Third party use of customer lists

Size: px
Start display at page:

Download "Third party use of customer lists"

Transcription

1 May 2006 slaughter and may marketing: part 4 Third party use of customer lists Rob Sumroy, Partner In the fi rst article in this series we considered the legislative and regulatory framework that direct marketers are required to work within. The second article considered in greater detail the requirement to obtain consent before carrying out marketing activities and the third considered the rules and guidance which apply in relation to direct marketing to children. This fourth and fi nal article considers some of the data protection issues which arise in the context of transactions relating to databases. Selling Databases: Three Scenarios Increasingly in today s world companies are regarding their customer databases as an asset to be exploited. Having collected data relating to their customers, companies seek diverse opportunities to exploit that data in a way which generates income for them. Often this is referred to this as selling a database, but what exactly does this mean? In our practice, we have seen this worked out in a number of different ways. The database may be exploited by entering into a commercial arrangement with a third party, in order that that third party may market its products or services to the customers contained within the database. Alternatively, a party may seek to exploit its database by selling its rights in the database in their entirety to a third party, or indeed, by disposing of the company which owns the rights to the data. In whichever context clients will often refer to customers and their data in terms of ownership; concerned to know whether they own a particular group of customers. This may be a correct characterisation from the perspective of the intellectual property rights which exist in the data and the commercial exploitation of those rights. However, from a data protection perspective, the position is more complex. Whatever the structures adopted, when data controllers enter into such a transaction (whether they are sellers, purchasers or parties to a commercial agreement) they will process personal data. Below are three examples which will be referred to throughout this article. Commercial Agreements Where two parties seek to collaborate by entering into a commercial agreement, for example to market a range of products of one party to the customers of the other, it will result in the transfer of certain customer data between the parties. At each stage of the negotiations, the parties will need to consider at each stage whether any personal data is being passed between them. In this case, processing of personal data may occur during the negotiation stage, in connection with due diligence carried out by each party. However processing of personal data will occur: > on and following completion where information relating to customers will be passed between each party and used by each of the parties for their respective commercial ends. In addition, following completion, management reports and other data relating to the customer base will be transferred between the parties on a regular basis. Sale of database as an asset ( Database Sale ) When a company disposes of the entirety of its rights in a database by selling that database as an asset it will need to consider the same issue as when it contemplates entering into a commercial agreement at each stage of the transaction will any personal data be passed between them. In this situation processing of personal data will occur: > on completion of the transaction, where the database is transferred to the actual purchaser and processed in the purchaser s business.

2 Sale of a company which owns a database ( Company Sale ) In the case of a company sale, processing of personal data will occur: > during the negotiation process, where the seller will provide prospective purchasers with information including personal data relating to the directors, employees, suppliers and customers of the target. > during the disclosure exercise where documents relating to the target are handed over to the prospective purchasers via a data room or otherwise. Compliance with the Act Whenever a company processes personal data they must comply with all the provisions of the Data Protection Act 1998 (the Act ). As has been discussed in the previous articles in the series, this will include, amongst other things, complying with both the data protection principles and the notifi cation obligations. Fair Processing Information Although it is important that data controllers observe all the Act s principles and comply with all other obligations under Act, a key principle to consider in the context of a sale of database is the fi rst principle (that data be processed fairly and lawfully). Disclosing or transferring information to a prospective purchaser or to a commercial partner will not be fair unless certain information (the fair processing information ) has been provided to the data subject. This information must include the following: > the identity of the data controller > the purpose(s) for which the data will be processed; and > any other information which is necessary to enable the particular processing to be fair. In the ordinary course of business, data controllers typically provide the fair processing information at the moment they fi rst capture personal details from their data subjects (for example by including a statement on the company s standard terms of business). However, in most cases data controllers do not specify at data capture stage that the personal data may at some point in the future be disclosed (or sold) to parties in the context of a commercial transaction. In addition, parties to a commercial transaction who receive data will also be processing data and would therefore be obliged under the Act to provide the data subject with a new fair processing notice. Where new use of the data is envisaged, the fair processing information should be given before the proposed processing takes place. In limited circumstances, where the personal data are obtained by someone other than the data subject (for example, from a seller) the provision of fair processing information need not be given where it would involve a disproportionate effort. Disproportionate effort is not defi ned but is likely to mean that the benefi t to the data subject of receiving the information does not justify the administrative burden and/or cost to the data controller in providing it. It is not clear when this provision may be relied upon but the Information Commissioner has emphasised that in certain circumstances, a quite considerable effort could reasonably be expected of the data controller. Providing The Fair Processing Information In Each Scenario Commercial Agreements Pre-contract disclosures Where two parties enter into a commercial agreement under which they agree that one party will provide its products or services to the customers of the other there may be an exchange of information between the parties prior to the signing of the agreement. It is not commercially viable to notify customers of the potential (and at that stage confi dential) transaction affecting their data. In these circumstances both parties will need to ensure that this information is anonymised to the extent possible, and (where anonymising is not commercially practicable) that any disclosure is protected by strictly enforced confi dentiality undertakings. 2 slaugh ter and may

