REGULATION CONCERNING THE PROCESSING OF PERSONAL DATA AND THE PROTECTION OF PRIVACY IN THE ELECTRONIC COMMUNICATIONS SECTOR SECTION ONE

Size: px
Start display at page:

Download "REGULATION CONCERNING THE PROCESSING OF PERSONAL DATA AND THE PROTECTION OF PRIVACY IN THE ELECTRONIC COMMUNICATIONS SECTOR SECTION ONE"

Transcription

1 REGULATION CONCERNING THE PROCESSING OF PERSONAL DATA AND THE PROTECTION OF PRIVACY IN THE ELECTRONIC COMMUNICATIONS SECTOR SECTION ONE Purpose, Scope, Basis and Definitions Purpose and scope ARTICLE 1 (1) The purpose of this Regulation is to set out the procedures and principles to be followed by operators performing activity in the electronic communications sector for the processing and the retention of personal data and the protection of privacy in the electronic communications sector. (2) Retention of data related to the content of communication is not included in the scope of this Regulation. Basis ARTICLE 2 (1) This Regulation has been issued on the basis of Articles 4, 6, 12 and 51 of Electronic Communications Law Nr Definitions and abbreviations ARTICLE 3 (1) In this Regulation the following definitions shall apply: a) Subscriber: means any natural person or legal entity who or which is party to a contract with a provider of electronic communications services for the supply of such services, b) Emergency calls: mean calls made to the fire department, the police, gendarmerie, healthcare and similar institutions with a request for emergency service in relation to emergency situations such as fire, health, natural disasters and security, which are recognized in national and international arrangements, c) Anonymization: means the processing of personal data in such a way that the data subject can no longer be associated with an identified or identifiable natural person or its source cannot be ascertained, ç) Unsuccessful call attempt: means a communication where a telephone call has been successfully connected but not answered or there has been a network management intervention, d) Cell ID: means the identity of the cell from which a mobile telephony call originated or in which it terminated, e) IMEI: International Mobile Equipment Identity, f) IMSI: International Mobile Subscriber Identity, g) Process log: means the electronic logs kept in relation to a process so as to ensure that such process executors authorized to access personal data can be identified at a subsequent date, and containing at least the person performing the process, date and time of the process, details, grounds and nature of the process performed and the details of the points to which the process executor connected, ğ) Operator: means any legal entity, which has the right to provide electronic communications services and/or to provide electronic communications network and to operate the infrastructure within the framework of authorization, h) Personal data: means any information relating to an identified or identifiable natural persons and legal entities,

2 ı) Personal data breach: means a breach of security leading to the accidental, unauthorized or unlawful destruction, loss, transmission, alteration, storage, process, disclosure of, or access to personal data, i) Processing of personal data: means a set of operations performed upon personal data, whether or not by automatic means,, such as collection, recording, storing, alteration, erasure or destruction, re-organization, dissemination or otherwise making available, disclosure by transmission, marking, combination or blocking, j) Location data: means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service, k) User: means any natural person or legal entity using electronic communications services without necessarily having subscribed to that services, l) User ID: means a unique identifier allocated to persons when they subscribe to or register with an internet access service or internet communications service, m) Board: means the Information and Communication Technologies Board, n) Authority: means the Information and Communication Technologies Authority, o) Masking: means the processing of personal data by the operator in such a way that third parties cannot associate such data with the data subject, ö) Consent: means freely given and provable declaration of intention by the data subject before processing of his/her personal data and within the scope and aim of the processing of the data, p) Traffic data: means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof, r) Data: means the traffic data, location data and other related information used to identify the subscriber or the user. (2) The definitions in the related legislation shall be applicable for the concepts and the abbreviations referred to herein and not defined in the first paragraph. SECTION TWO Principles of Implementation Principles regarding the processing of personal data ARTICLE 4 It is essential that personal data must be; a) processed fairly and lawfully, b) processed upon consent of the data subject, c) adequate, relevant and not excessive in relation to the purposes for which they are collected, ç) accurate and, where necessary, kept up to date, d) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Security ARTICLE 5 (1) Operators set out a security policy in respect of processing of personal data. Operators shall implement appropriate technical and organizational measures to ensure security of their networks, personal data of their

3 subscribers/ users and services they provide. Having regard to the state of the art, these measures shall ensure a level of security appropriate to the risk presented. (2) The measures referred to in paragraph 1 shall at least include protection of personal data against accidental, unauthorized or unlawful destruction, loss, alteration, storage, process, disclosure of, or access to personal data. (3) Operators are liable to ensure access to personal data only by authorized persons and security of systems in which personal data are kept, and of applications used to provide access to personal data. (4) Operators are liable to keep, for a period of five years, process logs of any and all access to personal data and to other associated systems, and of processes performed by the authorized personnel. (5) When necessary, the Authority is entitled to require operators to provide any information and documents related to the systems in which personal data are kept and security measures taken by them, and to request for change in the mentioned security measures. Notification of risk and personal data breach ARTICLE 6 (1) In case of a particular risk of a breach of the security of the network or personal data, the operator is liable to inform the Authority and its subscribers/users concerning such risk in an efficient manner and without undue delay. (2) Where the risk lies outside the scope of the measures to be taken by the operator, the operator shall inform the subscribers/users of the scope of risk, any possible remedies, including an indication of the likely costs involved in an efficient manner and without undue delay. (3) In case of a personal data breach, the operator shall inform the Authority in relation to details of the notification to be made to subscribers/users concerning the nature and consequences of the mentioned breach and measures taken for addressing the breach. (4) When the personal data breach is likely to adversely affect subscribers/users, the operator shall inform subscribers/users free of charge regarding the nature of personal data breach, the contact points where more information can be obtained and measures to mitigate the possible adverse effects of the personal data breach. (5) The operator is liable to keep an inventory of personal data breaches comprising the facts surrounding the breach, its effects and the remedies by ensuring confidentiality and integrity of the inventory. SECTION THREE Processing and Retention of Data Confidentiality of the communications ARTICLE 7 (1) It is essential to ensure the confidentiality of communications and the related traffic data; and prohibited to listening, tapping, storage or other kinds of interception or surveillance of communications without the consent of the parties of communication, without prejudice to the relevant legislation and judicial decisions. (2) Electronic communications networks can be used for other than carrying out the transmission of a communication, storing of information or the gaining of access to information already stored in the terminal equipment of subscribers/users on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, inter alia, about the purposes of the processing. Processing of traffic data ARTICLE 8 (1) Operators cannot process traffic data for purposes other than the scope of services they provide.

