NORDUnet. AGREEMENT ADDENDUM No. 05 between. NORDUnet Af S Kastruplundgade 22 DK-2770 Kastrup DENMARK. UNINETf Abels gate 5 NO-7030 Trondheim NORWAY

Size: px
Start display at page:

Download "NORDUnet. AGREEMENT ADDENDUM No. 05 between. NORDUnet Af S Kastruplundgade 22 DK-2770 Kastrup DENMARK. UNINETf Abels gate 5 NO-7030 Trondheim NORWAY"

Transcription

1 NORDUnet AGREEMENT ADDENDUM No. 05 between NORDUnet Af S Kastruplundgade 22 DK-2770 Kastrup DENMARK And UNINETf Abels gate 5 NO-7030 Trondheim NORWAY regard ing Idp proxy for box NORDUnet I UNINETT Agreement Addendum no. 05

2 NORDUnet Rtrh 1. SCOPE OF THE AGREEMENT ADDENDUM This Agreement, being an Addendum to the NORDUnet General Terms & Conditions is specifying the services related to the Idp Proxy provided by NORDUnet to UNINETT. The service is governed by the data processing agreement in Annex DURATION OF THE AGREEMENT Upon signature the AgreementAddendum is effective from December 1st The agreement is automatically renewed for I year at a time, if not terminated within 30 days of the expiry of the initial or any renewed contract period. If terminated by the customer a notice must be submitted to contracts@nordu.net. 3. DELIVERYDATE The service delivery is expected to be December i SERVICE SPECIFICATION The service is based on a shared virtual senter providing the ldp proxy functionality. 5. SERVICE CHARGES AND INVOICING The annual base charge is EUR The setup fee is The service will be invoiced on annual basis, first time December SIGNATURE The below signatures by representatives of NORDUnet and UNINETT are to confirm the content of this Agreement Addendum. (Signature/Date) U NI NETT Petter Kongshaug NORDUnet! UNINETT Agreement Addendum no. 05

3 Data Handling Agreement in accordance with Section 13, cf, Seetion 15 of the Personal Data Act and Chapter 2 of the Norwegian Personal Data Regulations by and between UNINETT AS (Controller) and NORDUnet AIS (Processor) 1

4 1. Intention ofthe Data Handling Agreement in Agreement Addendum 5 - IdP proxy for Box T between NORDUnet A/S and UNINETT AS, UNINETT and NORDUnet have agreed that NORDUnet will operate an Identity Provisioning proxy for UNINETT s Box service. To provide this service NORDUnet needs to process certain personal data on behalfofuninett which both parties desire to regulate in this Data Handling Agreement ( The DHA ). As is the case for Agreernent Addendum 5, this DI-JA is subjec to the provision of the NORDUnet General Terrns and Conditions signed between UNJNETT and NORDUnet AIS The intention ofthe DHA is to regulate rights and obligations pursuan to the Norwegian Act of 14April 2000 No. 31 relating to the processing ofpersonal data (the Personal Data Act) and the Regulations of 15 December 2000 No (the Personal Data Regulations). The DHA shall ensure that personal information relating to the data subjects is not used unlawfùlly or comes into the hands of a third party. The DHA concerns the Processor s use of personal data on behalf of the Controller, including collection, recording, alignment, storage and disclosure or a combination of such uses. 2 Purpose Controller offers a personal cloud storage solution based on the Box.com platform to its members, primarily the Norwegian higher education and research community. Controller uses Feide, the Norwegian SAML-based single-signon solution for higher education and research, for account creation and user logon. While Box.com supports SAML-based authentication it does not support authorisation based on SAML-attributes. Controller wants to allow its menibers a certain level of control with regards which user groups ofa member institution will have the ability to create a Box.com account. To facilitate basic authorisation, a SAML IdP logon proxy component is needed between Box.com and Feide. NORDUnet offers such a component as a service to the Nordic NRENs. Data subjects Users from a UNINETT niember institution who have or want to crcatc a Box account under the agreernent between UNINETT and Box. The personal data transfcrred concern the following categories of data: typical user account data pertaining to Users with a l3ox account under the agreement between UNINETf and Box, including but not limited to: name, , other details transferred with federated logon, messages, identification data or location data. A detailed specification is inoluded in Annex i, Specification of SAML attributes. Processing operations 2