3 Disclosures on and following completion Following the conclusion of such a commercial agreement, there will be a transfer of customer information between each party. In addition, the data will be used by one or both of the parties following completion in connection with the commercial arrangement. In this situation both parties will be processing the data on their own behalf (they will each be a data controller) and, as such, will each have a direct connection with their respective data subjects. Best practice in this case would be for the parties to agree the form of notifi cation to be given by each party (or jointly) to the data subjects. The commercial agreement is a convenient place to document these obligations. If it is not practicable for the parties to agree the exact form of the wording for this prior to signing the commercial agreement, the parties should at least agree which party is responsible for determining the form of the language and whether the other party is to have a right of approval over the substance, style and content of that wording. Database Sale or Company Sale Pre-sale disclosures in a Database Sale or Company Sale During the due diligence and disclosure stages of a transaction, the data protection issues will be similar regardless of whether the transfer is of the database or the shares in the company which owns the database. This is because similar due diligence processes will be undertaken and lists of customers, suppliers, employees or offi cers will be exchanged by the seller to the prospective purchasers. The rules on providing fair processing information require that both the seller and the prospective purchaser to a transaction inform the data subject of the disclosure and receipt of personal data. As with the prospective commercial agreement considered above, it is not commercially acceptable to notify data subjects of the potential transaction. In order to avoid the requirement to notify, sellers should anonymise the personal data so that it falls outside the ambit of the Act. Where purchasers object to information being redacted, it is worth pointing out that the receipt of personal data will make them data controllers in respect of that information. In guidance issued by the Information Commissioner it is acknowledged that sometimes the disclosure of personal data without the provision of fair processing information during the course of a transaction is inevitable. In these circumstances the best approach would be to minimise the risk of further disclosures by asking the purchaser to sign a confi dentiality undertaking which would in addition ensure that the information will be returned to the seller or destroyed should the sale not go ahead. Transfer of data on completion Company Sale On completion of a company sale there will be no actual transfer other than that relating to the shares. This means that the identity of the data controller will not have changed and no fair processing information need be given, except where the new owner of the shares proposes to use the data for a new purpose. However, fair processing issues may arise if data subjects felt it was important that they had given their data to the target company as a member of a particular group. For example, if a data protection consent obtained at the time of the data permitted marketing to the data subject by a member of the data controller s corporate group, a change on the identity of that group should be notifi ed to the data subject. Transfer of data on completion - Database Sale On the sale of a database as an asset, there will be a transfer of personal data between the seller and the purchaser. As both the disclosure and receipt of personal data in these circumstances will amount to processing, both parties will be under a duty to inform the data subject that the personal data is now being held by a new data controller. Although the Act requires that both seller and purchaser as data controllers provide the fair processing information to the data subject, in practice it is suffi cient for one of the parties to fulfi l this obligation. As the transfer of personal data in a straightforward sale of a business will mean that the seller will no longer be the data controller of that data, it is more common for the purchaser to notify the data subjects on behalf of both parties. Where sellers rely on the purchaser to contact the data subjects on their behalf, it is important that they obtain assurances from the purchaser that this will be done, for example in the sale documentation. It is common for sellers to seek to agree with the purchaser the text of the fair processing notice to ensure that it is consistent with the general message being publicised by the seller regarding the sale. 3 slaugh ter and may

4 Fair Processing Conditions Schedule 2 In addition to providing the fair processing information, data controllers must ensure that all processing can be justifi ed under one of the conditions set out in the Act at Schedule 2. In essence, this will require that either the consent of the data subject is obtained, or that processing must be necessary for one of a number of specifi ed purposes. In the context of commercial transactions the two most important conditions are the consent condition and the legitimate interest condition. Consent The Act does not provide any defi nition of consent. The Data Protection Directive (95/46/EC) defi nes a data subject s consent as any freely given specifi c and informed indication of his wishes by which the data subject signifi es his agreement to personal data relating to him being processed. The Information Commissioner has made it clear that obtaining consent is not easy to achieve. Where the data subject feels he or she has no option but to consent, it may be that consent is not freely given. Where it is intended that databases will be used to market individuals electronically (which is defi ned as being by fax, , SMS or automated calling system), prospective purchasers will need to consider the additional restrictions imposed by the Privacy and Electronic (EC Directive) Regulations The requirements of these regulations in respect of consents obtained from data subjects were discussed in the second article in this series, Getting the consent right on data capture, volume 6, issue 3 of Privacy & Data Protection (January/February 2006). The Privacy and Electronic (EC Directive) Regulations 2003 do not apply where direct marketing communications are sent by post. However, consent must nonetheless be obtained in respect of communications to be sent by post for the purposes of complying with the Act. This is considered further below, in respect of each scenario. Legitimate interest Most data controllers would agree that obtaining consent from each data subject before entering into a confi dential commercial transaction is both impracticable and undesirable. For this reason, data controllers will often turn to one of the other conditions set out in Schedule 2 of the Act. The most useful of these is the condition relating to the legitimate interest which requires the proposed processing by data controllers (and any third party to whom the data are disclosed) to be in their legitimate interest, but at the same time not prejudicial to the rights and freedoms or the legitimate interests of the data subject. Clearly, this balancing act that data controllers must perform will be a subjective one. However, it would appear reasonable to rely on this condition unless the proposed processing would be prejudicial to the interests of the data subject. What may be prejudicial in this context is discussed further below. Complying with the Schedule 2 Conditions in Each Scenario In relation to the different case studies described above, the application of the Schedule 2 conditions would be as follows. Commercial Agreement Although the disclosure, transfer and use of the data in connection with the operation of a commercial agreement is comparable in many ways to the sale of a business the database is likely to be transferred to the other party - care must be taken when considering how to justify the processing involved under Schedule 2. Legitimate interest condition Although it is clearly in the interest of both the parties to the commercial agreement for the processing to take place, the same may not be said of the data subjects. As described above, the purpose of entering into the commercial agreement was so that one party could effectively market new products or services to the other party s customer base. This means that the processing carried on following disclosure of the personal data is likely to be different to that prior to disclosure. 4 slaugh ter and may

