Compliance guide: Data protection. A practical guide to meeting your regulatory and best practice obligations

Size: px
Start display at page:

Download "Compliance guide: Data protection. A practical guide to meeting your regulatory and best practice obligations"

Transcription

1 Compliance guide: Data protection A practical guide to meeting your regulatory and best practice obligations

2 Contents Introduction 3 5 Principle 1: Data must be fairly and lawfully processed 4 5 Principle 2: Data must be processed for limited purposes 7 6 Principle 3: Data must be adequate, relevant and not excessive Principle 4: Data must be accurate and up to date Principle 5: Data must not be kept for longer than is necessary Principle 6: Data must be processed in line with the data 18 subject s right Principle 7: Data must be secure Principle 8: Data must not be transferred to other countries without adequate protection Glossary Please note that this guide should not be taken as legal advice. Its purpose is simply to promote compliant activity and best practice. If you have any legal concerns, you should seek independent legal advice. 2

3 Introduction The Data Protection Act Under the Data Protection Act (1998), an individual has several rights in relation to their personal data. The act aims to balance these rights against the legitimate needs of an organisation to process personal data. It is underpinned by eight common sense principles. Personal data must: Be fairly and lawfully processed Be processed for limited purposes Be adequate, relevant and not excessive Be accurate and up to date Not be kept for longer than is necessary Be processed in line with the data subject s rights Be secure Not be transferred to other countries without adequate protection If you are involved with the processing of personal data, you will be required by law to comply with the Data Protection Act. The Experian UK Compliance team have written this guide to help you understand the eight principles and fulfil your obligations under the act. The Information Commissioners Office (ICO) The Information Commissioner s Office is an independent authority who is responsible for promoting awareness, good practice and ensuring compliance within the Data Protection Act. Where appropriate, the Information Commissioner has powers to issue enforcement notices for organisations to take steps or introduce methods in order to be compliant with the act. The ICO can also impose financial penalties on organisations where there has been a serious breach of the act. The ICO also maintains a list of organisations that process personal data. The Data Protection Register is available to the public on the ICO website, uk and describes the type of data and the purpose for which it will be processed. It is a requirement of the Data Protection Act to notify the Information Commissioner of this information. Details of how to notify the ICO can be found on their website. Alternatively, please see our Guide for Small to Medium Businesses copies can be obtained from the Experian UK Compliance Team (contact details at the back of this guide) OUR AIM To ensure that Experian s Compliance Department is a centre of excellence; developing robust, professional, reliable and effective policies and processes, which underpin and fully support the business in meeting its regulatory and best practice obligations. 3

4 Principle 1: Data must be fairly and lawfully processed Obtaining data In order to ensure that you are processing personal data fairly, you must have a legitimate reason for processing the data. The individual should also be aware of and understand exactly how you are going to use their data. This is particularly important where the individual has a choice about whether to enter into a relationship with you. Being open and clear about how you are going to process an individual s data allows them to make an informed decision, and therefore your processing is more likely to be considered fair. The Experian UK Compliance team have written a set of Fair Processing Notices (FPN) to help our clients ensure that they are obtaining data from individuals fairly. They can be found on our website: responsibilities/compliance/fairobtaining-clauses.html Our FPN have been endorsed by the Information Commissioner s Office and can be directly used by our clients, or adapted to suit their business and products. Obtaining personal data fairly also means that it must be provided by someone who is legally authorised or required to do so. You must also ensure that your FPN covers all purposes for processing that are specific to your business. The impact of processing In addition to ensuring that data is obtained fairly, the general impact on the individual of processing their personal data should also be considered. 4 Processing that has an adverse effect on the individual is not necessarily unfair, the important issue is whether or not the negative affect is justified. Conditions of processing The Data Protection Act stipulates that you must be able to satisfy one or more of the conditions for processing as set out in Schedules 2 and 3 of the act. Satisfying one or more of the conditions does not guarantee that your processing is fair and lawful. However, having a legitimate reason and processing data fairly will usually mean that you are able to satisfy at least one of the conditions below: The data subject has consented to the processing Or the processing is necessary: In relation to a contract which the individual has entered into Because the individual has asked for something to be done so they can enter into a contract Because of a legal obligation that applies to you (except obligations imposed by a contract) To protect the individual s vital interests (see definitions on p32) For the administration of justice, or for exercising statutory, governmental, or other public functions To pursue legitimate interests When processing sensitive personal data, you must also be able to satisfy one of these conditions: The data subject has given their explicit consent The processing is done by a none profiting organisation and does not involve disclosing personal data to a third party, unless the individual consents to this (Extra limitations apply) The data subject has deliberately made the information public Or the processing is necessary: In order to be compliant with employment law To protect the vital interests of the data subject or another person (where the individual s consent has been unreasonably withheld) In relation to legal proceedings; for obtaining legal advice; or otherwise for establishing, exercising or defending legal rights For the administration of justice, or for exercising statutory or governmental functions For medical purposes, and is undertaken by a health professional or someone who is subject to an equivalent duty of confidentiality To monitor equal opportunities Lawful processing The term lawful is not defined within the Data Protection Act. Many areas of law are complex and therefore neither Experian, nor the Information Commissioner s Office can be expected to be knowledgeable or expert in all of them. Some unlawful acts are obvious, for example committing of a crime. However, lawful includes both statute and common law, whether criminal or civil. If you have any doubts about whether or not your processing is lawful, you should seek independent legal advice.

5 Case Study: Principle 1 The newspaper subscription A newsagent offers a newspaper delivery service to its local customers. Individuals complete a short form with their name, address and choice of newspaper(s) in order to sign up for the service. The newsagent collects and stores this personal data, as it needs to know which newspapers to deliver to which customers and at which address they live. There is a short paragraph at the bottom of the registration form explaining to customers that their personal data will be used for the purposes of providing and maintaining the service, it also explains that the personal data may be passed to third parties for the same purpose. The customer then signs the form consenting to the processing of their personal data as per the explanation on the registration form. The data has been obtained fairly, because it has been explained to the customer exactly how their information will be used. The customer has made an informed decision to consent to the processing of their personal data as described on the registration form. Some conditions of processing, have been satisfied, as the customer has given their consent and the processing is required in relation to the agreement that the customer has entered into with the newsagent. The newsagent would not be able to use or pass details of its customers to a third party for marketing purposes, as this has not been specified in the agreement on the registration form and therefore would be considered unfair. The newsagent is carrying out their daily paper round and arrives at one of their customer s property to deliver their newspaper. The newsagent notices through the window that the customer has collapsed and is on the floor unconscious and calls for an ambulance. The customer is well known to the newsagent and the newsagent is aware that they have a serious medical condition. Although the individual may be embarrassed that others will know about their medical condition, the negative impact of embarrassment is justified as it is in the interests of the customer that the newsagent s knowledge of their medical condition is disclosed. Given that the customer has a serious medical condition. It is likely that disclosing this information in this scenario satisfies the vital interests condition of processing. 5

6 Checklist: Principle 1 Has the individual consented to the processing of their data? Do they clearly understand exactly how their data will be used? Have you considered the potential impact on the individual of processing their data? Can any negative impacts be legitimately justified? Are you able to satisfy at least one of the conditions of processing? Will you be processing any sensitive personal data? If so, are you able to satisfy at least one of the additional conditions of processing? Is the processing lawful? / Have you considered any legal obligations or implications? See Glossary for explanation of terms Notes: 6