4 (2) Traffic data may be processed, in conformity with provisions of the relevant legislation, for traffic management, interconnection, billing, fraud detection and customer enquiries or settling disputes, in particular interconnection and billing disputes; and they are kept by ensuring their confidentiality and integrity until the period of settlement of such disputes has been completed. (3) Traffic data required for the purpose of marketing electronic communication services or for the provision of value added electronic communications services may be processed only to the extent and for the duration necessary for such services or similar services in line with the prior consent given by related subscribers/ users after having been informed to the type of traffic data to be processed and of the duration of such processing. (4) Traffic data relating to subscribers and users processed and stored by the operatorshall be deleted or anonymized after the completion of the activity which requires the processing and retention of such data. (5) Subscribers/users shall be provided by operators the possibility to withdraw their consent, given via short message service, call centers, internet and similar methods, at any time by using the same method or any other simple method, free of charge. Authorization for the processing of traffic data ARTICLE 9 (1) Processing of traffic data is restricted to persons acting under the authority of operators handling traffic management, interconnection, billing, fraud detection, customer enquiries, marketing electronic communications services or provision of a value added electronic communications service. (2) Traffic data cannot be taken out of the operator systems without masking in case of traffic data processing for marketing of electronic communications services or provision of value added electronic communications services. (3) Traffic data cannot be exported abroad. Notification of traffic data ARTICLE 10 (1) Traffic data for settlement of disputes, in particular interconnection and billing disputes, handling of customer enquiries and inspection activities shall be transmitted upon request in writing to the competent bodies. Processing of location data ARTICLE 11 (1) Location data of the subscribers/users may only be processed by operators when they are made anonymous or with the consent of the subscribers/users to the extent and for the duration necessary for the provision of a value added electronic communications service. (2) The operators must inform the subscribers/users, prior to obtaining their consent, of the type of location data which will be processed, of the purposes and duration of the processing. (3) Subscribers/users shall be provided by operators with the possibility to withdraw their consent, given for processing of their location data via short message service, call centers, internet and similar methods, at any time by using the same method or any other simple method, free of charge. (4) Without prejudice to the relevant legislation and judicial decisions, location data and data subjects s identity information may only be processed without the consent of the subscriber/user in case of emergency calls.

5 Authorization for the processing of location data ARTICLE 12 (1) Processing of location data is restricted to persons acting under the authority of the operator and to what is necessary for the purposes of providing the mentioned services. The mentioned data cannot be taken out of the operator systems without masking. (2) Location data cannot be exported abroad. Categories of data to be retained ARTICLE 13 (1) Below are the categories of data to be retained under this Regulation. a) To trace and identify the source of a communication: 1) Concerning fixed network telephony and mobile telephony, the calling telephone number and the name and address of the subscriber; the name and address of the subscriber to whom telephone number was allocated at the time of communication. 2) Concerning Internet access, Internet and Internet telephony, the user ID and telephone number allocated, internet protocol address at the time of communication, the name and address of the subscriber. b) To identify the destination of a communication: 1) Concerning fixed network telephony and mobile telephony, the number(s) dialled / called, and, in cases involving supplementary services such as call forwarding or call transfer, the number or numbers to which the call is routed, the name and address of the subscriber(s). 2) Concerning Internet and Internet telephony, the user ID of the recipients, the user ID or telephone number of the intended recipients of an Internet telephony call, the name(s) and address(es) of the Internet telephony or e- mail recipients. c) To identify the date, time and duration of a communication: 1) Concerning fixed network telephony and mobile telephony, the date and time of the start and end of the communication. 2) Concerning Internet access, Internet and Internet telephony, the date and time of the log-in and log-off of the Internet access service, together with the IP address, whether dynamic or static, allocated, and the user ID of the subscriber/user; the date and time of the log-in and log-off of the Internet service or Internet telephony service. ç) To identify the type of communication: 1) Concerning fixed network telephony and mobile telephony: the telephone service used; 2) Concerning Internet and Internet telephony: the Internet service used; d) Data necessary to identify users communication equipment or what purports to be their equipment: 1) Concerning fixed network telephony, the calling and called telephone numbers.

6 2) Concerning mobile telephony; the calling and called telephone numbers; the International Mobile Subscriber Identity (IMSI) of the calling and called parties; the International Mobile Equipment Identity (IMEI) of the calling and called parties; in the case of pre-paid anonymous services, the date and time of the initial activation of the service and the location label (Cell ID) from which the service was activated. 3) Concerning Internet access, Internet and Internet telephony; the calling telephone number for dial-up access, the digital subscriber line (DSL) or other end point of the originator of the communication. e) To identify the location of mobile communication equipment where necessary under the relevant legislation; the location label (Cell ID) at the start of the communication, data identifying the geographic location of cells by reference to their location labels (Cell ID) during the period for which communications data are retained, the cell address and dates when the cell ID was designated to and removed from such address. (2) Liabilities entailed hereunder in respect of retention of data concerning and internet telephony are only restricted to services provided by the operators themselves. Periods of retention ARTICLE 14 (1) The categories of data specified in Article 13 are retained by the operators for a period of one year from the date of the communication. (2) Personal data subject to inspection, examination, investigation or dispute shall be retained until the related period has been completed. Data protection and data security ARTICLE 15 (1) The operators shall ensure, as minimum principles with respect to data retained in accordance with this Regulation, that: a) the retained data shall be of the same quality and subject to the same security and protection as those data on the network, b) the data shall be retained by the operator in itself within the country, c) the data shall be subject to appropriate technical and organizational measures to protect the data against accidental, unauthorized or unlawful destruction, loss, transmission, alteration, storage, process, disclosure or access, ç) the data shall be subject to appropriate technical and organizational measures to ensure that they can be accessed by specially authorized personnel only, d) the data processed and retained shall be destroyed or anonymized at the end of the period of retention and such processes shall be recorded automatically or in form of a report or. (2) Operators are liable to guarantee at any stage the security, integrity, confidentiality and accessibility of data they acquired in the scope of services they provided. This liability also comprises processes executed by means of persons acting under the authority of the operator. (3) Data retained and any other necessary information relating to such data shall be transmitted upon request to the competent authorities without undue delay. Statistical information ARTICLE 16 - (1) Operators are liable to retain statistical information within the last one year relating to: a) categories of data requested by competent authorities in accordance with the relevant law and number of requests made for such data,