5 In these circumstances, where a new use of data is envisaged, it will not be possible to rely on the legitimate interest condition, as some data subjects will invariably object to their personal details being used for a purpose other than that to which they originally consented. Consent The processing of personal data by the other party to the commercial agreement will therefore need the consent of each of the customers. This will be a consideration in respect of both the data transferred between the parties at the beginning of the operation of the agreement and in respect of any new data collected by either party over the duration of the agreement. In order to comply with the Act, the party who is passing personal data to the other party will need to be sure that, in respect of all data being passed, it has the consent of the data subjects to share that data with third parties and for the purpose being contemplated by the agreement. To the extent that party does not already have the relevant consents, these will need to be obtained. As these entities will already have to provide the fair processing notice (see above) it would be best for both obligations to be carried out at the same time. This means that no processing of personal data should occur prior to consents having being obtained (if not already in place) which will probably take place after the commercial agreement has been signed. It is important to bear in mind also that if either party is collecting new personal data during the term of the agreement and it is intended that this data is shared with the other party (for example, for the purposes of marketing or reporting management information) then the consents obtained at the point of data capture will need to be suffi ciently broad to cover this purpose. It is advisable to agree the wording of this consent at the outset of the relationship or if this is not possible at least to agree which party will have control of the language and whether the other party should have a right of approval. Database Sale or Company Sale Disclosures and receipt of personal data pre-sale (in the context of both a sale of a company or a database) and the ultimate transfer of personal data (in the context of a sale of a database) may be justifi ed by both the seller and the prospective purchaser either under the consent condition or the legitimate interest condition. Obtaining customer consents pre-completion may be impracticable in the context of a confi dential commercial transaction. For these reasons, it is likely that in the context of acquisitions of a business as a going concern both the seller and the purchaser would rely on the legitimate interest condition, on the grounds that the transfer of data in connection with a sale or acquisition of an asset is clearly within a data controller s legitimate interest and would not prejudice the rights or freedoms or the legitimate interests of the data subject. It would however remain necessary to make the legitimate interest balancing assessment in each particular case. For example, in the context of a transaction involving the transfer of insurance polices, where the disclosure of personal data would ensure a continuity of an identical service to the policy holders, it would be hard for the policyholder to claim their rights, freedoms or legitimate interests were being prejudiced. Another example may relate to an employee of that same business - the transfer of their contract of employment thereby ensuring continuity of their jobs would appear to be justifi able under the legitimate interest condition. However, we must distinguish between the situation where a company or business is being sold as a going concern and the situation where a database (or indeed a company which owns the database) is simply being sold to enable the purchaser to use the data contained within the database for its own purposes. If the latter is true, it is unlikely that the disclosure could ever fall within the legitimate interest condition of Schedule 2 to the Act. Processing Sensitive Data When processing sensitive personal data, for example data which concerns a data subject s health or sexuality, a data controller must comply with one of the conditions set out in Schedule 3 (in addition to a condition set out in Schedule 2). Schedule 3 conditions are harder to comply with than Schedule 2 conditions and in most cases data controllers will have to opt for the condition which requires processing of the sensitive data to be done with the explicit consent of the data subject. The term explicit consent is not defi ned in the Act. However the Information Commissioner has issued guidance which suggests that the use of the word explicit suggests that the consent of the data subject must be absolutely clear. In appropriate cases it should cover the specifi c detail of the processing, the particular type of data to be processed (or even the specifi c information), the purposes of the processing and any special aspects of 5 slaugh ter and may

6 the processing which may affect the individual, for example disclosures which may be made of the data. Although sensitive personal data will be more relevant to certain types of businesses (for example, healthcare organisations and insurance companies), most businesses will process some, particularly in records relating to employees. A Pragmatic Approach Navigating the data protection maze during a transaction can be a frustrating and diffi cult task. It is important therefore that consideration is given to the key issues as early as possible so that the transaction can be managed in a way which adopts a responsible but pragmatic approach to compliance. Early consideration of these issues and careful assessment of the risks of non-compliance should ensure that transactions proceed without prejudice to the data subject. The steps that any company will need to take and the issues it will need to consider will be similar regardless of the structure of the particular transaction. Due Diligence Prior to agreeing to acquire or use under a commercial agreement another party s database, a company should undertake due diligence in regard to the database. It is particularly important that the true size (and therefore value) of the database is ascertained at this stage. For example, if a database may contain the details of 5000 customers. However, if only 1000 of those customers have consented to their personal data being passed to third parties for the purposes of marketing, this will signifi cantly reduce the value of the database to the acquire. Indeed, such information may ultimately affect the acquirers decision as to whether it proceeds with the proposed transaction. In this situation, the acquirer may seek protection from the seller by obliging the seller only to transfer to it such parts of the database in respect of which it has the relevant consents. Alternatively, the transaction may be expressed to be conditional upon the seller obtaining relevant consents in respect of the entire database. Defining the database Consideration should be given to how the database to be acquired is defi ned. This will be particularly important to the purchaser in a Database Sale as they will want to be confi dent they have all the rights required to use the database. However, it will also be an important consideration in the context of a Company Sale and commercial agreement. If a purchaser is buying a company in order to acquire the database, the purchaser will want to be sure that the company it is buying owns all the rights in the database. In the context of a commercial agreement, the parties will need to consider whether the transfer of data is a once in time event or whether the party selling its database will be obliged to refresh the database on a regular basis as it collects new data. Warranty protection In any of the transactions considered in this article, the acquiring party may seek warranties from the other party in respect of the database. These warranties may cover areas such as the ownership of the data, that party s ability to pass the personal data to third parties and whether they have fully complied with the provisions of the Act in respect of the data. Protection such as this should act to reduce the fi nancial risk to the acquiring party. Use of the database going forward The acquirer of a database should consider its intended future use of the database and particularly whether that use is covered by the original consent obtained from the data subjects at the point of data capture. The acquirer will need to consider whether it is not prepared to use the database (or at least those parts in respect of which the consent does not cover its future use) until it has had the opportunity to refresh the fair processing information and consent. Weighing the risks Any potential breach of a principle should be approached with caution. However, full compliance with the data protection principles (and particularly the fi rst principal requiring fair and lawful processing) in the context of a commercial transaction may present signifi cant barriers to the parties abilities to complete the transaction. Certain acts of non-compliance will present greater risks than others. For example a one off breach or a breach which will ultimately be resolved will present less of a risk than a breach which will continue after the relevant transfer of the 6 slaugh ter and may

7 database. Whilst the importance of complying with all of the Act must not be underestimated, data controllers may have to take a view, in each set of circumstances on the risk of non-compliance. With the benefi t of proper planning it should be possible to minimise the breaches of the Act and manage the risk of any non-compliance whilst avoiding prejudice to data subjects. A version of this article appeared in Volume 6, issue 5 of Privacy & Data Protection (May 2006) London One Bunhill Row London EC1Y 8YY United Kingdom T +44 (0) F +44 (0) Paris 130 rue du Faubourg Saint-Honoré Paris France T +33 (0) F +33 (0) Brussels Square de Meeûs Brussels Belgium T +32 (0) F +32 (0) Hong Kong 47th Floor Jardine House One Connaught Place Central Hong Kong T F Published to provide general information and not as legal advice Slaughter and May, 2006 One Bunhill Row, London EC1Y 8YY T +44 (0) F +44 (0) jmya188.indd308