7 Principle 2: Data must be processed for limited purposes Specified purposes The second principle of the Data Protection Act states that you must specify the purpose(s) for which you will process data. In addition, it states that you must not process personal data in any manner incompatible with that purpose or those purposes, i.e. you may only process data: For the purpose(s) that you have specified Or: For a purpose that is in relation to the purpose(s) you have specified and could be reasonably expected by the data subject The aim of this principle is to ensure that organisations: Are open and clear about why they are obtaining data and how they will use it Are compliant with the fair processing requirements of the Data Protection Act as discussed in Principle 1 (pages 5 and 6) Who wish to use personal data in any new or additional purposes do so in a way that is fair to the individual New or additional purposes If you wish to use personal data for a purpose that is incompatible with the purpose(s) for which it was originally obtained, it is usual that you would need to obtain additional consent from the individual concerned prior to processing their data for the new purpose(s). This links with the first data protection principle of processing data fairly (see pages 5 and 6). Being specific about the purposes for which you wish to obtain and process data also helps to determine what information you should provide to the data subject in your fair processing notices. Notifying the Information Commissioner s Office It is a requirement of the Data Protection Act that organisations notify the ICO of the types of personal data that they intend to process and the purposes for which they intend to process it. All organisations are required to register their notification with the ICO, unless they are exempt from notification. Exempt organisations must still comply with the rest of the provisions of the Data Protection Act and may choose to notify voluntarily. Details of how to notify the ICO and guidance on exemptions from notification can be found on their website, Registrations must be updated if you wish to process data for any new or additional purposes and must be renewed annually, even if there are no changes. You should also update your registration with the ICO if there are any changes in the Data Controller s name, address or contact details. It is a criminal offence to fail to notify the ICO or renew your registration unless you are exempt from notification 7

8 Case Study: Principle 2 The mailing list A DVD rental company creates and uses a mailing list to notify its customers of promotional offers and new movie releases. Customers who wish to receive marketing of this nature sign up to the mailing list and can ask to be taken off it at any time. The registration form does not include notification or request consent to pass the individual s data to any 3rd parties. As the company have notified the individual that their data will be used specifically for marketing purposes (and the individual has consented to this), it is acceptable to send a regular newsletter or similar marketing material to them. The company expands its business to include rental of video games. To encourage uptake of this new service, the company wish to advertise it to customers on their existing mailing list. As the new video game rental service is of a similar nature to DVD rentals, the customer could reasonably expect to receive information and offers relating to this. Therefore it is likely to be considered compatible with the original purpose and so it would be acceptable to include information and offers on the new product offering in their material that is sent to customers on the existing mailing list. 8

9 Checklist: Principle 2 Have you registered a notification with the ICO? Have you specified to the individual the purpose(s) for which you are obtaining and processing their personal data, e.g. Fair Processing Notice as discussed on pages 5 and 6? Are you processing the data only for the purpose(s) that you have specified? Do you anticipate or intend to process the data for any new or additional purposes? If so, are you processing the data in a way that could be reasonably expected by the data subject? Have you obtained consent from the individual to process the individual s data for the new purpose(s) (if they could not already reasonably expect their data to be processed in this way)? See Glossary for explanation of terms Notes: 9

10 Principle 3: Data must be adequate, relevant and not excessive Establishing what is adequate, relevant and not excessive The Data Protection Act states: Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed Although the Data Protection Act does not specifically define the terms, in order to be able to measure whether data is adequate, relevant and not excessive ; you need to be clear about the purpose for which you are processing it (see details of the second DPA principle). To ensure that you are compliant with the act, you should: Identify the minimum amount of personal data that would be sufficient to fulfil the purpose for which you are processing it Obtain, process and store that amount of personal data no more and no less Not hold any personal data on the off-chance that it could be useful in the future You should also consider the terms Adequate, Relevant and Not Excessive in relation to each data subject. Information that is required for a certain person may be excessive in relation to another individual. This, in addition to the points previously mentioned, is especially important in relation to sensitive personal data. Adequacy and relevance in relation to opinions An opinion about an individual is considered to be their personal data. To comply with the Data Protection Act, it is important to ensure that there is sufficient information for an opinion and its context to be interpreted correctly. This could include the name and position of the author and / or evidence of the circumstances that the opinion is based on. 10

11 Case Study: Principle 3 The gym membership A local leisure centre operates a membership scheme. Upon registration for the scheme, customers fill in a form with their personal details including their name, address, date of birth, contact details, some health information and bank details in order to set up a direct debit for payment of the membership fee. The data collected is adequate in order to for the leisure centre to be able to identify their customer and administer the membership (for example contact and payment in relation to the membership). Health information will be relevant for some customers, for example certain health conditions may mean that a customer is not able to use certain items of equipment, or may require assistance from staff in certain circumstances. The data that the leisure centre is requesting and processing is not excessive as they are only asking for information relevant for the purpose of administration of the customer s membership. If irrelevant information is obtained, such as a customer putting in their health information that they had the flu several years ago, should be deleted. 11

12 Checklist: Principle 3 Have you identified the minimum amount of data you require for the purpose you wish to process it? Is the amount of data you are collecting sufficient (adequate) for its purpose? Is all of the data you are collecting relevant to the purpose for which you are processing it? Are / will you be processing any sensitive personal data? (If so, consideration of the above is especially important!) Does / could the data you hold contain opinions about an individual? If so, is the context of the opinion clear and is it clear whose opinion it is? See Glossary for explanation of terms Notes: 12

13 Principle 4: Data must be accurate and up to date Accuracy of data In order for data to be accurate, it must not be incorrect or misleading as to any matter of fact. The context in which the data is held can also affect whether or not it is accurate. For example, if an individual works for Company A and then moves to a new job within Company B, it would be inaccurate to say the individual works for Company A. However, it would still be accurate to say that the individual used to work for Company A. If data that has been recorded is then deemed to be inaccurate, it should be amended or deleted. In certain circumstances, it would be impractical to check and double check every single item of data you receive and the Data Protection Act recognises this. The legislation therefore makes special provision about the accuracy of information that is obtained from the data subject themselves or that is provided by a third party. Regarding the accuracy of personal data provided by the data subject or obtained from a third party, you must: Accurately record the information as it has been provided to you, i.e. by the data subject or third party Take reasonable steps to ensure that the data is accurate Make it clear if the accuracy of the information has been challenged, such as by adding a note Reasonable steps The definition of the term reasonable steps will vary, depending on the type of data and the purpose for which it will be processed. The greater the potential impact of processing the data, the more important the accuracy of it is and therefore the greater the effort you should make to ensure that it is accurate. Challenged accuracy If the data subject challenges the accuracy of data you hold about them, although it is not a legal obligation to mark the record as being in dispute it is good practice to do so. The advantage of this is that, if it does transpire that the data is inaccurate, you are not likely to be found in breach of this principle - as long as you have met the other criteria in the three points previously described above. Keeping data up to date Whether or not data needs to be updated, and the frequency that it should be updated, usually depends on the purpose(s) for which it is being processed. This is usually fairly obvious i.e. if the purpose for which data is being processed is reliant upon it being up to date (for example an organisation that delivers goods to a customer s address), it is important to ensure that the information is up to date. Recording and retaining a record of mistakes As long as an organisation s records are accurate and not misleading, it is deemed acceptable within the Data Protection Act to retain a record of mistakes that have occurred. It should be made clear that a mistake has occurred, for example by adding notes to the information. 13

14 Case Study: Principle 4 The Credit Reference Agency Credit Reference Agencies obtain data from a variety of public and financial sources about individuals, for multiple purposes, such as helping banks and other companies make decisions about whether to lend money to them or not. One of the sources of data is financial information from organisations that the data subject already has dealings with, for example in relation to an existing loan agreement. Banks and other creditors provide regular feeds of data (usually monthly) to the Credit Reference Agency. As the data is being provided to the Credit Reference Agency by a third party, i.e. the existing loan account information from the data subject s bank, the information can be deemed accurate, as long as it is recorded correctly as has been provided by the lender. Because credit referencing data can have a significant impact on the data subject, i.e. it can affect credit decisions made about them. Althought the data has been obtained from a lender, the Credit Reference Agency must take reasonable steps to ensure its accuracy. It does this, by conducting tests on a sample of data received each month to check for any discrepancies or inconsistencies. The Credit Reference Agency ensures that they are keeping data from lenders and other sources up to date by obtaining regular (usually monthly) updates from its sources. An individual obtains a copy of their credit report and notices that it shows a mistake. They contact the Credit Reference Agency to notify them of the inaccuracy. The Credit Reference Agency takes reasonable steps to ensure the accuracy of the data by contacting the third party that provided it (for example, a lender). In the meantime, they add a dispute notice to the item of data, so that anyone viewing it while the accuracy of the data is being challenged will be aware that it may be inaccurate. The individual could also add a notice of correction to explain circumstances surrounding information on their credit report, for example late payments due to losing their job unexpectedly. 14

