Data Protection in Germany. Axel Freiherr von dem Bussche Markus Stamm

Size: px
Start display at page:

Download "Data Protection in Germany. Axel Freiherr von dem Bussche Markus Stamm"

Transcription

1 Data Protection in Germany Axel Freiherr von dem Bussche Markus Stamm Verlag C. H. Beck München 2013

2 Preface What is the data privacy law in Europe? is perhaps one of the most frequently asked questions that lawyers face when supporting data privacy clients in an international context. Through the implementation of its directive 95/46/EC, the European Union, at least, has attempted to ensure the harmonisation of the data privacy frameworks of its member states a harmonisation which, even today, is far from having been achieved. The question, as it relates to Germany, must therefore at least for now and for the foreseeable future continue to be What is the data privacy law in Germany?. Due to the principle of territoriality in European data protection law, even companies or other entities not based in Germany are faced with Germany s implementation of the EU data protection framework. Companies that are not based within the European Union (EU) or the area of the European Economic Area (EEA) have to adhere to German data protection law if they intend to collect, process or use personal data in Germany. The same applies to companies within the EU or the EEA if they intend to render a specific data processing operation through a subsidiary based in Germany. In addition cross-border data transfer becomes more and more important the requirements that apply to such operations are relevant to many types of outsourcing, centralisation across legal entities, functional transfers, and all off-shoring activities. While these kinds of activities are most commonly associated with international groups of companies, any small or mid-sized business could face the same compliance requirements. Compliance with these requirements cannot be achieved unless those entities, respectively the persons entrusted with data protection and secrecy within these entities, are familiar with the complex legal framework of German data protection. This, however, poses difficulties even for Germen experts especially because of the fragmented and dense set of rules and regulations of the German Data Protection Act (BDSG), the German Telecommunications Act (TKG), the German Telemedia Act (TMG), respective state laws and further sector-specific regulations as well as with respect to their fine differentiation and separation between them. Germany is Europe s economic engine. This is also, and especially, being recognised outside Europe. In this regard data protection law is becoming an ever more important site factor. Consequently, inquiries for legal advice and counsel within the field of German data protection have increased noticeably in recent years. These inquiries are not only issued by large groups of companies with subsidiaries in Germany or IT-Outsourcing-Providers abroad, but also by foreign lawyers, economical auditors, and universities. What these stakeholders commonly share, is that they do not readily speak German, and if they do, they will find it difficult to command the vocabulary necessary to understand and implement advice and counsel in German. Therefore even the most elemental questions may fail merely because of the language barrier. When the authors of this book joined forces to conduct a workshop in German privacy law, for the benefit of foreign experts, at the European Data Protection Day 2011, it was a clearly appreciated advantage that they were able to present the matter to their audience in English. This book strives to share the authors knowledge in a language the reader will feel comfortable with. It is intended as an introduction to German data protection law in English language, which shall address the fundamentals as well as the typi-

3 cally occurring issues in practice with regard to German data protection law. The book has been conceived as a companion handbook not as a scientific textbook or commentary and thus corresponds with the expectations of especially the Anglo-American coined judicial area. The book s ambition is to provide business and practice oriented solutions of common issues within the field of German data protection law. The book primarily targets non-german speaking persons entrusted with data protective tasks within companies or other entities, which however are nevertheless faced with German data protection provisions due to the aforementioned principle of territoriality in course of their area of activity within the businesses of their employers. Additionally it shall serve any other persons being confronted with German data protection provisions within their professional practice like foreign lawyers, but also computer specialists, business managers, directors and entrepreneurs. German data protection law shall not act as a stumbling block for this audience on its way to the German market. This book shall furthermore illustrate how German data protection provisions can be effectively implemented in own business models as a business enabler and thus utilised to one s own advantage.