7 b) the time elapsed between the date on which the data were retained and the date on which the competent authority requested the transmission of the data, c) the cases where requests for data could not be met, and to transmit such information to the Authority upon request. (2) Such statistics shall not contain personal data. SECTION FOUR Possibilities Provided Preventing the presentation of the calling line identification ARTICLE 17 (1) Where presentation of calling line identification is offered, the operator must a) offer the calling user the possibility, using a simple means and free of charge, of preventing the presentation of the calling line identification on a per-call basis, b) offer the called subscriber the possibility, using a simple means and free of charge, of preventing the presentation of the calling line identification on incoming calls, c) offer the called subscriber/user the possibility, using a simple means and free of charge, of rejecting incoming calls where the presentation of the calling line identification has been prevented by the calling user or subscriber. (2) Where presentation of connected line identification is offered, the operator must offer the called subscriber the possibility, using a simple means and free of charge, of preventing the presentation of the connected line identification to the calling user. (3) The operator is liable to inform its subscribers/users free of charge about service possibilities mentioned in the first and the second paragraphs of this article by means of short message service, Internet, media organs, mail or similar means. (4) The possibility of preventing presentation of the calling line identification is not applicable for emergency calls. Automatic call forwarding ARTICLE 18 (1) Operators shall enable stopping of automatic call forwarding made to telephones and similar electronic communication devices by themselves or third parties, where technically possible, by a simple method and free of charge upon the subscriber s request. (2) In case forwarding to any other number or automatic message system by operators is charged, the subscriber s/user s prior consent shall be obtained. Directories of subscribers ARTICLE 19 (1) Subscribers are informed, free of charge and before they are included in the directory, about the purpose(s) of a printed or electronic directory of subscribers available to the public or obtainable through directory enquiry services, in which their personal data can be included and of any further usage possibilities based on search functions embedded in electronic versions of the directory. (2) Personal data in a public directory are determined in accordance with the purpose and scope of the directory service.

8 (3) Subscribers who agree to be included in directories are given the opportunity to have their personal data in the directory verified, corrected and/or withdrawed by a simple method and free of charge. (4) For inquiries in the scope of directory service, the arrangements made under article 27 of the Regulation on Authorization Regarding Electronic Communications Sector in respect of the Definition, Scope and Durations of Electronic Communications Service, Network and Infrastructures shall prevail. Itemized billing ARTICLE 20 (1) Upon request by subscribers, the operators shall offer them a type of detailed bill in which a certain number of digits of the calling or called numbers have been deleted. SECTION FIVE Miscellaneous and Final Provisions Administrative fines and other sanctions ARTICLE 21 (1) In case the operators fail to fulfill the liabilities set out hereunder, provisions of the Regulation dated 5/9/2004 and no on Administrative Fines and Other Sanctions and Measures to be Imposed Upon Service Providers by the Telecommunication Authority, which was published on the Official Gazette, shall be applicable. Provisions not stipulated herein ARTUCLE 22 (1) In circumstances which are not stipulated herein, arrangements shall be made by means of a Communique or a Board Decision. Abolished regulation ARTICLE 23 (1) The Regulation dated 6/2/2004 no on Processing of Personal Data and the Protection of Privacy in the Telecommunication Sector which was published on the Official Gazette has been abolished. References ARTICLE 24 (1) References to the Regulation dated 6/2/2004 no on Processing of Personal Data and the Protection of Privacy in the Telecommunication Sector which was published on the Official Gazette in the legislation shall be regarded as references to this Regulation. Status of current arrangements PROVISIONAL ARTICLE 1 (1) Procedures and principles on basis of the Regulation on Processing of Personal Data and the Protection of Privacy in the Telecommunication Sector, Board Decisions passed and other administrative procedures which are not in breach of this Regulation shall remain effective until a new procedure is executed in respect of the issue. Entry into force ARTICLE 25 (1) This Regulation shall enter into force six months after its publication.. Enforcement ARTICLE 26 (1) Provisions of this Regulation are executed by the President of Information and Communication Technologies Authority.

2014 No. ELECTRONIC COMMUNICATIONS. The Data Retention Regulations 2014

2014 No. ELECTRONIC COMMUNICATIONS. The Data Retention Regulations 2014 Draft Regulations laid before Parliament under section 2(5) of the Data Retention and Investigatory Powers Act 2014, for approval by resolution of each House of Parliament. D R A F T S T A T U T O R Y

More information

Number 3 of 2011 COMMUNICATIONS (RETENTION OF DATA) ACT 2011 ARRANGEMENT OF SECTIONS

Number 3 of 2011 COMMUNICATIONS (RETENTION OF DATA) ACT 2011 ARRANGEMENT OF SECTIONS Number 3 of 2011 COMMUNICATIONS (RETENTION OF DATA) ACT 2011 ARRANGEMENT OF SECTIONS Section 1. Interpretation. 2. Non-application of Act. 3. Obligation to retain data. 4. Data security. 5. Access to data.

More information

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011

STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 STATUTORY INSTRUMENTS. S.I. No. 336 of 2011 EUROPEAN COMMUNITIES (ELECTRONIC COMMUNICATIONS NETWORKS AND SERVICES) (PRIVACY AND ELECTRONIC COMMUNICATIONS) REGULATIONS 2011 (Prn. A11/1165) 2 [336] S.I.