5 The Personal Data transferred will be subject to the following basic processing activities: automated provisioning and further management of a Box user account using user account attributes from a users home organisation. As part ofthis particular processing activity a certain set of user attributes is transferred onward to Box service under the agreement between UNINETT and Box.com. A detailed specification of the attributes subjcc to onward transfer are detailed in Annex 1, Specification of SAML attributes. logging and other basic service provisioning activities data gathered as part of operating the service may be used in research projects. Such use is subjec to explicit acceptance by Processor. 3. The Processor s obligations When processing personal data on behalf ofthe Controller, the Processor shall follow any resonable routines and instructions stipulated by the Controller at any given time. The Processor is obliged to give the Controller aceess to his written technical and organizational security measures and to provide assistance so that the Controller can fulfil his responsibilities pursuant to the Act and the Regulations. Unless otherwise agreed or pursuant to statutory regulations, the Controller is entitled to access all personal data being processed on behalf of the Controller and the systcms used for this purpose. The Processor shall provide the necessary assistance for this. The Processor must observe professional secrecy in regard to the docurnentation and personal data to which be has aceess in accordance with this Agreement. This provision also applies after the DHA has been discontinued. 4. Use ofa subcontractor If the Processor uses a subcontractor or other resources not formally employed by the Processor, this shall be agreed in writing with the Controller prior to starting the processing of personal data. Anyone who performs assignrnents on behalf of the Processor which include further processing of the relevant personal data shall be familiar with the Processor s contraotual and legal obligations and fulfil the requirements thereto. At the start of the DHA no subcontractors are used by the Processor. 5. Security The Processor shall fulfil the requirements for security measures stipulated in the Personal 15 of the Personal Data Act and the Personal Data Regulations, in particular Sections 13 Data Act and Regulations thereto. The documentation shall be available upon the Controller s request. The Processor shall report to the Controller all discrepaneies according to Seetion 2-6. The Controller is responsible for reporting the discrepancy to the Data Inspectorate. 3:

6 6. Security audit The Processor shall make available a written security audity report not older than 18 rnonths. The security audit shall be executed according the requirements and guidelines of the Secretariat for IT security for the Norwegian higher education sector. At least once a year the Processor shall make itself available to discuss with Controller the security measures affecting the Service. 7. Duration ofthe DHA The DHA is valid for as long as Processor is processing personal data on behalf of Controller for the purpose of providing the service thldp proxy for Box as per Agreement Addendurn 5 regarding IdP proxy for Box. The DRA can only be terminated simultaneously with and on the same conditions as the Agreement Addendum 5 regarding IdP proxy for Box. In the event of breach of this Agreement or the Personal Data Act, the Controller can instruct the Processor to stop further handling ofthe information with immediate effect. 8. Termination Upon termination of this DHA, the Processor is obliged to retum all personal data received on behalfofthe Controller and covered under this DRA. The Controller shall scnd an cncrypted dump of all account-related data to Processor. The Processor shall delete or destroy in a secure and deflnite/irrevcrsible manner all documents, data, diskettes, CDs, etc. that contain personal data covered under this DHA. This also applies to any baok-up copies. If no other timetable has been agreed upon, deletion shall be executed i month after termination of this DHA. The Processor shall document in writing that deletion or destruction has taken place in accordance with the DRA within a reasonable period of time after termination of the DRA. 9. Notifications Notifications under this DI-TA shall be submitted in writing to: NORDUnet A/S UNINETT AS contracts@nordu.net postmottak@uninett.no telephone: address: 7465 Trondheim, Norway 4 _t

7 10. Signature This DHA has been drawn up in 2 two copies, of which the parties retain one copy each. Place and date For Controller For Processor (signature) (signature) I3 5

8 Annex i - Speficication of SAML attributes For detailed deseription see the Feide attribute specification at Personal data transferred from Feide to NORDUnet Box IdP proxy service: mai! displayname sn givenname edupersonprincipalname schachomeorganization edupersonscopedaffihiation edupersonaffiliation edupersonprimaryaffihiation Personal data transferred from NORDUnet Box IdP proxy service to Box: mall displayname sn givenname edupersonprincipalname schachomeorganization 6

Some practical experiences with negotiating cloud services

Some practical experiences with negotiating cloud services Some practical experiences with negotiating cloud services 27 January 2015, CoCo Cloud Seminar, Oslo Jan Meijer, UNINETT License: CC BY 4.0 UNINETT AS! NREN: national research & education network! Not-for-profit,

More information

Recommendations for companies planning to use Cloud computing services

Recommendations for companies planning to use Cloud computing services Recommendations for companies planning to use Cloud computing services From a legal standpoint, CNIL finds that Cloud computing raises a number of difficulties with regard to compliance with the legislation

More information

Getting Started with Single Sign-On

Getting Started with Single Sign-On Getting Started with Single Sign-On I. Introduction NobleHour sets out to incentivize civic engagement by enabling users within companies, educational institutions, and organizations to conduct and coordinate

More information

Data Processing Agreement for Oracle Cloud Services

Data Processing Agreement for Oracle Cloud Services Data Processing Agreement for Oracle Cloud Services Version December 1, 2013 1. Scope and order of precedence This is an agreement concerning the Processing of Personal Data as part of Oracle s Cloud Services

More information

Feide Integration Guide. Technical Requisites

Feide Integration Guide. Technical Requisites Feide Integration Guide Technical Requisites Document History Version Date Author Comments 1.1 Apr 2015 Jaime Pérez Allow the use of the HTTP-POST binding. 1.0 Oct 2014 Jaime Pérez First version of this

More information

Norwegian Data Inspectorate

Norwegian Data Inspectorate Norwegian Data Inspectorate Narvik kommune Postboks 64 8501 NARVIK Norway Your reference Our reference (please quote in any reply) Date 1111/1210-6/PEJA 11/00593-7/SEV 16 January 2012 Notification of decision

More information

Shibboleth Authentication. Information Systems & Computing Identity and Access Management May 23, 2014

Shibboleth Authentication. Information Systems & Computing Identity and Access Management May 23, 2014 Shibboleth Authentication Information Systems & Computing Identity and Access Management May 23, 2014 For every question an answer: Why should I care about SAML? What is a Shibboleth? What is a Federation?