Getting the right consent on data capture

Getting the right consent on data capture January/February 2006 slaughter and may marketing: part 2 Getting the right consent on data capture Rob Sumroy, Partner In the fi rst article in this series Introduction to data protection and direct marketing:

More information

Introduction to data protection and direct marketing: the rules of the game

Introduction to data protection and direct marketing: the rules of the game December 2005 marketing: part 1 Introduction to data protection and direct marketing: the rules of the game slaughter and may Rob Sumroy, Partner Direct marketers are data controllers who use personal

More information

Securitisation and Private Equity. slaughter and may. October 2004

Securitisation and Private Equity. slaughter and may. October 2004 Securitisation and Private Equity slaughter and may October 2004 contents Securitisation and Private Equity 1 1. Refi nancing an Acquisition 2 2. Providing Debt Financing for an Acquisition 4 3. Realising

More information

Data protection and direct marketing:

Data protection and direct marketing: March 2006 marketing: part 3 Data protection and direct marketing: slaughter and may child s play Rob Sumroy, Partner The fi rst article in this series Introduction to data protection and direct marketing:

More information

Disclosure of CfDs concerns for corporate issuers. slaughter and may. January 2008

Disclosure of CfDs concerns for corporate issuers. slaughter and may. January 2008 Disclosure of CfDs concerns for corporate issuers slaughter and may January 2008 contents 1. Introduction 1 2. The Failings of the Current Regime 1 3. The FSA Options 2 4. Option 2 3 5. Concerns with Option

More information

Enterprise Act 2002 Insolvency Aspects. slaughter and may. 16 December 2004

Enterprise Act 2002 Insolvency Aspects. slaughter and may. 16 December 2004 Enterprise Act 2002 Insolvency Aspects slaughter and may 16 December 2004 contents Page 1. Introduction 1 2. Commencement 1 3. Principal Reforms 1 4. Prohibition of administrative receivership 1 4.3 Capital

More information

Unsolicited visits and surprise requests for information by the Financial Services Authority. April 2009

Unsolicited visits and surprise requests for information by the Financial Services Authority. April 2009 Unsolicited visits and surprise requests for information by the Financial Services Authority April 2009 Contents 1. Introduction 1 2. The FSA s investigatory powers 2 3. Confidentiality of information

More information

Conflicts of Interest MiFID and the General Law

Conflicts of Interest MiFID and the General Law slaughter and may Companies Briefing Paper Act 2006 September 2008 Conflicts of Interest MiFID and the General Law Much has been said and written in recent years about the conflicts of interest that can

More information

An Introduction to the UK Anti-Money Laundering Regime. slaughter and may. March 2008

An Introduction to the UK Anti-Money Laundering Regime. slaughter and may. March 2008 An Introduction to the UK Anti-Money Laundering Regime slaughter and may March 2008 contents 1. Introduction 1 1.1 Money Laundering 1 1.2 The Regulated Sector 1 2. UK Anti-Money Laundering Measures 3 2.1

More information

DATA PROTECTION GUIDELINES

DATA PROTECTION GUIDELINES Data Protection Commissioner DATA PROTECTION GUIDELINES GUIDELINES FOR THE PROMOTION OF GOOD PRACTICE INSURANCE BUSINESS SECTOR February 2006 These guidelines have been jointly developed by a working group

More information

Dealer and Broker Guide. to Financial Conduct Authority Regulation. Dealer_conduct_guide_Oct15 This is a Business-to-Business communication

Dealer and Broker Guide. to Financial Conduct Authority Regulation. Dealer_conduct_guide_Oct15 This is a Business-to-Business communication Dealer and Broker Guide to Financial Conduct Authority Regulation Dealer_conduct_guide_Oct15 This is a Business-to-Business communication Legal Disclaimer The information contained in this Dealer and Broker

More information

Duties of the directors of companies in financial difficulties. slaughter and may. October 2010

Duties of the directors of companies in financial difficulties. slaughter and may. October 2010 Duties of the directors of companies in financial difficulties slaughter and may October 2010 Contents 1. Introduction 01 2. Overview 01 3. Practical guidance 02 4. Common law, statutory and regulatory

More information

Companies in administration: an overview. slaughter and may DECEMBER 2011

Companies in administration: an overview. slaughter and may DECEMBER 2011 Companies in administration: an overview slaughter and may DECEMBER 2011 Contents 1. Appointment 01 2. Effect of appointment on management and directors powers 02 3. Role of administrator 03 4. Effect

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party 11601/EN WP 90 Opinion 5/2004 on unsolicited communications for marketing purposes under Article 13 of Directive 2002/58/EC Adopted on 27 February 2004 This Working

More information

UK corporation tax on dividends

UK corporation tax on dividends October 2009 slaughter and may UK corporation tax on dividends Graham Airs, Partner The rules for the taxation of dividends received by UK resident companies (and, in those few cases where relevant, non-uk

More information

Freedom of information guidance Exemptions guidance Section 41 Information provided in confidence

Freedom of information guidance Exemptions guidance Section 41 Information provided in confidence Freedom of information guidance Exemptions guidance Section 41 Information provided in confidence 14 May 2008 Contents Introduction 2 What information may be covered by this exemption? 3 Was the information

More information

Advisory agreement Terms & Conditions

Advisory agreement Terms & Conditions Advisory agreement Terms & Conditions Retail Client The purpose of this client notice is to set out the basis on which Central Markets (London) Ltd ( CML ) will provide advisory services to you in relation

More information

Regulatory Compliance Needs Process Management

Regulatory Compliance Needs Process Management White Paper Regulatory Compliance Needs Process Management A Pathfinder Technology Solutions Whitepaper October 22, 2004-1 - Introduction All businesses need to comply with government regulations, regardless

More information

Communication policy NASPERS GROUP 1. PURPOSE 2. DEFINITIONS. Approved by the board on: 26 June 2015

Communication policy NASPERS GROUP 1. PURPOSE 2. DEFINITIONS. Approved by the board on: 26 June 2015 Approved by the board on: 26 June 2015 NASPERS GROUP Communication policy (This policy must be read in conjunction with the investor relations policy) 1. PURPOSE The purpose of this policy is to record

More information

US Private Placements for European Issuers

US Private Placements for European Issuers financing BRIEFING april 2013 Recent turmoil in European debt markets has prompted many European companies to consider alternative sources of debt financing. One source of funding which is proving increasingly