4 Abbreviations AG BCR BDSG BetrVG BGB BITKOM BVerfG CEO CR DPO DuD e.g. et seq. etc. EC/EG EEA EU EUCR ff. GG HR ID i.e. IFG IP IT ITRB JuS K&R LDSG MDStV MMR NGO no. /pl. nos. OECD p./pl. pp. Aktiengesellschaft (Public Company) Binding Corporate Rules Bundesdatenschutzgesetz (German Federal Data Protection Act) Betriebsverfassungsgesetz (Works Constitution Act) Bürgerliches Gesetzbuch (German Civil Code) Arbeitskreis Datenschutz des Bundesverbands Informationswirtschaft, Telekommunikation und neue Medien e.v. (Working Group Data Protection of the Registered Federal Association Informational Economy, Telecommunications and New Media) Bundesverfassungsgericht (Federal Constitutional Court) Chief Executive Officer Computer und Recht Datenschutzbeauftrager (Data Protection Officer) Datenschutz und Datensicherheit exempli gratia/zum Beispiel (for example) et sequentes/und Folgende (and the following) et cetera/und so weiter (and so forth) European Community/Europäische Gemeinschaft Europäischer Wirtschaftsraum (European Economic Area) Europäische Union (European Union) Europäische Menschenrechtskonvention (European Convention of Human Rights) und die folgenden Seiten (and the following pages) Grundgesetz (German Constitution) Human Resources Identitätsdokument (Identity Document) id est/das heißt (that is) Informationsfreiheitsgesetz (German Freedom of Information Act) Internet Protocol Informationstechnologie (Informational Technology) Der IT Rechtsberater Juristische Schulung Kommunikation & Recht Landesdatenschutzgesetz (State Data Protection Act) Mediendienstestaatsvertrag (State Treaty on Media Services) Multimedia und Recht Nichtstaatliche Organisation (Non-Governmental Organisation) Nummer(n) (number(s)) Organisation für wirtschaftliche Zusammenarbeit und Entwicklung (Organisation for Economic Co-operation and Development) Seite(n) (page(s))

5 para. Sec. /pl. Secs. SMS TDG TDDSG TKG TMG ULD UWG ZD Absatz (paragraph) Paragraph(en) (Section(s)) Short Message Service Teledienstegesetz (German Teleservices Act) Teledienstedatenschutzgesetz (German Data Security for Telecommunication Services Act) Telekommunikationsgesetz (German Telecommunications Act) Telemediengesetz (German Telemedia Act) Unabhängiges Landeszentrum für Datenschutz (Independent State Centre for Data Protection) Gesetz gegen den unlauteren Wettbewerb (Law Against Unfair Competition) Zeitschrift für Datenschutz

6 Table of Contents A. The Concept of Data Privacy and Protection in Germany... 1 I. Key Legislation: The structure and function of the Federal Data Protection Act The short history of Data Protection Law The European General Data Protection Regulation The Future of Data Protection? The legal structure of German Data Protection Law... 5 II. The underlying principles of the German Data Protection Concept General Principles... 7 a. Personal data... 7 b. Scope of the BDSG: automated and non-automated collection, processing and use of personal data... 8 c. Collection, processing and use of personal data... 9 d. Legal permission... 9 e. Consent... 9 aa. Free decision of the data subject bb. Informing the data subject cc. Consent for sensitive data dd. Formal requirements ee. Revocation of the consent f. Further requirements of lawful data processing aa. Collection from data subject bb. Principle of data reduction and data economy g. The controller When does German data protection law apply? III. Rights of the Data Subject and Legal Consequences of Breach of Law B. The Regulatory Framework: Supervisory Authorities and Compliance I. The Role and Position of the Supervisory Authorities The Federal and State Structure of the Supervisory Authorities The Separation between Public and Private entity Supervision Scrutiny of the Supervisory Authorities Roles and Dependencies Changes to the Judicial Review Process Headcount Ramp-up in the Supervisory Authorities The Role of the Düsseldorf Circle II. Notification Duties Not necessary in Germany! Obligation to notify Exceptions from the notification duty... 20