More information

The regulation applies to direct insurance only.

The regulation applies to direct insurance only. KREDITTILSYNET Norway Translation revised June 2006 This translation is for information purposes only. Legal authenticity remains with the original Norwegian version as published in Norsk Lovtidend. 22

More information

On Data Protection and the Detailed and Uniform Data Management Regulation

On Data Protection and the Detailed and Uniform Data Management Regulation Rector s Directive No. 1/2013 On Data Protection and the Detailed and Uniform Data Management Regulation Budapest, 2013 Version effective as of 31 January 2013 Directives on Data Protection and the Uniform

More information

Software Development Agreement Agreement for the development of software Government Standard Terms and Conditions for IT Procurement SSA-U

Software Development Agreement Agreement for the development of software Government Standard Terms and Conditions for IT Procurement SSA-U Software Development Agreement Agreement for the development of software Government Standard Terms and Conditions for IT Procurement SSA-U SSA U 03 04 2009 EN Agreement for the development of software

More information

Getting Started with Single Sign-On

Getting Started with Single Sign-On Getting Started with Single Sign-On I. Introduction Your institution is considering or has already purchased Collaboratory from Treetop Commons, LLC. One benefit provided to member institutions is Single

More information

Acquia Comments on EU Recommendations for Data Processing in the Cloud

Acquia Comments on EU Recommendations for Data Processing in the Cloud Acquia Comments on EU Recommendations for Data Processing in the Cloud Executive Summary On July 1, 2012, European Union (EU) data protection regulators provided guidelines for service providers processing

More information

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 --------------

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 -------------- w Microsoft Volume Licensing Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 Enrollment for Education Solutions number Microsoft to complete --------------

More information

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document Data Protection Processing and Transfer of Personal Data in Kvaerner Binding Corporate Rules Public Document 1 of 19 1 / 19 Table of contents 1 Introduction... 4 1.1 Scope... 4 1.2 Definitions... 4 1.2.1

More information

Act no 41 on Insurance Mediation (2005-06-10)

Act no 41 on Insurance Mediation (2005-06-10) Translation Translated January 2006 This translation is for information purposes only. Legal authenticity remains with the official Norwegian version as published in Norsk Lovtidend. Act no 41 on Insurance

More information

Microsoft Online Services - Data Processing Agreement

Microsoft Online Services - Data Processing Agreement Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID This Amendment consists of

More information

Exhibit 2. Business Associate Addendum

Exhibit 2. Business Associate Addendum Exhibit 2 Business Associate Addendum This Business Associate Addendum ( Addendum ) governs the use and disclosure of Protected Health Information by EOHHS when functioning as a Business Associate in performing

More information

<Choose> Addendum Windows Azure Data Processing Agreement Amendment ID M129

<Choose> Addendum Windows Azure Data Processing Agreement Amendment ID M129 Addendum Amendment ID Proposal ID Enrollment number Microsoft to complete This addendum ( Windows Azure Addendum ) is entered into between the parties identified on the signature form for the

More information

Cloud computing and the legal framework

Cloud computing and the legal framework Cloud computing and the legal framework - Guidance on legislative requirement and the contractual environment related to cloud computing Content 1. Introduction 3 2. The Danish Act on Processing of Personal

More information

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid.

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid. Microsoft Online Subscription Agreement Amendment adding Office 365 Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID Proposal ID MOSA number Microsoft to complete This Amendment

More information

GENERALLY ACCEPTED ACCOUNTING PRINCIPLES

GENERALLY ACCEPTED ACCOUNTING PRINCIPLES GENERALLY ACCEPTED ACCOUNTING PRINCIPLES GRFS 3 Invoicing Preliminary standard of 15 August 2006, prepared by the Norwegian Association of Authorized Accountants (NARF) and Økonomiforbundet (the Finance

More information

Article 29 Working Party Issues Opinion on Cloud Computing

Article 29 Working Party Issues Opinion on Cloud Computing Client Alert Global Regulatory Enforcement If you have questions or would like additional information on the material covered in this Alert, please contact one of the authors: Cynthia O Donoghue Partner,

More information

INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7

INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7 Information Technology Management Page 357-1 INFORMATION TECHNOLOGY MANAGEMENT CONTENTS CHAPTER A GENERAL 357-3 1. Introduction 357-3 2. Applicability 357-3 CHAPTER B SUPERVISION AND MANAGEMENT 357-4 3.