More information

Data Protection Workshop: How the Law Affects You Practice Questions

Data Protection Workshop: How the Law Affects You Practice Questions Data Protection Workshop: How the Law Affects You Practice Questions 1. Which of the following is not personal data covered by the Data Protection Act (pick one or more): A. Comments about an individual

More information

Public Consultation regarding Data Sharing and Governance Bill. Contribution of Office of the Data Protection Commissioner

Public Consultation regarding Data Sharing and Governance Bill. Contribution of Office of the Data Protection Commissioner Submission of the Office of the Data Protection Commissioner (DPC) on the data-sharing and Governance Bill: - Policy Proposals (dated the 1 st of August 2014) Public Consultation regarding Data Sharing

More information

Guidance on political campaigning

Guidance on political campaigning I ICO guidance Guidance on political campaigning 3 Guidance on political campaigning Data Protection Act Privacy and Electronic Communications Regulations Contents Introduction... 3 A. Why comply?... 5

More information

23/1/15 Version 1.0 (final)

23/1/15 Version 1.0 (final) Information Commissioner s Office response to the Cabinet Office s consultation on the proposal to amend the Privacy and Electronic Communications (EC Directive) Regulations 2003 ( PECR ), to enable the

More information

Big Data for Mutuals. Marc Dautlich 25 November 2013

Big Data for Mutuals. Marc Dautlich 25 November 2013 Big Data for Mutuals Marc Dautlich 25 November 2013 Agenda BIG DATA What is it? OPPORTUNITIES What are they? LEGAL CHALLENGES How do we overcome them? LEGAL REFORM What can we do now to minimise impact?

More information

The Companies Act 2006: Insolvency Aspects

The Companies Act 2006: Insolvency Aspects May 2008 slaughter and may The Companies Act 2006: Insolvency Aspects Sarah Paterson, partner and Davina Guinness, associate Introduction The new Companies Act 2006 (the 2006 Act ) represents the most

More information

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Controller Policy Contents INTRODUCTION 3 PART I: BACKGROUND AND ACTIONS 4 PART II: CONTROLLER OBLIGATIONS 6 PART III: APPENDICES 13 2 P a g e INTRODUCTION

More information

Employment law newsletter

Employment law newsletter www.parissmith.co.uk Employment law newsletter 1. Early Conciliation ACAS has published guidance on the new early conciliation procedure which is now mandatory, in most cases, for claims lodged on or after

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data;

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; OBJECTS AND REASONS This Bill would provide for (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; (b) the protection of the privacy of individuals in relation

More information

technical factsheet 176

technical factsheet 176 technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection

More information

Science Europe Position Statement. On the Proposed European General Data Protection Regulation MAY 2013

Science Europe Position Statement. On the Proposed European General Data Protection Regulation MAY 2013 Science Europe Position Statement On the Proposed European General Data Protection Regulation MAY 2013 Science Europe Position Statement on the Proposal for a Regulation of the European Parliament and

More information

Due Diligence and Disclosure in Private Acquisitions and Disposals. slaughter and may. August 2007

Due Diligence and Disclosure in Private Acquisitions and Disposals. slaughter and may. August 2007 Due Diligence and Disclosure in Private Acquisitions and Disposals slaughter and may August 2007 contents 1. introduction 1 2. putting due diligence and disclosure into context 2 3. due diligence 6 3.1

More information

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Processor Policy Confidential Contents INTRODUCTION TO THIS POLICY 3 PART I: BACKGROUND AND ACTIONS 4 PART II: PROCESSOR OBLIGATIONS 6 PART III:

More information

information Records Management Checklist business people security preservation accountability Foreword Introduction Purpose of the checklist

information Records Management Checklist business people security preservation accountability Foreword Introduction Purpose of the checklist Records Management Checklist Foreword We fi rst developed the Records Management Checklist in 2008 to complement our performance audit Records Management in the Victorian Public Sector. At that time the

More information

Data Protection for the Guidance Counsellor. Issues To Plan For

Data Protection for the Guidance Counsellor. Issues To Plan For Data Protection for the Guidance Counsellor Issues To Plan For Author: Hugh Jones Data Protection Specialist Longstone Management Ltd. Published by the National Centre for Guidance in Education (NCGE)

More information

Merthyr Tydfil County Borough Council. Data Protection Policy

Merthyr Tydfil County Borough Council. Data Protection Policy Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the

More information

GSK Public policy positions

GSK Public policy positions Safeguarding Personally Identifiable Information A Summary of GSK s Binding Corporate Rules The Issue The processing of Personally Identifiable Information (PII) 1 and Sensitive Personally Identifiable

More information

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person.

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person. PART I: INTRODUCTION AND BACKGROUND Purpose This Data Protection Binding Corporate Rules Policy ( Policy ) establishes the approach of Fluor to compliance with European data protection law and specifically

More information

DEPARTMENTAL INTERPRETATION AND PRACTICE NOTES NO. 39 PROFITS TAX TREATMENT OF ELECTRONIC COMMERCE

DEPARTMENTAL INTERPRETATION AND PRACTICE NOTES NO. 39 PROFITS TAX TREATMENT OF ELECTRONIC COMMERCE Inland Revenue Department Hong Kong DEPARTMENTAL INTERPRETATION AND PRACTICE NOTES NO. 39 PROFITS TAX TREATMENT OF ELECTRONIC COMMERCE These notes are issued for the information and guidance of taxpayers

More information

"Direct marketing" is not limited to advertising goods or services for sale. It also includes promoting an organisation s aims and ideals.