More information

Click here for Explanatory Memorandum

Click here for Explanatory Memorandum Click here for Explanatory Memorandum AN BILLE CUMARSÁIDE (SONRAÍ A CHOIMEÁD) 2009 COMMUNICATIONS (RETENTION OF DATA) BILL 2009 Section 1. Interpretation. Mar a tionscnaíodh As initiated ARRANGEMENT OF

More information

Statutory Instruments 2007: No. 2199

Statutory Instruments 2007: No. 2199 Statutory Instruments 2007: No. 2199 Data Retention (EC Directive) Regulations SI 2007/2199 ELECTRONIC COMMUNICATIONS Made: 26th July 2007 Coming into force: 1st October 2007 The Secretary of State, being

More information

EUROPEAN UNION. Brussels, 12 July 2002 (OR. en) PE-CONS 3636/02 2000/0189 (COD) LEX 365 ECO 217 CODEC 778

EUROPEAN UNION. Brussels, 12 July 2002 (OR. en) PE-CONS 3636/02 2000/0189 (COD) LEX 365 ECO 217 CODEC 778 EUROPEAN UNION THE EUROPEAN PARLIAMT THE COUNCIL Brussels, 12 July 2002 (OR. en) 2000/0189 (COD) LEX 365 PE-CONS 3636/02 ECO 217 CODEC 778 DIRECTIVE 2002/58/EC OF THE EUROPEAN PARLIAMT AND OF THE COUNCIL

More information

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 February 2005 6566/05 LIMITE COPEN 35 TELECOM 10

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 February 2005 6566/05 LIMITE COPEN 35 TELECOM 10 COUNCIL OF THE EUROPEAN UNION Brussels, 24 February 2005 6566/05 LIMITE COPEN 35 TELECOM 0 REPORT from : Working Party on cooperation in criminal matters to : Article 36 Committee No. prev. doc. : 5098/04

More information

1. Introduction. 2. Sectoral Areas Affected. 3. Data Security. 4. Data Breach Requirements. 5. Traffic Data

1. Introduction. 2. Sectoral Areas Affected. 3. Data Security. 4. Data Breach Requirements. 5. Traffic Data 1. Introduction Special data protection rules apply to the protection of Personal Data by Data Controllers in the electronic communications sector. These are in addition to the general obligations that

More information

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

COMMISSION OF THE EUROPEAN COMMUNITIES. Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 21.9.2005 COM(2005) 438 final 2005/0182 (COD) Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the retention of data processed

More information

Important Notice: In case of divergent interpretation, the original Turkish text shall prevail.

Important Notice: In case of divergent interpretation, the original Turkish text shall prevail. Unofficial Translation of Communique on the Implementation of Annex-4 of the By-Law on Quality of Service in the Electronic Communications Sector prepared by Information and Communication Technologies

More information

How To Protect Your Data In European Law

How To Protect Your Data In European Law Corporate Data Protection Code of Conduct for the Protection of the Individual s Right to Privacy in the Handling of Personal Data within the Deutsche Telekom Group 2010 / 04 We make ICT strategies work

More information

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Sopra HR Software as a Data Processor Sopra HR Software, 2014 / Ref. : 20141120-101114-m 1/32 1.

More information

Executive Order on the Provision of Electronic Communications Networks and Services 1)

Executive Order on the Provision of Electronic Communications Networks and Services 1) Executive Order No. 715 of 23 June 2011 Executive Order on the Provision of Electronic Communications Networks and Services 1) Pursuant to section 3, section 4(1), section 5(1), section 8(1), section 61(1),

More information

Binding Corporate Rules ( BCR ) Summary of Third Party Rights

Binding Corporate Rules ( BCR ) Summary of Third Party Rights Binding Corporate Rules ( BCR ) Summary of Third Party Rights This document contains in its Sections 3 9 all provision of the Binding Corporate Rules (BCR) for Siemens Group Companies and Other Adopting

More information

TABLE OF CONTENTS. Maintaining the Quality and Integrity of Information. Notification of an Information Security Incident

TABLE OF CONTENTS. Maintaining the Quality and Integrity of Information. Notification of an Information Security Incident AGREEMENT BETWEEN THE UNITED STATES OF AMERICA AND THE EUROPEAN UNION ON THE PROTECTION OF PERSONAL INFORMATION RELATING TO THE PREVENTION, INVESTIGATION, DETECTION, AND PROSECUTION OF CRIMINAL OFFENSES

More information

Guidelines on Data Protection. Draft. Version 3.1. Published by

Guidelines on Data Protection. Draft. Version 3.1. Published by Guidelines on Data Protection Draft Version 3.1 Published by National Information Technology Development Agency (NITDA) September 2013 Table of Contents Section One... 2 1.1 Preamble... 2 1.2 Authority...

More information

Privacy and Electronic Communications Regulations

Privacy and Electronic Communications Regulations ICO lo Notification of PECR security breaches Privacy and Electronic Communications Regulations Contents Introduction... 2 Overview... 2 Relevant security breaches... 3 What is a service provider?... 3

More information

SERIES A : GUIDANCE DOCUMENTS. Document Nr 3

SERIES A : GUIDANCE DOCUMENTS. Document Nr 3 DATRET/EXPGRP (2009) 3 - FINAL EXPERTS GROUP "THE PLATFORM FOR ELECTRONIC DATA RETENTION FOR THE INVESTIGATION, DETECTION AND PROSECUTION OF SERIOUS CRIME" ESTABLISHED BY COMMISSION DECISION 2008/324/EC

More information

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid.

This Amendment consists of two parts. This is part 1 of 2 and must be accompanied by and signed with part 2 of 2 (Annex 1) to be valid. Microsoft Online Subscription Agreement Amendment adding Office 365 Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID Proposal ID MOSA number Microsoft to complete This Amendment

More information

Johnson Controls Privacy Notice

Johnson Controls Privacy Notice Johnson Controls Privacy Notice Johnson Controls, Inc. and its affiliated companies (collectively Johnson Controls, we, us or our) care about your privacy and are committed to protecting your personal

More information

Data retention current state of UK and EU legislation. Dr. Ian Brown, UCL

Data retention current state of UK and EU legislation. Dr. Ian Brown, UCL Data retention current state of UK and EU legislation Dr. Ian Brown, UCL UK legislation Anti-Terrorism, Crime and Security Act 2001 gives powers for government to require data retention Government has

More information

PRIVACY POLICY. To start, it is important for you to know two definitions that are key to understanding our programs and privacy practices:

PRIVACY POLICY. To start, it is important for you to know two definitions that are key to understanding our programs and privacy practices: PRIVACY POLICY At Brand Loyalty International B.V., or any of its subsidiaries or affiliates, including IceMobile, Merison and Edison companies, all Companies (, we, us, or our ), we advise on, implement,