15 Checklist: Principle 4 Are you obtaining data from either the data subject or a third party? If so, how will you make sure you record the data accurately as it is provided to you? What reasonable steps will you take to ensure that the data you process is accurate? Have you considered the impact of inaccurate data? Do your reasonable steps reflect this? What process do you have in place for when an individual disputes the accuracy of the data you hold? What process do you have for correcting the data? How often will you update the data? Is your frequency of updates sufficient for the purpose(s) for which you are processing the data? See Glossary for explanation of terms Notes: 15

16 Principle 5: Data must not be kept for longer than is necessary Retention of personal data The Data Protection Act does not specify how long you should retain data for, it simply states: Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. As with some of the other principles, this suggests that, in order to decide how long you should keep data for, you need to be clear on the purpose(s) for which you intend to use it. You must also ensure that information is securely deleted or disposed of when it is no longer required for its specified purpose. Data which is still required for the specified purpose, however is not accessed regularly, should be archived and stored securely. It is important to regularly review the personal data you hold and delete or archive it as appropriate. Defining retention periods It is a good idea to consider the following points, as they may help you to decide on how long your retention periods should be: The purpose for which the data will be processed. Any surrounding circumstances, e.g. whether or not you still have dealings with the data subject. Legislation and regulatory requirements. Agreed practice within the industry. You should also consider the implications of retaining data, for example: Larger capacity may be required in order to store larger amounts of data, i.e. if data is needed and kept for a long time. You must be able to satisfy a data subject s request for access to their personal data. This could be more difficult if you retain data for longer than you need it. It may be more difficult to verify the accuracy of data that was obtained a long time ago. Data may become out of date and could be used in error. Data should not be retained just in case however it is acceptable to retain data for foreseeable circumstances that may only happen occasionally. The data should still only be kept for as long as the purpose for which it is stored is reasonably foreseeable, and there must always be a genuine business reason for keeping it. Depending on the size of your business, you may wish to create a data retention policy to define the periods for which you are going to hold data and to ensure consistency across your organisation. Your policy should also be reviewed from time to time to ensure that it is still appropriate. 16

17 Case Study: Principle 5 The online account An independent online music retailer has a mixed customer base, ranging from DJ s who place regular orders with them to individual members of the general public that make one off purchases. When placing an order through the website, the customer is required to set up an online account by providing personal information and setting up login details, so that the order will be sent to the correct address and the customer can be identified should they have any enquiries or need to make any changes. The retailer should retain customer data long enough to fulfil the order and for a period of time after, as it is reasonably foreseeable that the customer may make queries or complaints following delivery of their order. It is the retailer s decision how long to keep the data for, however they should be able to justify the chosen timescale and ensure that it is not longer than necessary. When signing up for an online account, customer s have the option to receive regular updates and promotions from the retailer. A customer that had previously opted into the marketing, then contacts the retailer and states that they no longer wish to receive this information. Most of the data that was originally collected for marketing purposes, for example details of the customer s music preferences, will no longer be required and therefore should be deleted. It is however, permissible to retain enough information to ensure that marketing is no longer sent to that particular customer. Regular customers returning to the retailer s website in future to place further orders will find it more convenient if they can just log in and do not have to reenter all of their personal details, however this reason alone would not justify keeping their data indefinitely. Personal data of customer s who have not placed an order for some time should therefore be deleted. 17

18 Checklist: Principle 5 Have you defined the retention periods for which you will keep each type of data you hold? Are the retention periods sufficient and not excessive in relation to the purpose(s) for which you are processing the data? Have you considered legislative and regulatory obligations when deciding on retention periods? Have you considered any agreed practices within your industry? Do you have the facility and capacity to keep data for the length of time you require? Is there a data retention policy in place within your organisation? See Glossary for explanation of terms Notes: 18

19 Principle 6: Data must be processed in line with the data subject s rights Rights under the Data Protection Act The Data Protection Act sets out the rights that an individual has in terms of their personal data. Principle 6 of the act states that personal data must be processed in line with these rights. If an individual is not satisfied that you are processing their data within their rights under the act, they can apply to a court to order you to do so. Access to personal data Section 7 of the DPA states that an individual is entitled to know whether a data controller is processing personal data about them, including a description of the type of data being processed, the purpose for which it is being processed and to whom the data may be disclosed to. Section 7 of the act also stipulates that an individual is entitled to request a copy of their personal data that an organisation holds on them. Data Subject Access Requests (DSAR) A DSAR is the request made by the data subject, to obtain a copy of their personal data from an organisation. As the data controller, you are obliged to supply this information when: The request has been made in writing. You have received such fee that you may require (the maximum amount you can charge is 10). The time specified within which you must comply with the DSAR is 40 calender days. You are however also entitled to request additional information in order to either identify the individual, or to enable you to satisfy the request for information. An example of this could be details that will help you to locate the data that the individual is requesting. If you reasonably require such additional information and have requested it, you are not obliged to release the data until you have received the additional information. You should also consider whether releasing data on the individual requires you to disclose another person s personal data. If this is the case, you are only obliged to supply the data if: The other individual has given their consent Or: It is reasonable in all circumstances to comply with the DSAR without the consent of the other individual. Consideration should be given to any applicable duty of confidentiality, steps taken to obtain consent, whether the other individual is capable to give consent and any express refusal of consent by the other individual. Prevention of processing that is likely to cause damage or distress An individual has the right to give notice that an organisation must cease to process their personal data, if that processing is causing, or is likely to cause substantial and unwarranted damage or distress. The objection to the processing should be made in writing and specify the reasons for which damage or distress is being or could be caused. An individual does not have the right to object to processing in certain circumstances. These include: Where the individual has consented to the processing. Or when the processing is necessary: In relation to a contract that the individual has entered into. Because the individual has asked for something to be done to enable them to enter into a contract. In relation to your legal obligations To protect the individual s vital interests. As the data controller, an organisation should respond to the individual within 21 calender days. You must either confirm that you will be complying with the notice, or give the reasons for which you believe the notice to be unjustified. 19

20 Prevention of processing for direct marketing The Data Protection Act defines direct marketing as the communication (by whatever means) of any advertising or marketing material which is directed to particular individuals. An individual has the right to ask an organisation not to process or to cease processing their personal data for this purpose. The request can be made at any time and must be complied with by the data controller. A response to such request should be sent to the individual within 21 calendar days Prevention of automated decision making An individual has three rights in relation to automated decisions made about them and which may have a significant impact on them. Examples of significant decisions defined within the Data Protection Act are performance at work, creditworthiness, reliability and conduct. The first right is the right to prevent automated decision making. You must not make an automated decision where an individual has provided a written request not to. Individuals also have the right to be informed when an automated decision has been made. An organisation must notify the individual that an automated decision has been made using their personal data as soon as is reasonably practicable to do so. Finally, an individual has the right to request that an automated decision is reconsidered or reviewed. The individual has 21 days from when they are notified of the automated decision to appeal against it. As the data controller, you have 21 calendar days within which you must respond to the individual. There are some automated decisions which are exempt from the individual s rights under the act. These include decisions that are: Authorised or required by legislation. Made in preparation or in relation to a contract with the individual who is the data subject. To give the individual something that they have requested. Or: Where safeguards have been put in place to protect the individual s legitimate interests, for example allowing them to appeal the automated decision. Recification, blocking, erasure and destruction of data The fourth principle covers the accuracy of data. In the event that personal data is inaccurate, the data subject can apply to the court to have the data rectified, blocked, erased or destroyed. Alternatively, the court may order you to add a statement of true facts to the record that contains the personal data (any such statement must be in terms approved by the court). It is good practice to take reasonable steps to notify any third parties of changes to or deletions of inaccurate personal data. The court may also order you to do this, however they are only likely to do so if it is reasonably practicable to comply with the request. Compensation The Data Protection Act gives individuals the right to compensation for damage or distress caused by the data controller failing to comply with their obligations under the act. The DPA does not specifically define damage, however if an individual has suffered financial loss as a result of a breach of the act, then they are likely to be entitled to compensation. Distress alone is not usually sufficient to entitle an individual to compensation. The act states that an individual will only be entitled to compensation in relation to distress, if damage has also been suffered as a result of contravention of the act, or the breach relates to the processing of personal data for special purposes. The DPA also allows you to defend a request for compensation, on the basis that you took all reasonable care in the circumstances to avoid the breach. 20