Direct marketing is not limited to advertising goods or services for sale. It also includes promoting an organisation s aims and ideals. Direct Marketing Most direct marketing activities must comply with the requirements of the Data Protection Act 2002 (DPA) and, where that direct marketing is communicated by electronic mail, telephone

More information

Submission of feedback should reach LIA via email at lia@lia.org.sg by 4 October 2014

Submission of feedback should reach LIA via email at lia@lia.org.sg by 4 October 2014 PUBLIC CONSULTATION DRAFT OF PROPOSED LIA CODE OF CONDUCT FOR AGENTS OF LIFE INSURERS ON THE SINGAPORE PERSONAL DATA PROTECTION ACT 2012 (NO. 26 OF 2012) Submission of feedback should reach LIA via email

More information

COMMENTARY. Hong Kong Strengthens Its Personal Data. on Direct Marketing JONES DAY

COMMENTARY. Hong Kong Strengthens Its Personal Data. on Direct Marketing JONES DAY May 2013 JONES DAY COMMENTARY Hong Kong Strengthens Its Personal Data Privacy Laws and Imposes Criminal Penalties on Direct Marketing In 2012 Hong Kong introduced the Personal Data (Privacy) (Amendment)

More information

DATA PROTECTION MANUAL

DATA PROTECTION MANUAL DATA PROTECTION MANUAL VERSION TABLE Version Date Published CO Circular 1 September 2008 3 July 2015 July 2015 2 CONTENTS Part A: General Guidance 1 Introduction to the Data Protection Act 1998 5 2 The

More information

General Terms and Conditions for the Purchase and Maintenance of Hardware

General Terms and Conditions for the Purchase and Maintenance of Hardware General Terms and Conditions for the Purchase and Maintenance of Hardware A COMMON INTRODUCTORY PROVISIONS 1 Object and validity 1.1 The present General Terms and Conditions (GTC) govern the conclusion,

More information

Water brokers and exchanges your fair trading obligations

Water brokers and exchanges your fair trading obligations Water brokers and exchanges your fair trading obligations Australian Competition and Consumer Commission 23 Marcus Clarke Street, Canberra, Australian Capital Territory, 2601 Commonwealth of Australia

More information

The Manitowoc Company, Inc.

The Manitowoc Company, Inc. The Manitowoc Company, Inc. DATA PROTECTION POLICY 11FitzPatrick & Associates 4/5/04 1 Proprietary Material Version 4.0 CONTENTS PART 1 - Policy Statement PART 2 - Processing Personal Data PART 3 - Organisational

More information

Corporate Governance Statement

Corporate Governance Statement The Crown Limited Board is committed to the implementation and maintenance of good corporate governance practices. This Statement sets out the extent to which Crown Limited (Crown) has followed the best

More information

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy) PRESIDENT S DECISION No. 40 of 27 August 2013 Regarding Data Protection at the European University Institute (EUI Data Protection Policy) THE PRESIDENT OF THE EUROPEAN UNIVERSITY INSTITUTE, Having regard

More information

Data protection at the cost of economic growth?

Data protection at the cost of economic growth? Data protection at the cost of economic growth? Elina Pyykkö* ECRI Commentary No. 11/November 2012 The Data Protection Regulation proposed by the European Commission contains important elements to facilitate

More information

The Companies Act 2006: Directors Duties Guidance. By David Chivers QC

The Companies Act 2006: Directors Duties Guidance. By David Chivers QC The Companies Act 2006: Directors Duties Guidance By David Chivers QC The Companies Act 2006: Directors Duties Guidance By David Chivers QC Published in October 2007 by The Corporate Responsibility (CORE)

More information

Chapter 7: Australian Privacy Principle 7 Direct marketing

Chapter 7: Australian Privacy Principle 7 Direct marketing Chapter 7: APP 7 Direct marketing Version 1.0, February 2014 Chapter 7: Australian Privacy Principle 7 Direct marketing Version 1.0, February 2014 Key points... 2 What does APP 7 say?... 2 Direct marketing...

More information

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation The Data Protection Landscape Before and after GDPR: General Data Protection Regulation Data Protection regulations across Europe Current regulations & guidance European Directives 95/46/EC (Data Protection)

More information

The EC3\Legal Guide to TUPE

The EC3\Legal Guide to TUPE The EC3\Legal Guide to TUPE Overview and the 2014 Regulations Marina Garston Legal Director +44 (0)203 553 4879 marina@ec3legal.com This guide focuses on the main provisions of TUPE and takes into account

More information

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini Personal data and cloud computing, the cloud now has a standard by Luca Bolognini Lawyer, President of the Italian Institute for Privacy and Data Valorization, founding partner ICT Legal Consulting Last

More information

Report Published under Section 48(2) of the Personal Data (Privacy) Ordinance (Cap. 486) Report Number: R11-1696

Report Published under Section 48(2) of the Personal Data (Privacy) Ordinance (Cap. 486) Report Number: R11-1696 Report Published under Section 48(2) of the Personal Data (Privacy) Ordinance (Cap. 486) Report Number: R11-1696 Date issued: 20 June 2011 Transfer of Customers Personal Data by Fubon Bank (Hong Kong)

More information

Records Management Checklist. preservation. accountability. information. security. peoplep. A tool to improve records management

Records Management Checklist. preservation. accountability. information. security. peoplep. A tool to improve records management Records Management Checklist preservation accountability information security busine ess peoplep A tool to improve records management preservation people security business Foreword accountability information

More information

QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN 18 085 048 237. better health cover shouldn t hurt

QUEENSLAND COUNTRY HEALTH FUND. privacy policy. Queensland Country Health Fund Ltd ABN 18 085 048 237. better health cover shouldn t hurt QUEENSLAND COUNTRY HEALTH FUND privacy policy Queensland Country Health Fund Ltd ABN 18 085 048 237 better health cover shouldn t hurt 1 2 contents 1. Introduction 4 2. National Privacy Principles 5 3.

More information

Secure Information Exchange

Secure Information Exchange Secure File Delivery Secure Information Exchange in an Insecure World www.biscom.com 321 Billerica Road, Chelmsford, MA phone: 978-367-3612 email: sales@biscom.com EXECUTIVE SUMMARY Ask a group of offi

More information

On the edge Lexis PSL Restructuring & Insolvency

On the edge Lexis PSL Restructuring & Insolvency On the edge Lexis PSL Restructuring & Insolvency Data protection law for insolvency practitioners November 2014 Welcome to your third edition of On the edge, a series of guides highlighting a selection

More information

Data controllers and data processors: what the difference is and what the governance implications are

Data controllers and data processors: what the difference is and what the governance implications are ICO lo : what the difference is and what the governance implications are Data Protection Act Contents Introduction... 3 Overview... 3 Section 1 - What is the difference between a data controller and a

More information

Professional Direct Insurance Ockford Mill Ockford Road Godalming GU7 1RH. Terms and Conditions of Business Agreement. Our Service