7 III. The Data Protection Officer and how to integrate him into your Compliance Organisation Obligation to appoint a Data Protection Officer The German DPO a unique Function in the EU Dispensing with Notification Requirements The Duties of the DPO in General Does the DPO need to be a Lawyer? Beware of the Placeholder DPO The DPO and its Interface to the Supervisory Authority Avoiding Conflicts of Interest The external DPO as an alternative The Future of the DPO on an EU Level C. Customer and Supplier Data Protection Proving a Web Trust to your Partners I. General requirements II. Use of customer data for own commercial purpose (Sec. 28 para. 1 BDSG) III. Use of customer data for marketing purposes (Sec. 28 para. 3 BDSG) The use of personal data for marketing purposes without consent a. Use of personal data for advertising purposes b. Transferring for advertising purposes and address trading The use of personal data for marketing purposes with consent a. Formal requirements b. Using of standard consent forms c. Consent under the TMG Restrictions of unfair competition law (UWG) a. Distinction between marketing measures b. Declaration of consent (Double Opt-In) Commercial data collection and recording for the purpose of market or opinion research IV. Data protection in regard to website publishers Privacy Policy Online marketing and corresponding consent Use of cookies, tracking and analytic tools a. Use of cookies b. Use of web tracking and analytic tools V. Video surveillance & Street View Video surveillance Google Street View VI. Disclosure of Data Consequences of breaching applicable data protection rules VII. Annex: Useful Toolkit for companies for compliance with data protection law... 41

8 D. Employee Data Protection Using Employee Data in Globally Operating Organisations I. Centralised Functions and the Use of Personal Data General Concepts of Centralised Functions The Legal Employer and its Key Position The Absence of Group Regulations and its Effects The Position of the Düsseldorf Circle Practical Implementation of Düsseldorf Circle Guidance The N+x Approach Self-Generated and Perceived Needs to Know The Issue of Consent in Employee Relationships Anticipated Development on the EU Level II. The Role of the German Works Council Co-Determination and Information Obligations Works Council and Works Agreement Matching Works Councils and DPOs a. Limits to the Works Council Codetermination Rights b. The DPO as Expert for the Works Council c. Supervision of Works Councils by the DPO d. Cases of Conflict between Works Council and DPO III. Social Media and Social Networks Use of Social Media and Social Networks as Sources of Information Use of Social Media and Social Networks as Means of Publication IV. Compliance Requirements vs. Data Protection Requirements V. Mergers & Acquisitions and personal data in due diligence procedures E. International Transfer of Personal Data I. Legal requirements according to Sec. 4b BDSG International data transfer within the EU or EEA area International data transfer to countries outside of the EU or EEA area II. Safeguarding data transfers to the US Safe Harbor Principles. 54 III. Derogations according to Sec. 4c para. 1 BDSG IV. Derogations according to Sec. 4c para. 2 BDSG Standard Contractual Clauses Binding Corporate Rules a. Misconceptions as to the BCR b. Drawbacks in the implementation c. Future Development of BCR d. BCR Still the method of choice? F. Commissioned Data Processing in- and outside of the EU/EEA I. System and legal requirements for commissioned data processing... 59

9 1. Commissioned data processing in Germany, within the EU and the area of the EEA a. General Principles b. Agreement on commissioned data processing No privilege for commissioned data processing outside the area of the European Union and the EEA a. Is Sec. 11 BDSG applicable to commissioned data processing outside of the EU or EEA? b. Deviation from European regulations II. Central Processing and End-to-End Transfer of Personal Data within Groups of Companies A Viable Model Use of Central Platform Resources by the Controllers End-to-End Transfer of Personal Data between Controllers.. 65 III. Data Protection in the Cloud Annex Federal Data Protection Act (bi-lingual German-English) Index

Improving self-regulation through (law-based) Corporate Data Protection Officials *

Improving self-regulation through (law-based) Corporate Data Protection Officials * Improving self-regulation through (law-based) Corporate Data Protection Officials * Article by Christoph Klug ** The rise of globalization and multinational corporations is creating a pressing need for

More information

Panel 1. Greater Regulation of Special Threats to Privacy. Data Protection in the 21st Century

Panel 1. Greater Regulation of Special Threats to Privacy. Data Protection in the 21st Century Panel 1 Greater Regulation of Special Threats to Privacy Data Protection in the 21st Century Questions for Panel 1 Greater Regulation of Special Threats to Privacy I. Need for reform What are currently

More information

Data Protection, Software Licenses and other Legal Issues in the Cloud

Data Protection, Software Licenses and other Legal Issues in the Cloud Data Protection, Software Licenses and other Legal Issues in the Cloud Dr. Hendrik Schöttle Rechtsanwalt, Fachanwalt für IT-Recht OSDC 2012, Nuremberg 26. April 2012 Overview Introduction Data Protection

More information

Corporate Policy. Data Protection for Data of Customers & Partners.