21 Case Study: Principle 6 The letting agent An individual contacts their local letting agent, to enquire about a property that the agent is advertising for rent. Prior to arranging a viewing, the agent asks the individual to register with them, so that they can check the individual meets their criteria as a suitable tenant. The agent would also like to contact them about any other properties that they think the individual may be interested in. As part of the registration process, the individual signs the letting agent s terms and conditions, which include consent to a credit check being undertaken. As part of the terms and conditions, the individual also agrees that the letting agent may contact their previous landlords for tenant references. As the individual has consented to the processing of their personal data as part of the registration, they do not have the right to request that the letting agent ceases processing that is in relation to the contractual agreement. When conducting the credit check, the letting agent uses an automated system to score the individual s application. The decision is then produced automatically based on the automated scoring. The individual may exercise their right to prevent automated decision making and ask the letting agent to conduct the credit check manually. The letting agent could satisfy this request by putting an appeals process in place for applications that are declined as the result of an automated check. If the individual was declined, they could then have a manual decision made by following the appeals process. The letting agent sends out a weekly update, including details of new properties that are available to rent. After the individual has found and moved into their new home, they decide that they no longer wish to receive this marketing and contact the letting agent to advise them of their request. The letting agent is obliged to comply with the individual s right to prevent direct marketing and must respond to the individual within 21 calendar days. The individual decides that they would like to see a copy of their personal data that the letting agent holds about them. They write a letter to the letting agent requesting the information and enclose a cheque for 10. The letting agent is obliged to satisfy the Data Subject Access Request (DSAR) and must ensure that they have adequate procedures in place to locate and provide the individual with a copy of their personal data. 21

22 Checklist: Principle 6 Do you have a process in place to deal with Data Subject Access Requests, i.e. would you be able to identify, locate and supply a copy of all of an individual s personal data, if they were to ask for it? Have you considered whether your processing of an individual s personal data is likely to cause them damage or distress? If an individual asks you to stop marketing to them, would you be able to easily comply with this request? Does your business make any automated decisions? If so, is there a process in place to make manual decisions if an individual requests you to do so, e.g. a referral or appeals process? Do you have a procedure in place to handle compensation requests, for example as part of a complaints procedure? See Glossary for explanation of terms Notes: 22

23 Principle 7: Data must be secure Information security The Data Protection Act states that a data controller must take appropriate technical and organisational measures to protect personal data from being compromised. The measures appropriate will depend on the nature of the personal data that you hold and the impact or harm that could result in the event of a security breach. Data that is particularly valuable, sensitive or confidential is likely to have a more significant impact if it were to get into the wrong hands or be used in an inappropriate way. In order to protect personal data and keep it secure, it is important to: Create and implement robust policies and procedures regarding information security Put in place sufficient physical and technical security that is appropriate to the data you hold Train staff to ensure that they are aware of and are able to meet their obligations Be clear about who within your organisation is responsible for ensuring information security Be prepared and able to respond to any breach of security swiftly and effectively Although the act does not define the term appropriate, you should take a risk based approach which takes into account technological advances and the cost involved in relation to information security. You should also regularly review the data you hold, how you use it and how you protect it in order to ensure that the security measures in place remain appropriate. Security within the DPA also extends to state that the data controller must: Take reasonable steps to ensure the reliability of employees Obtain guarantees from any data processor working on their behalf in respect of using adequate protection to keep personal data secure. Put in place a written contract with the data processor, under which they are only able to act under the data controllers instructions and must comply with equivalent obligations to those under the DPA. Breach management It is important for an organisation to consider how they would react and respond to a breach, as breaches can occur even when there are appropriate security measures in place. A good breach management plan can help damage limitation and aid recovery from the breach. There are four main topics to consider when creating and implementing a breach management plan: Containment and recovery: reaction to an incident should include a recovery plan and procedures to limit any damage caused by the breach. Risk Assessment: will help you to establish actions to take in response to the breach and learn how to prevent future breaches of a similar nature. Notification: you should consider who needs to be notified and why. Examples of who you may consider making aware of the breach include the data subject(s) concerned, the ICO, other regulatory bodies, the police or the media. Evaluation and response: It is important to investigate causes of the breach and evaluate the effectiveness of your reaction and response to it. You should take the opportunity to learn from a breach and update any policies, procedures and other security elements where necessary. Further information There is further information in relation to breaches and breach management on the ICO website: You can also find further information and advice on information security at the following sites: General Information Security: infosecadvice/page10059.html Information Security Advice for Small and Medium Businesses: E-Learning Package: 23

24 Case Study: Principle 7 The travel agent A travel agent obtains a variety of information from its customer s, including their general details such as name and address, passport number and payment details. For customers who wish to arrange travel insurance through the agent, sensitive health information is also collated. Sensitive data, such as health and payment information could cause a great deal of damage or distress to the individual concerned if it were to be compromised. Therefore the travel agent should take extra care to ensure the data is kept secure. As part of its information security measures, the travel agent creates and implements an information security policy. The policy sets out a wide range of procedures to protect the organisation s data, including verifying the identity of staff upon employment and obtaining references from former employers to confirm reliability. The travel agent is meeting its obligation to take reasonable steps to ensure the reliability of its employees by implementing this element of the policy. Employees should be trained to ensure that they understand and meet their obligations regarding keeping data secure. The travel agent should also ensure that it is clear about who within the organisation is responsible for information security to ensure that a high standard is maintained. To keep data physically secure, the travel agency also adopts a number of physical security measures. These include building security, such as alarms and window shutters, coded locks on rooms where personal data is held, confidential waste bins to ensure secure disposal of waste, and password protected access to systems. The Data Protection Act does not define what is an appropriate level of security. These are just some of the ideas that your organisation may wish to consider. The travel agent discovers that it has been the victim of an information security breach. An employee is suspected of selling lists of customer information to a third party and is suspended while an investigation takes place to prevent any further misuse of data. It is important that the travel agent has a breach management system in place to limit the damage caused by the misuse of data and prevent similar occurrences in future. It should also be considered whether anyone should be notified of the breach. If the employee was found to be guilty, the organisation may choose to involve the police. They should also decide whether to notify the Information Commissioner and the individuals that the compromised data relates to. 24

25 Checklist: Principle 7 Do you have an information security policy in place? Is there a designated individual within your organisation who is responsible for information security? Have you put in place adequate physical security measures, in relation to the level of sensitivity of the personal data you hold? Do you have a training course / programme that must be completed by all employees? Do you take reasonable steps to ensure the reliability of your employees? Have you considered how you would handle an information security breach and put relevant policies and procedures in place? See Glossary for explanation of terms Notes: 25