More information

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy) PRESIDENT S DECISION No. 40 of 27 August 2013 Regarding Data Protection at the European University Institute (EUI Data Protection Policy) THE PRESIDENT OF THE EUROPEAN UNIVERSITY INSTITUTE, Having regard

More information

PORTERS HR Business Cloud Terms of Use

PORTERS HR Business Cloud Terms of Use PORTERS HR Business Cloud Terms of Use A Customer using the PORTERS HR Business Cloud Service ( PORTERS HR Business Cloud ) shall be deemed to have agreed to the following provisions and conditions simultaneously

More information

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT 2300 Pursuant to its authority from Article 59 of the Rules of Procedure of the Croatian Parliament, the Legislation Committee determined the revised text

More information

4. LIMITATION OF LIABILITY

4. LIMITATION OF LIABILITY LEGAL NOTICE Terms and conditions of use The website icem.it ( Website ) is the exclusive property of ICEM srl, with headquarters in Via Corriera, 40 48010 Barbiano di Cotignola (RA) Italy (hereinafter

More information

GlobalSign Subscriber Agreement for DocumentSign Digital ID for Adobe Certified Document Services (CDS)

GlobalSign Subscriber Agreement for DocumentSign Digital ID for Adobe Certified Document Services (CDS) GlobalSign Subscriber Agreement for DocumentSign Digital ID for Adobe Certified Document Services (CDS) Version 1.1 PLEASE READ THIS AGREEMENT CAREFULLY BEFORE USING THE DIGITAL CERTIFICATE ISSUED TO YOU

More information

Privacy Policy. February, 2015 Page: 1

Privacy Policy. February, 2015 Page: 1 February, 2015 Page: 1 Revision History Revision # Date Author Sections Altered Approval/Date Rev 1.0 02/15/15 Ben Price New Document Rev 1.1 07/24/15 Ben Price Verify Privacy Grid Requirements are met

More information

The potential legal consequences of a personal data breach

The potential legal consequences of a personal data breach The potential legal consequences of a personal data breach Tue Goldschmieding, Partner 16 April 2015 The potential legal consequences of a personal data breach 15 April 2015 Contents 1. Definitions 2.

More information

Microsoft Online Services - Data Processing Agreement

Microsoft Online Services - Data Processing Agreement Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID This Amendment consists of

More information

AGREEMENT REGARDING TELIA MOBILE HOST BETWEEN NETCOM AND. V7.0 2005-11-02 Side 1

AGREEMENT REGARDING TELIA MOBILE HOST BETWEEN NETCOM AND. V7.0 2005-11-02 Side 1 AGREEMENT REGARDING TELIA MOBILE HOST BETWEEN NETCOM AND V7.0 2005-11-02 Side 1 Table of Contents 1 BACKGROUND... 4 2 SCOPE OF AGREEMENT... 4 3 MOBILE SERVICES COVERED BY THE AGREEMENT... 6 4 MAIN INTERFACES

More information

COUNCIL OF EUROPE COMMITTEE OF MINISTERS. RECOMMENDATION No. R (95) 4 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES

COUNCIL OF EUROPE COMMITTEE OF MINISTERS. RECOMMENDATION No. R (95) 4 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES COUNCIL OF EUROPE COMMITTEE OF MINISTERS RECOMMENDATION No. R (95) 4 OF THE COMMITTEE OF MINISTERS TO MEMBER STATES ON THE PROTECTION OF PERSONAL DATA IN THE AREA OF TELECOMMUNICATION SERVICES, WITH PARTICULAR

More information

Service Line Warranties of Canada PRIVACY STATEMENT

Service Line Warranties of Canada PRIVACY STATEMENT Service Line Warranties of Canada PRIVACY STATEMENT We at Service Line Warranties of Canada ( us, our we, or Company ) consider the protection of your personal information to be a priority when you visit

More information

GUIDELINES FOR THE PROVISION OF INTERNET SERVICE PUBLISHED BY THE NIGERIAN COMMUNICATIONS COMMISSION

GUIDELINES FOR THE PROVISION OF INTERNET SERVICE PUBLISHED BY THE NIGERIAN COMMUNICATIONS COMMISSION GUIDELINES FOR THE PROVISION OF INTERNET SERVICE PUBLISHED BY THE NIGERIAN COMMUNICATIONS COMMISSION These Guidelines apply to all Licensees providing Internet access services or any other Internet Protocol

More information

Verified Volunteers. A division of SterlingBackcheck. Privacy Policy. Last Updated: November 5, 2014

Verified Volunteers. A division of SterlingBackcheck. Privacy Policy. Last Updated: November 5, 2014 1 Verified Volunteers A division of SterlingBackcheck Privacy Policy Last Updated: November 5, 2014 Verified Volunteers, a division of Sterling Backcheck ( Company, we, us, or our ) provide this Privacy

More information

General Terms and Conditions Regarding Accepting Ticket solutions for Meal and/or Sports and Cultural Services

General Terms and Conditions Regarding Accepting Ticket solutions for Meal and/or Sports and Cultural Services General Terms and Conditions Regarding Accepting Ticket solutions for Meal and/or Sports and Cultural Services 1. Purpose and Scope 1.1 The General Terms and Conditions shall be applicable to a contractual

More information

Terms of Use 1. [Preliminary provision] 1. All capitalized expressions and other terms contained and used in the Terms are primarily meanings assigned to them below: 1) Application - Software made available

More information

Last updated: 30 May 2016. Credit Suisse Privacy Policy

Last updated: 30 May 2016. Credit Suisse Privacy Policy Last updated: 30 May 2016 Credit Suisse Please read this privacy policy (the ) as it describes how we intend to collect, use, store, share, and safeguard your information. By accessing, visiting or using

More information

Technical Questions on Data Retention

Technical Questions on Data Retention Technical Questions on Data Retention 1) The list of data in the annex of the proposed Directive on Data retention is practically identical to the information required in the Council draft Framework Decision.