More information

Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen. Supplementary data protection agreement. to the license agreement for license ID: between

Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen. Supplementary data protection agreement. to the license agreement for license ID: between Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen Supplementary data protection agreement to the license agreement for license ID: between...... represented by... Hereinafter referred to as the "Client"

More information

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10 Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID This Microsoft Online Services Security Amendment ( Amendment ) is between

More information

Clause 1. Definitions and Interpretation

Clause 1. Definitions and Interpretation [Standard data protection [agreement/clauses] for the transfer of Personal Data from the University of Edinburgh (as Data Controller) to a Data Processor within the European Economic Area ] In this Agreement:-

More information

DATA RETENTION POLICY

DATA RETENTION POLICY DATA RETENTION POLICY Contents 1. Key Principles... 3 2. Introduction to the Policy and Guidelines... 3 3. Policy and Guidelines... 4 4. Scottish Ministers Requirements... 5 5. Access to information...

More information

COUNCIL OF THE EUROPEAN UNION. Brussels, 7 October 2003 (OR. en) 12858/03 RECH 152 OC 589

COUNCIL OF THE EUROPEAN UNION. Brussels, 7 October 2003 (OR. en) 12858/03 RECH 152 OC 589 COUNCIL OF THE EUROPEAN UNION Brussels, 7 October 2003 (OR. en) 12858/03 RECH 152 OC 589 LEGISLATIVE ACTS AND OTHER INSTRUMENTS Subject : Council Decision on the signing of the Framework Agreement between

More information

1.3 The Terms are accepted by the Customer upon registration or ordering of the Products or renewal of any such subscription.

1.3 The Terms are accepted by the Customer upon registration or ordering of the Products or renewal of any such subscription. September 2015 WEBCRM SUBSCRIPTION TERMS AND CONDITIONS COMMERCIAL USE ONLY 1. Introduction 1.1 These subscription terms and conditions ("Terms") govern your ("Customer") subscription for and use of the

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Addendum is made part of the agreement between Boston Medical Center ("Covered Entity ) and ( Business Associate"), dated [the Underlying Agreement ]. In connection with

More information

TELEFÓNICA UK LTD. Introduction to Security Policy

TELEFÓNICA UK LTD. Introduction to Security Policy TELEFÓNICA UK LTD Introduction to Security Policy Page 1 of 7 CHANGE HISTORY Version No Date Details Authors/Editor 7.0 1/11/14 Annual review including change control added. Julian Jeffery 8.0 1/11/15

More information

Office 365 Data Processing Agreement with Model Clauses

Office 365 Data Processing Agreement with Model Clauses Enrollment for Education Solutions Office 365 Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID Enrollment for Education Solutions number Microsoft to complete 7392924 GOLDS03081

More information

Regulations concerning measures to combat money laundering and the financing of terrorism, etc.

Regulations concerning measures to combat money laundering and the financing of terrorism, etc. Regulations concerning measures to combat money laundering and the financing of terrorism, etc. Translation as of April 2009. This translation is for information purposes only. Legal authenticity remains

More information

GENERALLY ACCEPTED ACCOUNTING PRINCIPLES

GENERALLY ACCEPTED ACCOUNTING PRINCIPLES GENERALLY ACCEPTED ACCOUNTING PRINCIPLES GRFS 2 - Payroll Preliminary standard dated 15 August 2006, prepared by the Norwegian Association of Authorized Accountants (NARF) and Økonomiforbundet (the Finance

More information

Agreement concerning Fimnet authentication service. Address: Contact person: E-mail:

Agreement concerning Fimnet authentication service. Address: Contact person: E-mail: Company: Business ID: Address: Postcode: Town or city: Contact person: E-mail: Telephone: Person/company in charge of technical matters, plus contact details: Invoicing details Company: Business ID: Invoicing

More information

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT 2300 Pursuant to its authority from Article 59 of the Rules of Procedure of the Croatian Parliament, the Legislation Committee determined the revised text

More information

Business Associate Agreement

Business Associate Agreement Business Associate Agreement I. Definitions Catch-all definition: The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated

More information

SQ 901 Version D. Railway Application Quality Specification REQUIREMENTS FOR THE QUALITY MANAGEMENT SYSTEM AND QUALITY PLAN

SQ 901 Version D. Railway Application Quality Specification REQUIREMENTS FOR THE QUALITY MANAGEMENT SYSTEM AND QUALITY PLAN SQ 901 Version D Railway Application Quality Specification OBTAINING QUALITY OF PRODUCTS PURCHASED BY SNCF REQUIREMENTS FOR THE QUALITY MANAGEMENT SYSTEM AND QUALITY PLAN Issue date March 2004 This English

More information

Cloud Computing and Data Protection Compliance - Experiences from Norway

Cloud Computing and Data Protection Compliance - Experiences from Norway Cloud Computing and Data Protection Compliance - Experiences from Norway PhD Thomas Olsen Legal Aspects of Cloud Computing, UiO, 27 January 2015 www.svw.no Overview Cloud Computing Introduction to EU and

More information

The supplier shall have appropriate policies and procedures in place to ensure compliance with