Professional Direct Insurance Ockford Mill Ockford Road Godalming GU7 1RH. Terms and Conditions of Business Agreement. Our Service Professional Direct Insurance Ockford Mill Ockford Road Godalming GU7 1RH Terms and Conditions of Business Agreement This document is important and sets out the basis upon which we will carry on our business

More information

Data Protection Policy June 2014

Data Protection Policy June 2014 Data Protection Policy June 2014 Approving authority: Consultation via: Court Audit and Risk Committee, University Executive, Secretary's Board, Information Governance and Security Group Approval date:

More information

The kinds of personal information we collect and hold vary depending on the services we are providing, but generally can include:

The kinds of personal information we collect and hold vary depending on the services we are providing, but generally can include: ABN 47 001 768 190 AFSL 244526 Our Privacy Policy At Capital Insurance Brokers, we are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian

More information

07/2013. Specific Terms and Conditions Mobile Device Management

07/2013. Specific Terms and Conditions Mobile Device Management 07/2013 Specific Terms and Conditions Mobile Device Management GENERAL PROVISIONS 1. Offer and Agreement 1.1 The present contractual terms and conditions (hereinafter referred to as Terms and Conditions

More information

FUND MANAGER CODE OF CONDUCT

FUND MANAGER CODE OF CONDUCT FUND MANAGER CODE OF CONDUCT First Edition pursuant to the Securities and Futures Ordinance (Cap. 571) April 2003 Securities and Futures Commission Hong Kong TABLE OF CONTENTS Page INTRODUCTION 1 I. ORGANISATION

More information

The Impact on Marketing-Related Activities of the Data Protection Act and Related Legislation

The Impact on Marketing-Related Activities of the Data Protection Act and Related Legislation The Impact on Marketing-Related Activities of the Data Protection Audience 1. This guidance is intended for all University staff who maintain or use database of contacts for marketing purposes, including

More information

Direct marketing The new rules 1

Direct marketing The new rules 1 3 Direct marketing The new rules 1 Ruth Boardman, solicitor, Bird & Bird 2 The majority of this paper focuses on the provisions in the Privacy and Electronic Communications (EC Directive) Regulations 2003

More information

The Transfer of Undertakings (Protection Of Employment) Regulations 2006 "TUPE"

The Transfer of Undertakings (Protection Of Employment) Regulations 2006 TUPE Revised April 2006. This information leaflet gives you introductory guidance to the 2006 TUPE regulations. It does not however give you legal advice. If you need legal advice please contact Matthew Parkinson

More information

Caedmon College Whitby

Caedmon College Whitby Caedmon College Whitby Data Protection and Information Security Policy College Governance Status This policy was re-issued in June 2014 and was adopted by the Governing Body on 26 June 2014. It will be

More information

SALES AND MARKETING OF MOBILE CONTENT SERVICES

SALES AND MARKETING OF MOBILE CONTENT SERVICES SALES AND MARKETING OF MOBILE CONTENT SERVICES These guidelines incorporate the laws governing mobile content services and explain the sales and marketing requirements for these services set down in the

More information

Combar/CLLS Guidance note on the Agreement for the Supply of Services by a Barrister in a Commercial Case

Combar/CLLS Guidance note on the Agreement for the Supply of Services by a Barrister in a Commercial Case Combar/CLLS Guidance note on the Agreement for the Supply of Services by a Barrister in a Commercial Case Introduction... 2 Background... 2 Entering into an agreement incorporating the Terms... 3 The Services...

More information

Information sharing. Advice for practitioners providing safeguarding services to children, young people, parents and carers

Information sharing. Advice for practitioners providing safeguarding services to children, young people, parents and carers Information sharing Advice for practitioners providing safeguarding services to children, young people, parents and carers March 2015 Contents Summary 3 About this government advice 3 Who is this advice

More information

Summary of the 2009 Debt Collection Round Table convened by the Legal Services Commissioner of Victoria

Summary of the 2009 Debt Collection Round Table convened by the Legal Services Commissioner of Victoria Summary of the 2009 Debt Collection Round Table convened by the Legal Services Commissioner of Victoria Level 9, 330 Collins Street Melbourne VIC 3000 DX 185 Melbourne Phone: 1300 796 344 or 03 9679 8001

More information

Scottish Rowing Data Protection Policy

Scottish Rowing Data Protection Policy Revision Approved by the Board August 2010 1. Introduction As individuals, we want to know that personal information about ourselves is handled properly, and we and others have specific rights in this

More information

Employee Securities Trading Policy

Employee Securities Trading Policy Employee Securities Trading Policy Regional Express Holdings Limited 1. Application This policy relates to trading in Regional Express Holdings Limited shares and related securities. In this policy: Shares

More information

Carriers Insurance Brokers Pty. Limited

Carriers Insurance Brokers Pty. Limited Our Privacy Policy At Carriers Insurance Brokers Pty. Limited, ABN 66 001 609 936, we are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian

More information

Decision 098/2007 Ms Sandra McGregor and the Common Services Agency for the Scottish Health Service

Decision 098/2007 Ms Sandra McGregor and the Common Services Agency for the Scottish Health Service Decision 098/2007 Ms Sandra McGregor and the Common Services Agency for the Scottish Health Service Request for information on claims of medical negligence Applicant: Ms Sandra McGregor Authority: Common

More information

Accessing Personal Information on Patients and Staff:

Accessing Personal Information on Patients and Staff: Accessing Personal Information on Patients and Staff: A Framework for NHSScotland Purpose: Enabling access to personal and business information is a key part of the NHSScotland Information Assurance Strategy

More information

3.6. Please also note, unless your policy confirms otherwise, the rights under your policy may only be pursued in an English court.

3.6. Please also note, unless your policy confirms otherwise, the rights under your policy may only be pursued in an English court. Terms of business agreement - commercial customers M & N Insurance Service Limited Authorised and regulated by the Financial Conduct Authority No: 305837. Registered Office: 248 Hendon Way London NW4 3NL

More information

MYSTERY SHOPPING STUDIES

MYSTERY SHOPPING STUDIES MYSTERY SHOPPING STUDIES All ESOMAR world research codes and guidelines, including latest updates, are available online at www.esomar.org Last revised: 2005 Copyright ESOMAR 2005 Latest reprint: 2005 MYSTERY

More information

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Sopra HR Software as a Data Processor Sopra HR Software, 2014 / Ref. : 20141120-101114-m 1/32 1.