More information

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 --------------

Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 EES17 -------------- w Microsoft Volume Licensing Enrollment for Education Solutions Addendum Microsoft Online Services Agreement Amendment 10 Enrollment for Education Solutions number Microsoft to complete --------------

More information

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10

Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10 Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID This Microsoft Online Services Security Amendment ( Amendment ) is between

More information

In these terms & conditions, the following terms are defined below.

In these terms & conditions, the following terms are defined below. Terms & Conditions for digitalpost (Dgtlpost AB) Our Service Thank you for using our online Service. Dgtlpost AB provides digitalpost web Service to collect all the mail (paper, email, and uploads) in

More information

GlobalSign Subscriber Agreement for PersonalSign and DocumentSign for Adobe CDS Certificates Combined Agreement for epki (US)

GlobalSign Subscriber Agreement for PersonalSign and DocumentSign for Adobe CDS Certificates Combined Agreement for epki (US) GlobalSign Subscriber Agreement for PersonalSign and DocumentSign for Adobe CDS Certificates Combined Agreement for epki (US) Version 1.1 PLEASE READ THIS AGREEMENT CAREFULLY BEFORE USING THE DIGITAL CERTIFICATE

More information

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY Page 1 of 16 Contents Policy Information 3 Introduction 4 Responsibilities 7 Confidentiality 9 Data recording and storage 11 Subject Access 12 Transparency

More information

Corporate Policy. Data Protection for Data of Customers & Partners.

Corporate Policy. Data Protection for Data of Customers & Partners. Corporate Policy. Data Protection for Data of Customers & Partners. 02 Preamble Ladies and gentlemen, Dear employees, The electronic processing of virtually all sales procedures, globalization and growing

More information

Hong Leong Asia Ltd.

Hong Leong Asia Ltd. Hong Leong Asia Ltd. Personal Data Protection Policy The protection of your Personal Data is important to us. This Personal Data Protection Policy ( PDP Policy ) outlines how we manage your personal data,

More information

The Electronic Transactions Law Chapter I Title and Definition

The Electronic Transactions Law Chapter I Title and Definition The Union of Myanmar The State Peace and Development Council The Electronic Transactions Law ( The State Peace and Development Council Law No. 5/2004 ) The 12th Waxing of Kason 1366 M.E. (30th April, 2004)

More information

DATA AND PAYMENT SECURITY PART 1

DATA AND PAYMENT SECURITY PART 1 STAR has teamed up with Prevention of Fraud in Travel (PROFiT) and the Fraud Intelligence Network (FIN) to offer our members the best advice about fraud prevention. We recognise the increasing threat of

More information

BUSINESS ASSOCIATE AGREEMENT TERMS

BUSINESS ASSOCIATE AGREEMENT TERMS BUSINESS ASSOCIATE AGREEMENT TERMS This Addendum ( Addendum ) is incorporated into and made part of the Agreement between SIGNATURE HEALTHCARE CORPORATION ("Covered Entity ) and ( Business Associate"),

More information

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data *) For the purposes of these Corporate Guidelines, Third Countries are all those countries, which do not

More information

Code of Conduct For Subscribers

Code of Conduct For Subscribers Code of Conduct For Subscribers WHEREAS: A. The Bureau is in the business, amongst others, of producing credit reports B. Subject always to Credit Reporting Agencies Act 2010 and any other applicable legislation,

More information

COMMISSION REGULATION (EU) No /.. of XXX

COMMISSION REGULATION (EU) No /.. of XXX EUROPEAN COMMISSION Brussels, XXX [ ](2013) XXX draft COMMISSION REGULATION (EU) No /.. of XXX on the measures applicable to the notification of personal data breaches under Directive 2002/58/EC on privacy

More information

Data Processing Agreement for Oracle Cloud Services

Data Processing Agreement for Oracle Cloud Services Data Processing Agreement for Oracle Cloud Services Version December 1, 2013 1. Scope and order of precedence This is an agreement concerning the Processing of Personal Data as part of Oracle s Cloud Services

More information

Abilities Centre collects personal information for the following purposes:

Abilities Centre collects personal information for the following purposes: Privacy Policy Accountability Abilities Centre is responsible for your personal information under its control. We have appointed a Privacy Officer who is accountable for our compliance with this Privacy

More information

GlobalSign Subscriber Agreement for DomainSSL Certificates

GlobalSign Subscriber Agreement for DomainSSL Certificates GlobalSign Subscriber Agreement for DomainSSL Certificates Version 1.3 PLEASE READ THIS AGREEMENT CAREFULLY BEFORE USING THE DIGITAL CERTIFICATE ISSUED TO YOU OR YOUR ORGANISATION. BY USING THE DIGITAL

More information

ECSA EuroCloud Star Audit Data Privacy Audit Guide

ECSA EuroCloud Star Audit Data Privacy Audit Guide ECSA EuroCloud Star Audit Data Privacy Audit Guide Page 1 of 15 Table of contents Introduction... 3 ECSA Data Privacy Rules... 4 Governing Law... 6 Sub processing... 6 A. TOMs: Cloud Service... 7 TOMs:

More information

MOBILE VOICE SERVICES PROVISION AGREEMENT

MOBILE VOICE SERVICES PROVISION AGREEMENT MOBILE VOICE SERVICES PROVISION AGREEMENT A. CUSTOMER INFORMATION Please select if you re an existing Customer Contract #. Corporate/Individual Name.. TIN...... Physical Address.. Postal Address......

More information

7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data. Directive 7.08 Protection of Personal Data

7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data. Directive 7.08 Protection of Personal Data Akzo Nobel N.V. Executive Committee Rules 7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data Source Directive Content Owner Directive 7.08 Protection of Personal Data AkzoNobel Legal

More information

GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS

GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS December 2005 2 GENERAL ELECTRIC COMPANY EMPLOYMENT DATA PROTECTION STANDARDS I. OBJECTIVE... 1 II. SCOPE... 1 III. APPLICATION OF LOCAL LAWS...

More information

Southern Law Center Law Center Policy #IT0014. Title: Privacy Expectations for SULC Computing Resources

Southern Law Center Law Center Policy #IT0014. Title: Privacy Expectations for SULC Computing Resources Southern Law Center Law Center Policy #IT0014 Title: Privacy Expectations for SULC Computing Resources Authority: Department Original Adoption: 5/7/2007 Effective Date: 5/7/2007 Last Revision: 9/17/2012

More information

Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion

Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion Page 1 sur 155 Proposal of regulation Com 2012 11/4 Directive 95/46/EC Conclusion Legal nature of the instrument Règlement Directive Directly applicable act in internal law 91 articles 34 articles Art.