The supplier shall have appropriate policies and procedures in place to ensure compliance with Supplier Instructions for Processing of Personal Data 1 PURPOSE SOS International has legal and contractual obligations on the matters of data protection and IT security. As a part of these obligations

More information

Feide Technical Guide. Technical details for integrating a service into Feide

Feide Technical Guide. Technical details for integrating a service into Feide Feide Technical Guide Technical details for integrating a service into Feide May 2015 Document History Version Date Initials Comments 1.0 Nov 2009 TG First issue 1.2 Nov 2009 TG Added SLO description 1.3

More information

Enclosure. Dear Vendor,

Enclosure. Dear Vendor, Dear Vendor, As you may be aware, the Omnibus Rule was finalized on January 25, 2013 and took effect on March 26, 2013. Under the Health Insurance Portability & Accountability Act (HIPAA) and the Omnibus

More information

European Code of Conduct on Data Centre Energy Efficiency

European Code of Conduct on Data Centre Energy Efficiency EUROPEAN COMMISSION DIRECTORATE-GENERAL JRC JOINT RESEARCH CENTRE Institute for Energy Renewable Energies Unit European Code of Conduct on Data Centre Energy Efficiency Introductory guide for applicants

More information

EASYNET CHANNEL PARTNERS LIMITED PARTNER MASTER SERVICES AGREEMENT HYBRID CLOUD IT PRODUCT TERMS

EASYNET CHANNEL PARTNERS LIMITED PARTNER MASTER SERVICES AGREEMENT HYBRID CLOUD IT PRODUCT TERMS EASYNET CHANNEL PARTNERS LIMITED PARTNER MASTER SERVICES AGREEMENT HYBRID CLOUD IT PRODUCT TERMS Registered Office at: St James House Oldbury Bracknell RG12 8TH Company No: 03676297 BMI MSA Hybrid Cloud

More information

PRIVACY POLICY. Consent

PRIVACY POLICY. Consent PRIVACY POLICY car2go N.A. LLC and car2go Canada Ltd. (collectively, car2go ) recognize the importance of protecting your personal information. We take the protection of your personal information seriously

More information

General Commercial Terms For Contracts on Internet Advertising

General Commercial Terms For Contracts on Internet Advertising MEDIA CLUB, s.r.o., Registered Office: Prague 8 Karlín, Palác Karlín, Thámova 183/11, Postal Code 186 00 Company Id No: 29413982, Tax Id No: CZ 29413982 Registered in the Commercial Register of the Municipal

More information

Regulations relating to the guarantee scheme for non-life insurance

Regulations relating to the guarantee scheme for non-life insurance FINANSTILSYNET Norway Translation as of May 2010 This translation is for information purposes only. Legal authenticity remains with the official Norwegian version as published in Norsk Lovtidend. Regulations

More information

Contracted representation powers of attorney

Contracted representation powers of attorney Contracted representation powers of attorney Anyone, be it a natural or legal person, when of full legal capacity, is eligible to gain rights and undertake obligations for itself through its own legal

More information

INFORMATION ON THE RULES OF THE GENERAL GOOD

INFORMATION ON THE RULES OF THE GENERAL GOOD INFORMATION ON THE RULES OF THE GENERAL GOOD Introduction: This information is aimed at insurance companies from the UE Member States, as well as from the EFTA Member States the party to the European Economic

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1 Protection of Personal Data RPC001147_EN_WB_L_1 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Responsibility of Employees

More information

ON MUTUAL COOPERATION AND THE EXCHANGE OF INFORMATION RELATED TO THE OVERSIGHT OF AUDITORS

ON MUTUAL COOPERATION AND THE EXCHANGE OF INFORMATION RELATED TO THE OVERSIGHT OF AUDITORS Mr. Ryutaro Hatanaka Commissioner Financial Services Agency Government of Japan 3-2-1 Kasumigaseki Chiyoda-ku, Tokyo Japan 100-8967 Dr. Kunio Chiyoda Chairman Certified Public Accountants and Auditing

More information

openqrm Enterprise Server and Client Licenses Agreement

openqrm Enterprise Server and Client Licenses Agreement openqrm Enterprise Server and Client Licenses Agreement (1) This openqrm Enterprise Server and Client License Agreement ( Agreement ) is by and between openqrm Enterprise GmbH, Berrenrather Strasse 188c,

More information

Policy and Procedure Title: Maintaining Secure Learner Records Policy No: CCTP1001 Version: 1.0

Policy and Procedure Title: Maintaining Secure Learner Records Policy No: CCTP1001 Version: 1.0 PROVIDER NAME: POLICY AREA: College of Computing Technology (CCT) Standard 10: Information Management, Student Information System & Data Protection Policy and Procedure Title: Maintaining Secure Learner

More information

Authorized. User Agreement

Authorized. User Agreement Authorized User Agreement CareAccord Health Information Exchange (HIE) Table of Contents Authorized User Agreement... 3 CareAccord Health Information Exchange (HIE) Polices and Procedures... 5 SECTION