26 Principle 8: Data must not be transferred to other countries without adequate protection The principle The Data Protection Act states: Personal data shall not be transferred to a country or territory outside the EEA unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. Transferring data Transferring data means sending personal data to someone (in another country). If data can be accessed in another country outside of the EEA, for example on a website, then this is also considered a transfer. However, a transfer does not include data passing through another country on route to its destination. For example if you transfer data from the UK, via a server in country A to its destination country B as long as the data is not accessed or manipulated in any way while in transit, the eighth principle of the DPA will only apply to the data having been transferred to country B. It is good practice to consider whether you need to process personal data or whether you can still meet your requirements by making the data anonymous. If it is not possible to identify individuals from the data (now or at any point in the future), then the data protection act does not apply and you would therefore be free to transfer data outside of the EEA. European Economic Area (EEA) Countries Personal data can currently be transferred freely within the EEA without restriction. The current EEA member countries are listed below: Austria Belgium Bulgaria Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Hungary Iceland Ireland Italy Countries with an adequate level of protection The European Commission has deemed some other countries to have an adequate level of protection for personal data and therefore data can be transferred to these countries: Argentina Canada Guernsey Latvia Liechtenstein Lithuania Luxembourg Malta Netherlands Norway Poland Portugal Romania Slovakia Slovenia Spain Sweden Isle of Man Jersey Switzerland An up to date list of countries with an adequate level of protection can be found at the European Commission s data protection website: policies/privacy/thridcountries/ index_en.htm Although the USA is not included in the list above, US companies that are signed up to the Safe Harbour Scheme are considered to have an adequate level of protection. A list of companies that operate within the Safe Harbour Scheme can be found on the US department of commerce s website: safeharbor_index.asp Transferring data to other countries You may be able to transfer data to countries that are not approved as having an adequate level of protection. In order to do this, you should do at least one of the following: Assess the adequacy yourself. Use contracts to ensure that an adequate level of protection is provided. You may wish to include the model contractual clauses approved by the European Commission. Operate Binding Corporate Rules and have these approved by the ICO. Alternatively, an exception to the rule may apply to some transfers. Assessing Adequacy of Levels of Protection in Other Countries: In order to assess whether an adequate level of protection is in place in another country, you should carry out a risk assessment which takes into consideration the following factors. These have been set out within the Data Protection Act: The nature of the personal data being transferred. Where the data is being transferred to and the laws, obligations and practices adopted by that country (and to what extent). 26

27 The purpose(s) and period for which the data will be processed. Whether it can be ensured that the required standards are achieved in practice. Any procedure under which individuals can enforce their rights or obtain compensation if things go wrong. There are documents that offer further guidance on assessing levels of adequacy available on the ICO website: Using contracts to ensure adequate levels of protection Another way to ensure that adequate levels of protection are in place in another country that you are transferring data to, is to put a contract in place between you and the organisation to which you are transferring the data. You can either create a contract yourself within your organisation, or you may wish to use the European Commission s approved model clauses. The model clauses are attached as an annex to the European Commission decisions of adequacy, which approve their use. This can be found on the European Commission s website: privacy/modelcontracts/index_ en.htm If you intend to use the European Commission s model clauses, you are not able to amend them in anyway, such as removing parts or adding additional clauses to change the meaning. You can however, incorporate the clauses into other contracts instead of having two separate documents. If you choose to have a contract drawn up yourself, you do not have to have a separate contract relating to data protection. The clauses can be incorporated into any general contract you have that covers your relationship with the company concerned. You should however, ensure that your contract is comprehensive to minimise the risk of the contract s adequacy being challenged in future. Transfers approved by the information commissioner Only in exceptional circumstances, the Information Commissioner may authorise transfers of personal data on the basis that there is an adequate level of protection. Although the ICO has the power to do this, it would only be done in cases where the ICO can be satisfied that there is absolutely no other way to satisfy the eighth data protection principle. Binding corporate rules Binding Corporate Rules (BCR) are codes of corporate conduct that can be implemented within multi-national organisations. They are legally binding and are usually implemented through the use of intra-group declarations, agreements or corporate governance. BCRs give rights to individuals, which can be exercised before the courts or data protection authorities. The standard of an organisation s Binding Corporate Rules must be assessed by all of the relevant European data protection authorities in order to use them freely transfer personal data outside of the European Economic Area (EEA), within a group of companies. Exceptions It is always good practice to ensure, where possible, that there is an adequate level of protection for an individual s personal data when transferring it outside of the EEA. There are however, some exceptions that allow you in certain circumstances to transfer personal data, even where there may not be an adequate level of protection. The exemptions are: Where consent to transfer the data has been obtained from the individual (it is worth noting that the consent cannot be relied upon where the individual has no choice but to consent). If the data is part of a public register (as long as the recipient complies with restrictions regarding access and use of the information). Or the processing is necessary: In relation to contractual performance, where the contract that has been entered into is with the individual or is in their vital interests. For reasons of substantial public interest, such as the prevention and detection of crime, national security and tax collection. The public interest must be that of the UK and this exemption should be considered very carefully on a case by case basis. To protect the vital interests of the individual. In relation to legal proceedings. 27

technical factsheet 176

technical factsheet 176 technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection

More information

Data Transfer Policy London Borough of Barnet

Data Transfer Policy London Borough of Barnet London Borough of Barnet DATA PROTECTION 11 Document Control Document Description Data Transfer Policy Version v.2 Date Created December 2010 Status Authorisation Name Signature Date Prepared By: IS Checked

More information

Summary of Data Protection Requirements When transferring Data Outside the UK End Users

Summary of Data Protection Requirements When transferring Data Outside the UK End Users Summary of Data Protection Requirements When transferring Data Outside the UK End Users 14 May 2010 Background to transfers of the Data outside the UK Data can be transferred in a couple of ways in relation

More information

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person.

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person. PART I: INTRODUCTION AND BACKGROUND Purpose This Data Protection Binding Corporate Rules Policy ( Policy ) establishes the approach of Fluor to compliance with European data protection law and specifically

More information

Data Protection Policy Information for Clients

Data Protection Policy Information for Clients Data Protection Policy Information for Clients Foreword This document outlines Numis Securities Limited s ( the Firm or Numis ) legal obligations and policy on data protection. Further information can

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data;

OBJECTS AND REASONS. (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; OBJECTS AND REASONS This Bill would provide for (a) the regulation of the collection, keeping, processing, use or dissemination of personal data; (b) the protection of the privacy of individuals in relation

More information

CABINET OFFICE THE CIVIL SERVICE NATIONALITY RULES

CABINET OFFICE THE CIVIL SERVICE NATIONALITY RULES ANNEX A CABINET OFFICE THE CIVIL SERVICE NATIONALITY RULES Introduction The Civil Service Nationality Rules concern eligibility for employment in the Civil Service on the grounds of nationality and must

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title Author Approved By and Date Review Date Mike Pilling Latest Update- Corporation May 2008 1 Aug 2013 DATA PROTECTION ACT 1998 POLICY FOR ALL STAFF AND STUDENTS 1.0 Introduction 1.1 The Data Protection

More information

Data Protection in Ireland

Data Protection in Ireland Data Protection in Ireland 0 Contents Data Protection in Ireland Introduction Page 2 Appointment of a Data Processor Page 2 Security Measures (onus on a data controller) Page 3 8 Principles Page 3 Fair

More information

Dublin City University

Dublin City University Dublin City University Data Protection Policy Data Protection Policy Contents Purpose... 1 Scope... 1 Data Protection Principles... 1 Disclosure of Personal Data... 2 Summary of Responsibilities... 3 Rights

More information

EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update. By Stephen H. LaCount, Esq.

EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update. By Stephen H. LaCount, Esq. EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update By Stephen H. LaCount, Esq. Overview The European Union Data Protection Directive 95/46/EC ( Directive ) went effective in

More information

GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT. CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4

GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT. CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4 GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4 PREFACE The following provides general guidance on data protection

More information

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Controller Policy Contents INTRODUCTION 3 PART I: BACKGROUND AND ACTIONS 4 PART II: CONTROLLER OBLIGATIONS 6 PART III: APPENDICES 13 2 P a g e INTRODUCTION

More information

Data Protection. Policy and Application July 2009

Data Protection. Policy and Application July 2009 Data Protection Policy and Application July 2009 Produced for staff of the House of Commons Service by the Department of Resources Information Rights and Information Security (IRIS) Service Data Policy:

More information

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document Data Protection Processing and Transfer of Personal Data in Kvaerner Binding Corporate Rules Public Document 1 of 19 1 / 19 Table of contents 1 Introduction... 4 1.1 Scope... 4 1.2 Definitions... 4 1.2.1

More information

Personal Data Act (1998:204);

Personal Data Act (1998:204); Personal Data Act (1998:204); issued 29 April 1998. Be it enacted as follows. General provisions Purpose of this Act Section 1 The purpose of this Act is to protect people against the violation of their

More information

Employee eligibility to work in the UK

Employee eligibility to work in the UK Employee eligibility to work in the UK This document details legal requirements that apply to ALL new members of staff All employers in the UK are legally bound to comply with the Asylum and Immigration

More information

The eighth data protection principle and international data transfers

The eighth data protection principle and international data transfers Data Protection Act 1998 The eighth data protection principle and international data transfers The Information Commissioner s recommended approach to assessing adequacy including consideration of the issue

More information

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers Office of the Data Protection Commissioner of The Bahamas Data Protection (Privacy of Personal Information) Act, 2003 A Guide for Data Controllers 1 Acknowledgement Some of the information contained in

More information

Data Protection Policy June 2014

Data Protection Policy June 2014 Data Protection Policy June 2014 Approving authority: Consultation via: Court Audit and Risk Committee, University Executive, Secretary's Board, Information Governance and Security Group Approval date:

More information

PRINCIPLES OF THE TRANSFER OF PERSONAL DATA TO A THIRD COUNTRY. Introduction

PRINCIPLES OF THE TRANSFER OF PERSONAL DATA TO A THIRD COUNTRY. Introduction PRINCIPLES OF THE TRANSFER OF PERSONAL DATA TO A THIRD COUNTRY Introduction The continuous globalization of the world economy influences the international transfer of personal data. The transfer of personal

More information

Directive. for the transfer of personal data. to third countries outside the EEA

Directive. for the transfer of personal data. to third countries outside the EEA Directive for the transfer of personal data to third countries outside the EEA (Munich Re reinsurance group directive on third-country data transfer) Information correct at 1 July 2013 - 2 - Contents 1

More information

The European Union Savings Tax Directive. An historic guide

The European Union Savings Tax Directive. An historic guide The European Union Savings Tax Directive An historic guide Do you have any questions? This guide will tell you more If you are resident in an EU Member State and earn interest on deposits or investments

More information

The coordination of healthcare in Europe

The coordination of healthcare in Europe The coordination of healthcare in Europe Rights of insured persons and their family members under Regulations (EC) No 883/2004 and (EC) No 987/2009 Social Europe European Commission The coordination of

More information

Data Protection Policy and Code of Practice

Data Protection Policy and Code of Practice Data Protection Policy and Code of Practice All our written information can be made available, on request, in a range of different formats and languages. If you would like this document in any other language

More information

In May and July 2014 UK Visas and Immigration (UKVI) introduced changes to the right to work checks employers are required to carry out.

In May and July 2014 UK Visas and Immigration (UKVI) introduced changes to the right to work checks employers are required to carry out. Summary of changes - August 2014 In May and July 2014 UK Visas and Immigration (UKVI) introduced changes to the right to work checks employers are required to carry out. In light of the recent changes,

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1 Protection of Personal Data RPC001147_EN_WB_L_1 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Responsibility of Employees

More information

Family benefits Information about health insurance country. Udbetaling Danmark Kongens Vænge 8 3400 Hillerød. A. Personal data

Family benefits Information about health insurance country. Udbetaling Danmark Kongens Vænge 8 3400 Hillerød. A. Personal data Mail to Udbetaling Danmark Kongens Vænge 8 3400 Hillerød Family benefits Information about health insurance country A. Personal data Name Danish civil registration (CPR) number Address Telephone number

More information

Merthyr Tydfil County Borough Council. Data Protection Policy

Merthyr Tydfil County Borough Council. Data Protection Policy Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the

More information

Human Resources Policy documents. Data Protection Policy

Human Resources Policy documents. Data Protection Policy Policy documents Aims of the Policy apetito is committed to meeting its obligations under data protection law. As a business, apetito handles a range of Personal Data relating to its customers, staff and

More information

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY Originated by: Data Protection Working Group: November 2008 Impact Assessment: (to be confirmed) Recommended by Senate: 28 January 2009 Approved by Council:

More information

Guidance on Sponsorship

Guidance on Sponsorship Guidance on Sponsorship (Recruiting and Employing Non-EEA Nationals under Tier 2 of the UK s Points Based System) Human Resources 1 Introduction 1.1 These guidance notes set out the requirements in place

More information

DATA PROTECTION CORPORATE POLICY

DATA PROTECTION CORPORATE POLICY DATA PROTECTION CORPORATE POLICY Information Management V1.1 03 July 2012 Not protectively marked This policy must be complied with fully by all Members, Officers Agents and Contractors of Plymouth City

More information

Notes to help you apply for VAT registration checklist where to send your application Glossary About Corporate body the business

Notes to help you apply for VAT registration checklist where to send your application Glossary About Corporate body the business Notes to help you apply for VAT registration These notes will help you answer questions on form VAT1 Application for registration. The notes are numbered to correspond with the questions on the form. If

More information

DATA PROTECTION AUDIT GUIDANCE

DATA PROTECTION AUDIT GUIDANCE DATA PROTECTION AUDIT GUIDANCE CONTENTS Section I: Section II: Audit of Processing of Personal Data Audit Procedure Appendices: A B C D E Audit Form List of Purposes List of data subjects List of data

More information

Little Marlow Parish Council Registration Number for ICO Z3112320

Little Marlow Parish Council Registration Number for ICO Z3112320 Data Protection Policy Little Marlow Parish Council Registration Number for ICO Z3112320 Adopted 2012 Reviewed 23 rd February 2016 Introduction The Parish Council is fully committed to compliance with

More information

There is help on form VAT1 itself but these notes provide extra help with some of the questions.

There is help on form VAT1 itself but these notes provide extra help with some of the questions. additional information to help you There is help on form VAT1 itself but these notes provide extra help with some of the questions. The notes have the same numbers as the questions they refer to. On the

More information

Information Governance Policy

Information Governance Policy Information Governance Policy 1 Introduction Healthwatch Rutland (HWR) needs to collect and use certain types of information about the Data Subjects who come into contact with it in order to carry on its

More information

Data Protection Policy

Data Protection Policy Data Protection Policy CONTENTS Introduction...2 1. Statement of Intent...2 2. Fair Processing or Privacy Statement...3 3. Data Uses and Processes...4 4. Data Quality and Integrity...4 5. Technical and

More information

Scottish Rowing Data Protection Policy

Scottish Rowing Data Protection Policy Revision Approved by the Board August 2010 1. Introduction As individuals, we want to know that personal information about ourselves is handled properly, and we and others have specific rights in this

More information

235.1. Federal Act on Data Protection (FADP) Aim, Scope and Definitions

235.1. Federal Act on Data Protection (FADP) Aim, Scope and Definitions English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force. Federal Act on Data Protection (FADP) 235.1 of 19 June

More information

NO PURCHASE NECESSARY TO ENTER OR WIN. A PURCHASE DOES NOT IMPROVE YOUR CHANCES OF WINNING. VOID WHERE PROHIBITED BY LAW.