More information

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document Data Protection Processing and Transfer of Personal Data in Kvaerner Binding Corporate Rules Public Document 1 of 19 1 / 19 Table of contents 1 Introduction... 4 1.1 Scope... 4 1.2 Definitions... 4 1.2.1

More information

HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations

HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations HIPAA 203: Security An Introduction to the Draft HIPAA Security Regulations Presentation Agenda Security Introduction Security Component Requirements and Impacts Administrative Procedures Physical Safeguards

More information

3Degrees Group, Inc. Privacy Policy

3Degrees Group, Inc. Privacy Policy 3Degrees Group, Inc. Privacy Policy Your privacy is important to 3Degrees Group, Inc. ( 3Degrees ). The following Privacy Policy discloses the information practices followed by 3Degrees with respect to

More information

Privacy Policy and Notice of Information Practices

Privacy Policy and Notice of Information Practices Privacy Policy and Notice of Information Practices Effective Date: April 27, 2015 BioMarin Pharmaceutical Inc. ("BioMarin") respects the privacy of visitors to its websites and online services and values

More information

COMPUTER MISUSE AND CYBERSECURITY ACT (CHAPTER 50A)

COMPUTER MISUSE AND CYBERSECURITY ACT (CHAPTER 50A) COMPUTER MISUSE AND CYBERSECURITY ACT (CHAPTER 50A) (Original Enactment: Act 19 of 1993) REVISED EDITION 2007 (31st July 2007) An Act to make provision for securing computer material against unauthorised

More information

Personal Data & Privacy Policy Statement

Personal Data & Privacy Policy Statement Personal Data & Privacy Policy Statement Your Privacy Hong Kong Broadband Network Limited ("we" or the "Company") respect the privacy rights of visitors to all our company websites (the Websites ) and

More information

07/2013. Specific Terms and Conditions Mobile Device Management

07/2013. Specific Terms and Conditions Mobile Device Management 07/2013 Specific Terms and Conditions Mobile Device Management GENERAL PROVISIONS 1. Offer and Agreement 1.1 The present contractual terms and conditions (hereinafter referred to as Terms and Conditions

More information

Merchants and Trade - Act No 28/2001 on electronic signatures

Merchants and Trade - Act No 28/2001 on electronic signatures This is an official translation. The original Icelandic text published in the Law Gazette is the authoritative text. Merchants and Trade - Act No 28/2001 on electronic signatures Chapter I Objectives and

More information

INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7

INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7 Information Technology Management Page 357-1 INFORMATION TECHNOLOGY MANAGEMENT CONTENTS CHAPTER A GENERAL 357-3 1. Introduction 357-3 2. Applicability 357-3 CHAPTER B SUPERVISION AND MANAGEMENT 357-4 3.

More information

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, 2003. A Guide for Data Controllers Office of the Data Protection Commissioner of The Bahamas Data Protection (Privacy of Personal Information) Act, 2003 A Guide for Data Controllers 1 Acknowledgement Some of the information contained in

More information

Terms and Conditions for Online Services of BOC Credit Card (International) Limited

Terms and Conditions for Online Services of BOC Credit Card (International) Limited Terms and Conditions for Online Services of BOC Credit Card (International) Limited Online Services of BOC Credit Card (International) Limited ("BOCCC") are provided to you by Bank of China (Hong Kong)

More information

BOC Credit Card (International) Limited - Terms and Conditions for Online Services

BOC Credit Card (International) Limited - Terms and Conditions for Online Services BOC Credit Card (International) Limited - Terms and Conditions for Online Services These terms and conditions are applicable to all users of the Online Services and govern the use of the Online Services,

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT THIS HIPAA BUSINESS ASSOCIATE AGREEMENT ( BAA ) is entered into effective the day of, 20 ( Effective Date ), by and between the Regents of the University of Michigan,

More information

Policies For Online-Payments

Policies For Online-Payments Policies For Online-Payments The Terms and Conditions contained herein shall apply to any person ( User ) using the services of PharmaInfo Publications (PI) for making Journal Article Publication Fee payments

More information

Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen. Supplementary data protection agreement. to the license agreement for license ID: between

Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen. Supplementary data protection agreement. to the license agreement for license ID: between Astaro Services AG Rheinweg 7, CH-8200 Schaffhausen Supplementary data protection agreement to the license agreement for license ID: between...... represented by... Hereinafter referred to as the "Client"

More information

DailyMailz may collect and process the following personal information about you:

DailyMailz may collect and process the following personal information about you: Privacy Policy DailyMailz is committed to preserving the privacy of all visitors to its website www.dailymailz.nl ("Website"). This privacy policy along with DailyMailz s terms and conditions of use and

More information

singapore american school

singapore american school Background The Singapore Personal Data Protection Act - 2012 (PDPA) establishes a data protection law that comprises various rules governing the collection, use, disclosure, and care of personal data.

More information

Data Protection Policy

Data Protection Policy Data Protection Policy CONTENTS Introduction...2 1. Statement of Intent...2 2. Fair Processing or Privacy Statement...3 3. Data Uses and Processes...4 4. Data Quality and Integrity...4 5. Technical and

More information

SERVICE SCHEDULE & ADDITIONAL TERMS AND CONDITIONS FOR DIRECT WHOLESALE INTERCONNECT VOICE SERVICE

SERVICE SCHEDULE & ADDITIONAL TERMS AND CONDITIONS FOR DIRECT WHOLESALE INTERCONNECT VOICE SERVICE SERVICE SCHEDULE & ADDITIONAL TERMS AND CONDITIONS FOR DIRECT WHOLESALE INTERCONNECT VOICE SERVICE The following terms and conditions are additional to those in the prevailing Viatel General Terms and

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19 Protection of Personal Data RPC001147_EN_D_19 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Rules Responsibility