More information

Criminal Justice Act 1993 Insider Dealing Provisions. slaughter and may. April 2006

Criminal Justice Act 1993 Insider Dealing Provisions. slaughter and may. April 2006 Criminal Justice Act 1993 Insider Dealing Provisions slaughter and may April 2006 contents 1. INTRODUCTION 1 1.1 Criminal Justice Act 1993 (the Act ) 1 1.2 Financial Services and Markets Act 2000 ( FSMA

More information

Lombard Visa Card. Terms and Conditions

Lombard Visa Card. Terms and Conditions Lombard Visa Card Terms and Conditions Last Updated 30 Feb 2008 CONTENTS Lombard Visa Card Conditions of Use... pg 1-27 Part A: The Visa Card Account... pg 4-15 Part B: The Lombard Visa Card... pg 16-27

More information

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively.

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively. Joint work between experts from the Article 29 Working Party and from APEC Economies, on a referential for requirements for Binding Corporate Rules submitted to national Data Protection Authorities in

More information

A PRACTICAL GUIDE TO BUYING AND SELLING A BUSINESS

A PRACTICAL GUIDE TO BUYING AND SELLING A BUSINESS A PRACTICAL GUIDE TO BUYING AND SELLING A BUSINESS A COURTESY GUIDE PREPARED BY SWAAB ATTORNEYS 2014 Overview of the acquisition process TIMETABLE > Identify target / Invitation to tender > Initial investigation

More information

I refer to your email of 4 January 2016 in which you requested information under the FOI Act.

I refer to your email of 4 January 2016 in which you requested information under the FOI Act. 1 February 2016 By email Wellington House 133-155 Waterloo Road London SE1 8UG T: 020 3747 0000 E: enquiries@monitor.gov.uk W: www.monitor.gov.uk Dear Request under the Freedom of Information Act 2000

More information

LISTINGS, REGISTRATION, DEALINGS AND SETTLEMENT

LISTINGS, REGISTRATION, DEALINGS AND SETTLEMENT LISTINGS The Company currently has a primary listing of Shares on the LSE and a secondary listing of Shares on KASE, both of which it intends to maintain alongside its proposed secondary listing of Shares

More information

Risk Disclosure Statement

Risk Disclosure Statement Risk Disclosure Statement IMPORTANT INFORMATION Retail forex transactions involve the leveraged trading of contracts denominated in foreign currency with Kaiser Brokers as your counterparty.because of

More information

I ve been injured at work. What do I do? Information for workers

I ve been injured at work. What do I do? Information for workers The Application for Compensation form is an approved form under the Workers Compensation and Rehabilitation Act 2003. The general information contained on this and the following two pages are not part

More information

Hampstead Parochial CofE Primary School Data Protection Policy Spring 2015

Hampstead Parochial CofE Primary School Data Protection Policy Spring 2015 Hampstead Parochial CofE Primary School Data Protection Policy Spring 2015 1. Introduction and Scope 1.1 The Data Protection Act 1998 is the law that protects personal privacy and applies to any school

More information

Data protection issues on an EU outsourcing

Data protection issues on an EU outsourcing Data protection issues on an EU outsourcing Saam Golshani, Alastair Gorrie and Diego Rigatti, Orrick Herrington & Sutcliffe www.practicallaw.com/8-380-8496 Outsourcing can mean subcontracting a process

More information

FISHER & PAYKEL PRIVACY POLICY

FISHER & PAYKEL PRIVACY POLICY FISHER & PAYKEL PRIVACY POLICY 1. About this Policy Fisher & Paykel Australia Pty Limited (ABN 71 000 042 080) and its related companies ('we', 'us', 'our') understands the importance of, and is committed

More information

SUBJECT ACCESS REQUEST PROCEDURE

SUBJECT ACCESS REQUEST PROCEDURE SUBJECT ACCESS REQUEST PROCEDURE Document History Document Reference: Document Purpose: IG31 This procedure sets out the responsibility for staff when receiving requests for information provided under

More information

Priva. Privacy. in schools. A guide to the Privacy Act for principals, teachers and boards of trustees. By Kathryn Dalziel

Priva. Privacy. in schools. A guide to the Privacy Act for principals, teachers and boards of trustees. By Kathryn Dalziel Priva Privacy in schools A guide to the Privacy Act for principals, teachers and boards of trustees By Kathryn Dalziel About the author Kathryn Dalziel is one of New Zealand s leading privacy lawyers and

More information

Retired Public Safety Officer Insurance Premium Deduction Program. Frequently Asked Questions

Retired Public Safety Officer Insurance Premium Deduction Program. Frequently Asked Questions Program Information Frequently Asked Questions 1. What is this new program and when does it start? The Retired Public Safety Offi cer Insurance Premium Deduction Program allows eligible, retired public

More information

GUIDANCE NOTE ON OUTSOURCING

GUIDANCE NOTE ON OUTSOURCING GN 14 GUIDANCE NOTE ON OUTSOURCING Office of the Commissioner of Insurance Contents Page I. Introduction.. 1 II. Application...... 1 III. Interpretation.... 2 IV. Legal and Regulatory Obligations... 3

More information

Share Trading Policy GWA007

Share Trading Policy GWA007 GWA007 Created By Executive Director Date February 2005 Rev. No. 4 Updated By Executive Director Date December 2011 File Name Share Trading Policy GWA007 Approved By GWA Group Limited Board of Directors

More information

Quick guide to the employment practices code

Quick guide to the employment practices code Data protection Quick guide to the employment practices code Ideal for the small business Contents 3 Contents Section 1 About this guidance 4 Section 2 What is the Data Protection Act? 5 Section 3 Recruitment

More information

Key Rules for General Insurance Brokers

Key Rules for General Insurance Brokers Key Rules for General Insurance Brokers Contents 1. Introduction 3 2. Principles for businesses 6 3. Conduct of business rules 7 Financial promotion 7 Initial disclosure 9 Arranging and suitable advice

More information