More information

Signing the Contract - Contracture of People Managers

Signing the Contract - Contracture of People Managers CERTIFICATION APPLICATION FOR AN ELECTRONIC DOCUMENT MANAGEMENT SYSTEM This form is reserved for agencies and brokers acting on their own account and for designers of EDM systems for those agencies and

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT THIS IS A TEMPLATE ONLY. CERTAIN STATES MAY NOT PERMIT THE TYPES OF ACTIVITIES ALLOWED HEREUNDER RELATING TO PROTECTED HEALTH INFORMATION. THUS THIS AGREEMENT MAY NEED TO BE MODIFIED IN ORDER TO COMPLY

More information

ANNOUNCEMENT ON CONVENING AN EXTRAORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE)

ANNOUNCEMENT ON CONVENING AN EXTRAORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE) ANNOUNCEMENT ON CONVENING AN EXTRAORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE) The Management Board of Giełda Papierów Wartościowych w Warszawie S.A.

More information

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy) PRESIDENT S DECISION No. 40 of 27 August 2013 Regarding Data Protection at the European University Institute (EUI Data Protection Policy) THE PRESIDENT OF THE EUROPEAN UNIVERSITY INSTITUTE, Having regard

More information

DOMAIN CONFLICTS AND THE LEGAL SYSTEM

DOMAIN CONFLICTS AND THE LEGAL SYSTEM A GUIDE FOR JUDGES, LAWYERS, PROSECUTING AUTHORITIES AND THE POLICE DOMAIN CONFLICTS AND THE LEGAL SYSTEM 1 Table of Contents Foreword 4 Introduction 4 The Internet address system 5 Organization of the

More information

Feide login (currently username/password)

Feide login (currently username/password) Identity collaboration and federation in Norwegian education OECD workshop on Identity Management, Trondheim, 2006-05-08 Ingrid Melve, UNINETT Chief Technical Officer Feide login (currently username/password)

More information

Managing identities. TICAL 2012, Lima, Peru Roland Hedberg <roland.hedberg@adm.umu.se> tisdag 3 juli 12

Managing identities. TICAL 2012, Lima, Peru Roland Hedberg <roland.hedberg@adm.umu.se> tisdag 3 juli 12 Managing identities TICAL 2012, Lima, Peru Roland Hedberg Who am I? Got into networking in 1987 Managed computer networks and network applications Worked with standardisation

More information

ANNOUNCEMENT ON CONVENING AN ORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE)

ANNOUNCEMENT ON CONVENING AN ORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE) ANNOUNCEMENT ON CONVENING AN ORDINARY GENERAL MEETING OF GIEŁDA PAPIERÓW WARTOŚCIOWYCH W WARSZAWIE S.A. (WARSAW STOCK EXCHANGE) The Management Board of Giełda Papierów Wartościowych w Warszawie S.A. with

More information

AUTHORISATION JAMES PAGET UNIVERSITY HOSPITALS NHS FOUNDATION TRUST

AUTHORISATION JAMES PAGET UNIVERSITY HOSPITALS NHS FOUNDATION TRUST AUTHORISATION of JAMES PAGET UNIVERSITY HOSPITALS NHS FOUNDATION TRUST (pursuant to Section 6 of the Health and Social Care (Community Health and Standards) Act 2003) Signature:... 1 August 2006 1 TABLE

More information

Data Protection Policy.

Data Protection Policy. Data Protection Policy. Data Protection Policy Foreword 2 Foreword Ladies and Gentlemen, In the information age, we offer customers the means to be always connected, even in their cars. This requires data

More information

VPO NOK Rules. Rules for the Central Securities Settlement. in Norwegian Kroner

VPO NOK Rules. Rules for the Central Securities Settlement. in Norwegian Kroner Entry into force: 29. April 2015 Version: 1.1 Published 27. April 2015 VPO NOK Rules Rules for the Central Securities Settlement in Norwegian Kroner This document is a translation from the original Norwegian

More information

Independent Contractor Agreement (ICA)

Independent Contractor Agreement (ICA) Financial Services: Purchasing & Payment Independent Contractor Agreement (ICA) ICA# This Letter of Agreement is made on 20 between Ryerson University ( RYERSON ) and (the "Contractor ) and is effective

More information

between United Nations Industrial Development Organization (UNIDO), Vienna, Austria and

between United Nations Industrial Development Organization (UNIDO), Vienna, Austria and MEMORANDUM OF UNDERSTANDING between United Nations Industrial Development Organization (UNIDO), Vienna, Austria and.... 1 MEMORANDUM OF UNDERSTANDING between United Nations Industrial Development Organisation,

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ( BA Agreement ) amends, supplements, and is made a part of the Agreement ( Agreement ) entered with Client ( CLIENT ) and International

More information

1. Introduction. 2. Sectoral Areas Affected. 3. Data Security. 4. Data Breach Requirements. 5. Traffic Data

1. Introduction. 2. Sectoral Areas Affected. 3. Data Security. 4. Data Breach Requirements. 5. Traffic Data 1. Introduction Special data protection rules apply to the protection of Personal Data by Data Controllers in the electronic communications sector. These are in addition to the general obligations that