Corporate Policy. Data Protection for Data of Customers & Partners. Corporate Policy. Data Protection for Data of Customers & Partners. 02 Preamble Ladies and gentlemen, Dear employees, The electronic processing of virtually all sales procedures, globalization and growing

More information

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES 4 April 2013 James Castro-Edwards Solicitor Monica Salgado Advogada / Portuguese Lawyer OUR TEAM Speechly Bircham is an ambitious, full-service law firm with

More information

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data *) For the purposes of these Corporate Guidelines, Third Countries are all those countries, which do not

More information

BCS, The Chartered Institute for IT Consultation Response to:

BCS, The Chartered Institute for IT Consultation Response to: BCS, The Chartered Institute for IT Consultation Response to: A Comprehensive Approach to Personal Data Protection in the European Union Dated: 15 January 2011 BCS The Chartered Institute for IT First

More information

The eighth data protection principle and international data transfers

The eighth data protection principle and international data transfers Data Protection Act 1998 The eighth data protection principle and international data transfers The Information Commissioner s recommended approach to assessing adequacy including consideration of the issue

More information

THE TRANSFER OF PERSONAL DATA ABROAD

THE TRANSFER OF PERSONAL DATA ABROAD THE TRANSFER OF PERSONAL DATA ABROAD MARCH 2014 THIS NOTE CONSIDERS THE SITUATION OF AN IRISH ORGANISATION OR BUSINESS SEEKING TO TRANSFER PERSONAL DATA ABROAD FOR STORAGE OR PROCESSING, IN LIGHT OF THE

More information

Data Protection Policy.

Data Protection Policy. Data Protection Policy. Data Protection Policy Foreword 2 Foreword Ladies and Gentlemen, In the information age, we offer customers the means to be always connected, even in their cars. This requires data

More information

AIRBUS GROUP BINDING CORPORATE RULES

AIRBUS GROUP BINDING CORPORATE RULES 1 AIRBUS GROUP BINDING CORPORATE RULES 2 Introduction The Binding Corporate Rules (hereinafter BCRs ) of the Airbus Group finalize the Airbus Group s provisions on the protection of Personal Data. These

More information

Privacy in the cloud. DNB has indicated that it considers cloud computing a form of outsourcing.

Privacy in the cloud. DNB has indicated that it considers cloud computing a form of outsourcing. Privacy in the cloud computing, and the company concerned is required to submit a risk analysis to DNB. 3 Cloud computing entails the saving, processing and using of company data on the servers of a cloud

More information

The GmbH A Guide to the German Limited Liability Company

The GmbH A Guide to the German Limited Liability Company The GmbH A Guide to the German Limited Liability Company by Klaus J. Müller Verlag C.H.Beck Kluwer Law International 2006 Preface Overview of Contents Table of Contents Abbreviations Table of Contents

More information

Liechtenstein. Heinz Frommelt. Sele Frommelt & Partners Attorneys at Law Ltd

Liechtenstein. Heinz Frommelt. Sele Frommelt & Partners Attorneys at Law Ltd Sele Frommelt & Partners Attorneys at Law Ltd Heinz Frommelt Sele Frommelt & Partners Attorneys at Law Ltd Legislation and jurisdiction 1 What is the relevant legislation and who enforces it? is a member

More information

235.1. Federal Act on Data Protection (FADP) Aim, Scope and Definitions

235.1. Federal Act on Data Protection (FADP) Aim, Scope and Definitions English is not an official language of the Swiss Confederation. This translation is provided for information purposes only and has no legal force. Federal Act on Data Protection (FADP) 235.1 of 19 June