NO PURCHASE NECESSARY TO ENTER OR WIN. A PURCHASE DOES NOT IMPROVE YOUR CHANCES OF WINNING. VOID WHERE PROHIBITED BY LAW. NO PURCHASE NECESSARY TO ENTER OR WIN. A PURCHASE DOES NOT IMPROVE YOUR CHANCES OF WINNING. VOID WHERE PROHIBITED BY LAW. 1. Promotion Description: The ' Libidex $500 v3.0' ("Sweepstakes") begins on 01/11/2016

More information

PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE

PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE PERSONAL INJURIES ASSESSMENT BOARD DATA PROTECTION CODE OF PRACTICE ADOPTED ON 9 th January 2008 TABLE OF CONTENTS Page No. 1 Introduction...3 2 Glossary...3 3 Types of Personal Data held by Us...3 4 Obligations

More information

DATA PROTECTION ACT 1998 COUNCIL POLICY

DATA PROTECTION ACT 1998 COUNCIL POLICY DATA PROTECTION ACT 1998 COUNCIL POLICY Page 1 of 5 POLICY STATEMENT Blackpool Council recognises the need to fully comply with the requirements of the Data Protection Act 1998 (DPA) and the obligations

More information

- Assessment of the application by Member States of European Union VAT provisions with particular relevance to the Mini One Stop Shop (MOSS) -

- Assessment of the application by Member States of European Union VAT provisions with particular relevance to the Mini One Stop Shop (MOSS) - - Assessment of the application by Member States of European Union VAT provisions with particular relevance to the Mini One Stop Shop (MOSS) - BACKGROUND The information available on this website relates

More information

Data controllers and data processors: what the difference is and what the governance implications are

Data controllers and data processors: what the difference is and what the governance implications are ICO lo : what the difference is and what the governance implications are Data Protection Act Contents Introduction... 3 Overview... 3 Section 1 - What is the difference between a data controller and a

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19 Protection of Personal Data RPC001147_EN_D_19 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Rules Responsibility

More information

HERTSMERE BOROUGH COUNCIL

HERTSMERE BOROUGH COUNCIL HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act

More information

Commission on E-Business, IT and Telecoms Task Force on Privacy and the Protection of Personal Data

Commission on E-Business, IT and Telecoms Task Force on Privacy and the Protection of Personal Data International Chamber of Commerce The world business organization Department of Policy and Business Practices Commission on E-Business, IT and Telecoms Task Force on Privacy and the Protection of Personal

More information

An overview of UK data protection law

An overview of UK data protection law An overview of UK data protection law Our team Vinod Bange Partner +44 (0)20 7300 4600 v.bange@taylorwessing.com Graham Hann Partner +44 (0)20 7300 4839 g.hann@taylorwessing.com Chris Jeffery Partner +44

More information

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES 4 April 2013 James Castro-Edwards Solicitor Monica Salgado Advogada / Portuguese Lawyer OUR TEAM Speechly Bircham is an ambitious, full-service law firm with

More information

So the security measures you put in place should seek to ensure that:

So the security measures you put in place should seek to ensure that: Guidelines This guideline offers an overview of what the Data Protection Act requires in terms of information security and aims to help you decide how to manage the security of the personal data you hold.

More information

GSK Public policy positions

GSK Public policy positions Safeguarding Personally Identifiable Information A Summary of GSK s Binding Corporate Rules The Issue The processing of Personally Identifiable Information (PII) 1 and Sensitive Personally Identifiable

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Data Protection Policy Version: 3 Reference Number: CO59 Keywords: Data, access, principles, protection, Act. Data Subject, Information Supersedes Supersedes:

More information

INFORMATION GOVERNANCE HANDBOOK

INFORMATION GOVERNANCE HANDBOOK INFORMATION GOVERNANCE HANDBOOK SECTION ONE Author Tracey Burrows Role Information Governance Manager (CSCSU) Date / Version February 2015 Version FINAL V1.0 Approved by IM&T Board Date 27 February 2015

More information

ERASMUS+ MASTER LOANS

ERASMUS+ MASTER LOANS ERASMUS+ MASTER LOANS Erasmus+ Master Loan: opening up access to more affordable lending for cross-border studies The Erasmus+ programme makes it possible for students who want to take a full Masters level

More information

Data Protection Act. Privacy & Security in the Information Age. April 26, 2013. Ministry of Communications, Ghana

Data Protection Act. Privacy & Security in the Information Age. April 26, 2013. Ministry of Communications, Ghana Data Protection Act Privacy & Security in the Information Age April 26, 2013 Agenda Privacy in The Information Age The right to privacy Why We Need Legislation Purpose of the Act The Data Protection Act

More information

CIVIL SERVICE NATIONALITY RULES GUIDANCE ON CHECKING ELIGIBILITY

CIVIL SERVICE NATIONALITY RULES GUIDANCE ON CHECKING ELIGIBILITY CIVIL SERVICE NATIONALITY RULES GUIDANCE ON CHECKING ELIGIBILITY Employment Practice Division Civil Service Capability Group Cabinet Office November 2007 1 CIVIL SERVICE NATIONALITY RULES GUIDANCE ON CHECKING

More information

Quick guide to the employment practices code

Quick guide to the employment practices code Data protection Quick guide to the employment practices code Ideal for the small business Contents 3 Contents Section 1 About this guidance 4 Section 2 What is the Data Protection Act? 5 Section 3 Recruitment

More information

Data Protection Policy

Data Protection Policy Data Protection Policy September 2015 Contents 1. Scope 2. Purpose 3. Data protection roles 4. Staff training and guidance 5. About the Data Protection Act 1998 6. Policy 7. The Information Commissioner's

More information

START UP LOANS PRIVACY AND DATA PROTECTION TERMS AND CONDITIONS

START UP LOANS PRIVACY AND DATA PROTECTION TERMS AND CONDITIONS START UP LOANS PRIVACY AND DATA PROTECTION TERMS AND CONDITIONS Table of Contents 1. ABOUT THIS POLICY... 3 2. WHO WE ARE AND WHO IS RESPONSIBLE FOR YOUR PERSONAL DATA... 3 3. WHERE WE COLLECT YOUR PERSONAL

More information

Statistics on Requests for data under the Data Retention Directive

Statistics on Requests for data under the Data Retention Directive Statistics on Requests for data under the Data Retention Directive Introduction 1. Directive 2006/24/EC on data retention ('the DRD') 1 requires Member States to provide the Commission on a yearly basis

More information

Application Form: Receptionist / PA to the Senior Leadership Team

Application Form: Receptionist / PA to the Senior Leadership Team Application Form: Receptionist / PA to the Senior Leadership Team This application form is written in BLACK ink. Please answer the questions in dark blue and return electronically to Lesley Starkes, Finance

More information

Data Protection Policy

Data Protection Policy 1 Data Protection Policy Version 1: June 2014 1 2 Contents 1. Introduction 3 2. Policy Statement 3 3. Purpose of the Data Protection Act 1998 3 4. The principles of the Data Protection Act 1998 4 5 The

More information

Human Resources and Data Protection

Human Resources and Data Protection Human Resources and Data Protection Contents 1. Policy Statement... 1 2. Scope... 2 3. What is personal data?... 2 4. Processing data... 3 5. The eight principles of the Data Protection Act... 4 6. Council

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages

More information

1.2 Scope This policy and guidance applies to all University staff, students and others who use or process any personal information.

1.2 Scope This policy and guidance applies to all University staff, students and others who use or process any personal information. MANCHESTER METROPOLITAN UNIVERSITY DATA PROTECTION POLICY This policy should be read in conjunction with the Data Protection Guidance, which is attached as: Appendix A Dealing with Personal Data Appendix

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Version 1.3 April 2014 Contents 1 POLICY STATEMENT...2 2 PURPOSE....2 3 LEGAL CONTEXT AND DEFINITIONS...2 3.1 Data Protection Act 1998...2 3.2 Other related legislation.....4 3.3

More information

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk Data Protection Act 1998 The for the Borough Council of King's Lynn & West Norfolk 1 Contents Introduction 3 1. Statement of Intent 4 2. Fair Obtaining I Processing 5 3. Data Uses and Processes 6 4. Data

More information

The Act imposes foreign exchange restrictions, i.e. performance of certain actions requires a relevant foreign exchange permit.

The Act imposes foreign exchange restrictions, i.e. performance of certain actions requires a relevant foreign exchange permit. RESPONSIBILITIES OF THE NATIONAL BANK OF POLAND RESULTING FROM THE FOREIGN EXCHANGE ACT 1. FOREIGN EXCHANGE PROVISIONS Foreign exchange regulations, which constitute part of the financial legislation,

More information

Credit Union Code for the Protection of Personal Information

Credit Union Code for the Protection of Personal Information Introduction Canada is part of a global economy based on the creation, processing, and exchange of information. The technology underlying the information economy provides a number of benefits that improve

More information

Appendix 11 - Swiss Data Protection Act

Appendix 11 - Swiss Data Protection Act GLEIF- LOU Restricted Appendix 11 - Swiss Data Protection Act GLEIF Revision Version: 1.0 2015-09-23 Master Copy page 2 of 11 Applicable Provisions of the Swiss Data Protection Act (DPA) including the

More information

How To Understand The Data Protection Act

How To Understand The Data Protection Act DATA PROTECTION ACT 2002 The Basics Purpose of the Act Balance the rights of an individual with an organisation s legitimate need to process personal data Promote openness and transparency Establish and

More information

ERASMUS+ MASTER LOANS

ERASMUS+ MASTER LOANS ERASMUS+ MASTER LOANS Erasmus+ Master Loan: opening up access to more affordable lending for cross-border studies The Erasmus+ programme makes it possible for students who want to take a full Master's-level

More information

This factsheet contains help and information for financial advisers who wish to advise their clients who live in Europe.