More information

How To Protect School Data From Harm

How To Protect School Data From Harm 43: DATA SECURITY POLICY DATE OF POLICY: FEBRUARY 2013 STAFF RESPONSIBLE: HEAD/DEPUTY HEAD STATUS: STATUTORY LEGISLATION: THE DATA PROTECTION ACT 1998 REVIEWED BY GOVERNING BODY: FEBRUARY 2013 EDITED:

More information

RM BOOKS TERMS AND CONDITIONS

RM BOOKS TERMS AND CONDITIONS RM BOOKS TERMS AND CONDITIONS (Effective October 2012) Welcome to the RM Books website. Thank you for using RM Books, a service that allows you to view, download and use a variety of digitised electronic

More information

Terms and conditions of business for a NemID administrator of commercial NemID

Terms and conditions of business for a NemID administrator of commercial NemID Terms and conditions of business for a NemID administrator of commercial NemID 1 Background...2 2 Scope and object...3 3 Administrator and Certificates...3 3.1 General obligations of the Customer...3 3.2

More information

Personal Data Act (1998:204);

Personal Data Act (1998:204); Personal Data Act (1998:204); issued 29 April 1998. Be it enacted as follows. General provisions Purpose of this Act Section 1 The purpose of this Act is to protect people against the violation of their

More information

General Conditions for the Assignment, Registration and Administration of Domain Names under the.dk Top Level Domain

General Conditions for the Assignment, Registration and Administration of Domain Names under the.dk Top Level Domain General Conditions for the Assignment, Registration and Administration of Domain Names under the.dk Top Level Domain Version 05 1 July 2010 1. THE MAIN PRINCIPLES FOR THE ASSIGNMENT AND REGISTRATION OF

More information

Terms used in this Agreement, but not otherwise defined, shall have the same meaning as those terms contained within the Privacy Rule.

Terms used in this Agreement, but not otherwise defined, shall have the same meaning as those terms contained within the Privacy Rule. H-l BUSINESS ASSOCIATE AGREEMENT CLAUSE Pursuant to the Health Insurance Portability and Accountability Act (HIPAA) of1996 and its implementing regulation, the Standards ofpnvacy ofindividual Identifiable

More information

Briefly summarised, SURFmarket has submitted the following questions to the Dutch DPA:

Briefly summarised, SURFmarket has submitted the following questions to the Dutch DPA: UNOFFICIAL TRANSLATION Written opinion on the application of the Wet bescherming persoonsgegevens [Dutch Data Protection Act] in the case of a contract for cloud computing services from an American provider

More information

NSW Government Digital Information Security Policy

NSW Government Digital Information Security Policy NSW Government Digital Information Security Policy Version: 2.0 Date: April 2015 CONTENTS PART 1 PRELIMINARY... 3 1.1 Scope... 3 1.2 Application... 3 1.3 Objectives... 3 PART 2 POLICY STATEMENT... 4 Core

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19 Protection of Personal Data RPC001147_EN_D_19 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Rules Responsibility

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) by and between (hereinafter known as Covered Entity ) and Office Ally, LLC. (hereinafter known as Business Associate ), and

More information

User Guide to Retention and Disposal Schedules Council of Europe Records Management Project

User Guide to Retention and Disposal Schedules Council of Europe Records Management Project Directorate General of Administration Directorate of Information Technology Strasbourg, 20 December 2011 DGA/DIT/IMD(2011)02 User Guide to Retention and Disposal Schedules Council of Europe Records Management

More information

Janison Terms and Conditions. Updated Jan 2013

Janison Terms and Conditions. Updated Jan 2013 Janison Terms and Conditions Updated Jan 2013 Terms and Conditions 1. Interpretation 1.1. In this Agreement, unless otherwise indicated by the context (a) (b) (c) (d) (e) (f) (g) (h) (i) words importing

More information

technical factsheet 176

technical factsheet 176 technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection

More information

Act on the Supervision of Credit Institutions, Insurance Companies and Securities Trading etc. (Financial Supervision Act)

Act on the Supervision of Credit Institutions, Insurance Companies and Securities Trading etc. (Financial Supervision Act) KREDITTILSYNET Norway Translation updated August 2003 Translated by Government Authorised Translator Peter Thomas This translation is for information purposes only. Legal authenticity remains with the

More information

Act on Payment Services

Act on Payment Services Act on Payment Services No. 120 27 September 2011 Entered into force 1 December 2011. EEA Agreement: Annex IX, Directive 2007/64/EC. Amended by Act No. 17/2013 (entered into force on 1 April 2013; EEA

More information

Lessons Management Hub. Support and maintenance agreement

Lessons Management Hub. Support and maintenance agreement Lessons Management Hub Support and maintenance agreement Lesson Management Hub Support and maintenance agreement SUPPORT and MAINTENANCE AGREEMENT between LESSON LEARNER LIMITED incorporated in Scotland

