salesforce s Processor Binding Corporate Rules. for the. Processing of Personal Data

Salesforce s Processor Binding Corporate Rules. for the. Processing of Personal Data Salesforce s Processor Binding Corporate Rules for the Processing of Personal Data Table of Contents 1. Introduction 3 2. Definitions 3 3. Scope and Application 4 4. Responsibilities Towards Customers

More information

BOARD OF DIRECTORS CHARTER AMENDED MARCH 2016

BOARD OF DIRECTORS CHARTER AMENDED MARCH 2016 BOARD OF DIRECTORS CHARTER AMENDED MARCH 2016 BOARD OF DIRECTORS CHARTER OF WSP GLOBAL INC. (THE "CORPORATION") AMENDED MARCH 2016 A. PURPOSE The role of the board of directors of the Corporation (the

More information

SERVICE EQUIPMENT DISPOSAL POLICY

SERVICE EQUIPMENT DISPOSAL POLICY SERVICE EQUIPMENT DISPOSAL POLICY Version 2.1 IT Equipment Disposal Policy COR/047/V2.01 December 2016 updated January 2018 Version 2.1 1 Subject and version number of document: Serial number: Service

More information

Online Store Application Form

Online Store Application Form Online Store Application Form You need to be a Lincoln Sentry Account holder to place orders using the online store website. Please provide your existing Lincoln Sentry account number. Submit the completed

More information

INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY

INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY INSTITUTE OF HOSPITALITY AWARDING BODY CONFLICT OF INTEREST POLICY Version 0.2, 13.08.2014 Institute of Hospitality Trinity Court, 34 West Street, Sutton, Surrey, SM1 1SH Tel:+44(0)20 8661 4900 www.instituteofhospitality.org.uk

More information