This factsheet contains help and information for financial advisers who wish to advise their clients who live in Europe. Financial Conduct Authority Factsheet No.025 Investment advisers Passporting This factsheet contains help and information for financial advisers who wish to advise their clients who live in Europe. Introduction

More information

Data Protection Act a more detailed guide

Data Protection Act a more detailed guide Data Protection Act a more detailed guide What does the Act do? The Data Protection Act 1998 places considerable duties on organisations which process personal data; increases the rights of access by data

More information

Overview of the Impact of the Privacy Reforms on Credit Reporting

Overview of the Impact of the Privacy Reforms on Credit Reporting Overview of the Impact of the Privacy Reforms on Credit Reporting June 2012 Andrew Galvin, Partner 1 OVERVIEW 1.1 Credit Reporting Reform - Background When initially passed, the Privacy Act 1988 essentially

More information

International Services tariff

International Services tariff International Services tariff Contents International Services Sending money abroad 1 International payments 1 International drafts 1 Receiving money from abroad 1 Cut-off times and exchange rates 2 BIC

More information

International Hints and Tips

International Hints and Tips International Hints and Tips Content Q: What is the cut off time for processing International payments? A: International payments must be submitted and fully approved within the cut off time indicated

More information

LV= LIFE INSURANCE. Plan Conditions Document reference: LVLI3

LV= LIFE INSURANCE. Plan Conditions Document reference: LVLI3 LV= LIFE INSURANCE Plan Conditions Document reference: LVLI3 LV= Life Insurance Plan Conditions Welcome to LV=, and thank you for choosing LV= Life Insurance These conditions and your Plan Schedule, application,

More information

Balancing Discovery with EU Data Protection in International Arbitration Proceedings By Karin Retzer and Sherman Kahn

Balancing Discovery with EU Data Protection in International Arbitration Proceedings By Karin Retzer and Sherman Kahn Balancing Discovery with EU Data Protection in International Arbitration Proceedings By Karin Retzer and Sherman Kahn As many organizations facing cross-border litigation know too well, U.S. discovery

More information

SPECIALIST VEHICLE LEGAL PROTECTION INSURANCE DOCUMENT

SPECIALIST VEHICLE LEGAL PROTECTION INSURANCE DOCUMENT Carole Nash Insurance Consultants Limited Trafalgar House, 110 Manchester Road, Altrincham, Cheshire, UK WA14 1NU Tel: 0800 458 2614 Fax: 0161 927 2404 www.carolenash.com email: specialistvehicles@carolenash.com

More information

The Guide to Data Protection. The Guide to Data Protection

The Guide to Data Protection. The Guide to Data Protection The Guide to Data Protection Contents Introduction 1 Key definitions of the Data Protection Act 4 The Data Protection Principles 19 1. Processing personal data fairly and lawfully (Principle 1) 20 2. Processing

More information

Health care in Sweden for foreign students [Sjukvård i Sverige för utländska studenter]

Health care in Sweden for foreign students [Sjukvård i Sverige för utländska studenter] Health care in Sweden for foreign students [Sjukvård i Sverige för utländska studenter] This fact sheet is intended for people from abroad who travel to Sweden to study. It describes the rules that apply

More information

ERASMUS+ MASTER LOANS

ERASMUS+ MASTER LOANS Ref. Ares(2015)660570-17/02/2015 ERASMUS+ MASTER LOANS Erasmus+ Master Loan: opening up access to more affordable lending for cross-border studies The Erasmus+ programme makes it possible for students

More information

Planned Healthcare in Europe for Lothian residents

Planned Healthcare in Europe for Lothian residents Planned Healthcare in Europe for Lothian residents Introduction This leaflet explains what funding you may be entitled to if you normally live in Lothian (Edinburgh, West Lothian, Midlothian and East Lothian

More information

Guidelines on Data Protection. Draft. Version 3.1. Published by

Guidelines on Data Protection. Draft. Version 3.1. Published by Guidelines on Data Protection Draft Version 3.1 Published by National Information Technology Development Agency (NITDA) September 2013 Table of Contents Section One... 2 1.1 Preamble... 2 1.2 Authority...

More information

Corporate ICT & Data Management. Data Protection Policy

Corporate ICT & Data Management. Data Protection Policy 90 Corporate ICT & Data Management Data Protection Policy Classification: Unclassified Date Created: January 2012 Date Reviewed January Version: 2.0 Author: Owner: Data Protection Policy V2 1 Version Control

More information

2015 No. 0000 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Businesses (Credit Information) Regulations 2015

2015 No. 0000 FINANCIAL SERVICES AND MARKETS. The Small and Medium Sized Businesses (Credit Information) Regulations 2015 Draft Regulations to illustrate the Treasury s current intention as to the exercise of powers under clause 4 of the the Small Business, Enterprise and Employment Bill. D R A F T S T A T U T O R Y I N S

More information

INTERNATIONAL. Helping your money travel around the world. International payments travel money and CHAPS. Talk to us today

INTERNATIONAL. Helping your money travel around the world. International payments travel money and CHAPS. Talk to us today INTERNATIONAL Helping your money travel around the world International payments travel money and CHAPS Talk to us today Access your money, at home and away Maybe you have family overseas and want to send

More information

On the edge Lexis PSL Restructuring & Insolvency

On the edge Lexis PSL Restructuring & Insolvency On the edge Lexis PSL Restructuring & Insolvency Data protection law for insolvency practitioners November 2014 Welcome to your third edition of On the edge, a series of guides highlighting a selection

More information

Photography and filming in schools Code of Practice

Photography and filming in schools Code of Practice Photography and filming in schools Code of Practice Data Protection compliance September 2010 Photography and filming in schools September 2010 1 Contents 1. About this code 3 2. Complying with the Data

More information

Clause 1. Definitions and Interpretation

Clause 1. Definitions and Interpretation [Standard data protection [agreement/clauses] for the transfer of Personal Data from the University of Edinburgh (as Data Controller) to a Data Processor within the European Economic Area ] In this Agreement:-

More information

Guidance on political campaigning

Guidance on political campaigning I ICO guidance Guidance on political campaigning 3 Guidance on political campaigning Data Protection Act Privacy and Electronic Communications Regulations Contents Introduction... 3 A. Why comply?... 5

More information

PAYMILL General Terms and Conditions

PAYMILL General Terms and Conditions PAYMILL General Terms and Conditions 1. Service Offer PAYMILL GmbH (hereinafter PAYMILL) is a technical service provider in the field of electronic processing of cashless payments via credit card, debit

More information

PHONE SELLING ADDITIONAL INFORMATION

PHONE SELLING ADDITIONAL INFORMATION COUNTRY PHONE SELLING ADDITIONAL INFORMATION ALLOWED Belgium The use of automatic system of phone call with a marketing goal without human intervention is not allowed without the authorization of the consumer.

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY The information and guidelines within this Policy are important and apply to all members, Fellows and staff of the College 1. INTRODUCTION Like all educational establishments, the

More information

Caedmon College Whitby

Caedmon College Whitby Caedmon College Whitby Data Protection and Information Security Policy College Governance Status This policy was re-issued in June 2014 and was adopted by the Governing Body on 26 June 2014. It will be

More information

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL EUROPEAN COMMISSION Brussels, 25.9.2014 COM(2014) 592 final REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on the implementation in the period from 4 December 2011 until 31 December

More information