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ( Agreement ) is by and between ( Covered Entity ) and Xelex Digital, LLC ( Business Associate ), and is effective as of. WHEREAS,

More information

CONTRACT ADDENDUM BUSINESS ASSOCIATE CONTRACT 1

CONTRACT ADDENDUM BUSINESS ASSOCIATE CONTRACT 1 CONTRACT ADDENDUM BUSINESS ASSOCIATE CONTRACT 1 THIS AGREEMENT is entered into on ( Effective Date ) by and between LaSalle County Health Department, hereinafter called Covered Entity and, hereinafter

More information

HIPAA Business Associate Agreement

HIPAA Business Associate Agreement HIPAA Business Associate Agreement This HIPAA Business Associate Agreement ( BAA ), effective as of, ( Effective Date ), is made by and between ( Covered Entity ) and da Vinci Motion Graphics, Inc. d/b/a

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Agreement ( Agreement ) is made and entered into this day of [Month], [Year] by and between [Business Name] ( Covered Entity ), [Type of Entity], whose business address

More information

Corporate Policy. Data Protection for Data of Customers & Partners.

Corporate Policy. Data Protection for Data of Customers & Partners. Corporate Policy. Data Protection for Data of Customers & Partners. 02 Preamble Ladies and gentlemen, Dear employees, The electronic processing of virtually all sales procedures, globalization and growing

More information

European Code of Conduct on Data Centre Energy Efficiency

European Code of Conduct on Data Centre Energy Efficiency European Code of Conduct on Data Centre Energy Efficiency Introductory guide for applicants Version 1.0.0 1 of 5 1 Summary This document provides guidance notes for organisations wishing to sign the European

More information

Privacy Level Agreement Outline for the Sale of Cloud Services in the European Union

Privacy Level Agreement Outline for the Sale of Cloud Services in the European Union Privacy Level Agreement Working Group Privacy Level Agreement Outline for the Sale of Cloud Services in the European Union February 2013 The PLA Outline has been developed within CSA by an expert working

More information

TUPAS Identification Service. Identification Principles

TUPAS Identification Service. Identification Principles TUPAS Identification Service Version 2.0b Table of contents 1 Introduction... 4 1.1 General description... 4 1.2 Document name and specification data... 5 1.3 Parties... 5 1.3.1 Banks... 5 1.3.2 Service

More information

ADDENDUM TO THE BLACKBERRY SOLUTION LICENSE AGREEMENT FOR BLACKBERRY BUSINESS CLOUD SERVICES FOR MICROSOFT OFFICE 365 ( the ADDENDUM )

ADDENDUM TO THE BLACKBERRY SOLUTION LICENSE AGREEMENT FOR BLACKBERRY BUSINESS CLOUD SERVICES FOR MICROSOFT OFFICE 365 ( the ADDENDUM ) ADDENDUM TO THE BLACKBERRY SOLUTION LICENSE AGREEMENT FOR BLACKBERRY BUSINESS CLOUD SERVICES FOR MICROSOFT OFFICE 365 ( the ADDENDUM ) IMPORTANT NOTICES: In order to access and/or use this Cloud Service

More information

C O N T R A C T N o. F M V I D 2015/106. ACL Desktop

C O N T R A C T N o. F M V I D 2015/106. ACL Desktop Annex 4 To the Regulations of the Procurement Provision of Maintenance Service for the Computerised Accounting Audit Software ACL Desktop, procurement identification No. FM VID 2015/2016, organised by

More information

Service Agreement SURE Project Workspace

Service Agreement SURE Project Workspace Service Agreement SURE Project Workspace Applicant Information Project Name Research Organisation ABN Number Contract number of SURE Head Agreement: This is an agreement to acquire a SURE Project Workspace

More information

GRTGAZ NETWORK TRANSMISSION CONTRACT

GRTGAZ NETWORK TRANSMISSION CONTRACT Page 1 of 9 GRTGAZ NETWORK TRANSMISSION CONTRACT APPENDIX A3 STANDARD EVIDENCE AGREEMENT English translation for information. Disclaimer The present translation is not binding and is provided by GRTgaz

More information

HIPAA Business Associate Contract. Definitions

HIPAA Business Associate Contract. Definitions HIPAA Business Associate Contract Definitions Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in the Privacy Rule. Examples of specific definitions:

More information

TERMS AND CONDITIONS FOR BUSINESS PARTNERS:

TERMS AND CONDITIONS FOR BUSINESS PARTNERS: Page 1 of 6 TERMS AND CONDITIONS FOR BUSINESS PARTNERS: I. PROVIDER'S DETAILS Company: Registered office:,, 29254191, tax ID No.: CZ 29254191 Incorporated in the Companies Register kept by the Regional

More information

CLIENT / PROJECT MANAGER AGREEMENT

CLIENT / PROJECT MANAGER AGREEMENT Authorship of this work is claimed by The Association of Construction Project Managers and any unauthorised reproduction constitutes an infringement in terms of the Copyright Act No 98 of 1978. CLIENT

More information