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

APPENDIX 8 THE DATA PROTECTION REGULATION OF SZIGET KULTURÁLIS MENEDZSER IRODA KORLÁTOLT FELELŐSSÉGŰ TÁRSASÁG

APPENDIX 8 THE DATA PROTECTION REGULATION OF SZIGET KULTURÁLIS MENEDZSER IRODA KORLÁTOLT FELELŐSSÉGŰ TÁRSASÁG APPENDIX 8 THE DATA PROTECTION REGULATION OF SZIGET KULTURÁLIS MENEDZSER IRODA KORLÁTOLT FELELŐSSÉGŰ TÁRSASÁG Sziget Kulturális Menedzser Iroda Kft. (the Data Controller ) executes the processing and protection

More information

UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY

UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY UNIVERSITY OF SOUTHAMPTON DATA PROTECTION POLICY 1. Purpose 1.1 The Data Protection Act 1998 ( the Act ) has two principal purposes: i) to regulate the use by those (known as data controllers) who obtain,

More information

ELECTRICITY SUPPLY/ TRADE LICENSE KORLEA INVEST A.S

ELECTRICITY SUPPLY/ TRADE LICENSE KORLEA INVEST A.S Hamdi Mramori Street, No 1 Prishtina 10000 Kosovo Tel: +381 (0) 38 247 615 ext. 103 Fax: +381 (0) 38 247 620 e-mail: info@ero-ks.org www.ero-ks.org ELECTRICITY SUPPLY/ TRADE LICENSE GRANTED TO: KORLEA

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT The parties to this ( Agreement ) are, a _New York_ corporation ( Business Associate ) and ( Client ) you, as a user of our on-line health record system (the "System"). BY

More information

The University of Information Technology Management System

The University of Information Technology Management System IT Monitoring Code of Practice 1.4 University of Ulster Code of Practice Cover Sheet Document Title IT Monitoring Code of Practice 1.4 Custodian Approving Committee Deputy Director of Finance and Information

More information

Beasley Broadcast Group, Inc. Privacy Policy

Beasley Broadcast Group, Inc. Privacy Policy Beasley Broadcast Group, Inc. Privacy Policy Last Updated and Effective December 31, 2015 This Privacy Policy has been updated to include a section regarding your California privacy rights if you are a

More information

Trelleborg Sealing Solutions Germany GmbH Handwerkstr. 5-7, 70565 Stuttgart. General Conditions of Purchase for Components

Trelleborg Sealing Solutions Germany GmbH Handwerkstr. 5-7, 70565 Stuttgart. General Conditions of Purchase for Components Trelleborg Sealing Solutions Germany GmbH Handwerkstr. 5-7, 70565 Stuttgart General Conditions of Purchase for Components 1. Basic Provisions 1.1 The General Conditions of Purchase of Trelleborg Sealing

More information

MIS Privacy Statement. Our Privacy Commitments

MIS Privacy Statement. Our Privacy Commitments MIS Privacy Statement Our Privacy Commitments MIS Training Institute Holdings, Inc. (together "we") respect the privacy of every person who visits or registers with our websites ("you"), and are committed

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT Please complete the following and return signed via Fax: 919-785-1205 via Mail: Aesthetic & Reconstructive Plastic Surgery, PLLC 2304 Wesvill Court Suite 360 Raleigh, NC 27607

More information

Guidance on Personal Data Protection in Cross-border Data Transfer 1

Guidance on Personal Data Protection in Cross-border Data Transfer 1 Guidance on Personal Data Protection in Cross-border Data Transfer PART 1: INTRODUCTION Section 33 of the Personal Data (Privacy) Ordinance (the Ordinance ) prohibits the transfer of personal data to places

More information

Office 365 Data Processing Agreement with Model Clauses

Office 365 Data Processing Agreement with Model Clauses Enrollment for Education Solutions Office 365 Data Processing Agreement (with EU Standard Contractual Clauses) Amendment ID Enrollment for Education Solutions number Microsoft to complete 7392924 GOLDS03081

More information

The supplier shall have appropriate policies and procedures in place to ensure compliance with

The supplier shall have appropriate policies and procedures in place to ensure compliance with Supplier Instructions for Processing of Personal Data 1 PURPOSE SOS International has legal and contractual obligations on the matters of data protection and IT security. As a part of these obligations

More information

prevailing of JAMS/Endispute. The arbitrator's award shall be binding and may be entered as a judgment in any court of competent jurisdiction.

prevailing of JAMS/Endispute. The arbitrator's award shall be binding and may be entered as a judgment in any court of competent jurisdiction. Safety Alert Apps, Inc. End User License Agreement By installing and using any of the personal safety app software from Safety Alert Apps, Inc., you are agreeing to be bound by the terms of this End User

More information

Binding Corporate Rules Privacy (BCRP) personal Telekom Group rights in the handling of personal data within the Deutsche Telekom Group

Binding Corporate Rules Privacy (BCRP) personal Telekom Group rights in the handling of personal data within the Deutsche Telekom Group Binding Corporate Rules Privacy (BCRP) Binding Corporate corporate Rules rules Privacy for (BCRP) the protection of personal Telekom Group rights in the handling of personal data within the Deutsche Telekom

More information

EXHIBIT C BUSINESS ASSOCIATE AGREEMENT

EXHIBIT C BUSINESS ASSOCIATE AGREEMENT EXHIBIT C BUSINESS ASSOCIATE AGREEMENT THIS AGREEMENT is made and entered into by and between ( Covered Entity ) and KHIN ( Business Associate ). This Agreement is effective as of, 20 ( Effective Date

More information

Terms and Conditions For Online-Payments

Terms and Conditions For Online-Payments Terms and Conditions For Online-Payments The Terms and Conditions contained herein shall apply to any person ( User ) using the services of Karnataka Examination Authority for making payment for Common

More information

Privacy Policy Last Modified: April 3, 2015 1

Privacy Policy Last Modified: April 3, 2015 1 Privacy Policy Last Modified: April 3, 2015 1 Introduction Jamberry Nails, LLC, a Utah limited liability company, U.S.A., (referred to herein as Jamberry, we, us and our ) understands the importance of

More information

Data Retention and Investigatory Powers Bill

Data Retention and Investigatory Powers Bill Data Retention and Investigatory Powers Bill CONTENTS Retention of relevant communications data 1 Powers for retention of relevant communications data subject to safeguards 2 Section 1: supplementary Investigatory

More information