More information

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Processor Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Processor Policy Confidential Contents INTRODUCTION TO THIS POLICY 3 PART I: BACKGROUND AND ACTIONS 4 PART II: PROCESSOR OBLIGATIONS 6 PART III:

More information

Binding Corporate Rules ( BCR ) Summary of Third Party Rights

Binding Corporate Rules ( BCR ) Summary of Third Party Rights Binding Corporate Rules ( BCR ) Summary of Third Party Rights This document contains in its Sections 3 9 all provision of the Binding Corporate Rules (BCR) for Siemens Group Companies and Other Adopting

More information

Questions for National Reporters of LIDC STOCKHOLM 2015

Questions for National Reporters of LIDC STOCKHOLM 2015 Questions for National Reporters of LIDC STOCKHOLM 2015 Prof. Dr. Thomas Hoeren 1 Questions for National Reporters of LIDC STOCKHOLM 2015 The Protection of Trade Secrets and Know-How in Germany - Are countries

More information

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING CCBE response regarding the European Commission Public Consultation on Cloud Computing The Council of Bars and Law

More information

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively.

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively. Joint work between experts from the Article 29 Working Party and from APEC Economies, on a referential for requirements for Binding Corporate Rules submitted to national Data Protection Authorities in

More information

All rights reserved. 2011, EuroPriSe/ULD

All rights reserved. 2011, EuroPriSe/ULD January 2011 Position paper on certifiability of online behavioural advertising systems according to EuroPriSe Follow-up EuroPriSe - European Privacy Seal at the Unabhängiges Landeszentrum für Datenschutz

More information

New EU Data Protection legislation comes into force today. What does this mean for your business?

New EU Data Protection legislation comes into force today. What does this mean for your business? 24 th May 2016 New EU Data Protection legislation comes into force today. What does this mean for your business? After years of discussion and proposals, the General Data Protection Regulation ( GDPR )

More information

Cloud Computing and Privacy Laws! 17.7. 22.7. 2011 Prof. Dr. Thomas Fetzer, LL.M. Technische Universität Dresden Law School

Cloud Computing and Privacy Laws! 17.7. 22.7. 2011 Prof. Dr. Thomas Fetzer, LL.M. Technische Universität Dresden Law School DEUTSCH-FRANZÖSISCHE SOMMERUNIVERSITÄT! FÜR NACHWUCHSWISSENSCHAFTLER 2011! CLOUD COMPUTING : HERAUSFORDERUNGEN UND MÖGLICHKEITEN UNIVERSITÉ DʼÉTÉ FRANCO-ALLEMANDE POUR JEUNES CHERCHEURS 2011! CLOUD COMPUTING

More information

The Payment Services Directive implementation in Germany regulatory part (Zahlungsdiensteaufsichtsgesetz/ZAG)

The Payment Services Directive implementation in Germany regulatory part (Zahlungsdiensteaufsichtsgesetz/ZAG) MÜNCHEN Karl-Scharnagl-Ring 8 80539 München Tel. +49 (89) 28 81 74-0 Fax +49 (89) 28 81 74-44 [email protected] The Payment Services Directive implementation in Germany regulatory part (Zahlungsdiensteaufsichtsgesetz/ZAG)

More information

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document Data Protection Processing and Transfer of Personal Data in Kvaerner Binding Corporate Rules Public Document 1 of 19 1 / 19 Table of contents 1 Introduction... 4 1.1 Scope... 4 1.2 Definitions... 4 1.2.1

More information

7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data. Directive 7.08 Protection of Personal Data

7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data. Directive 7.08 Protection of Personal Data Akzo Nobel N.V. Executive Committee Rules 7.08.2 Privacy Rules for Customer, Supplier and Business Partner Data Source Directive Content Owner Directive 7.08 Protection of Personal Data AkzoNobel Legal

More information

Data, Privacy, Cookies and the FTC in 2013. Kevin Stark - ExactTarget Maltie Maraj - ExactTarget Nicholas Merker - Ice Miller

Data, Privacy, Cookies and the FTC in 2013. Kevin Stark - ExactTarget Maltie Maraj - ExactTarget Nicholas Merker - Ice Miller Data, Privacy, Cookies and the FTC in 2013 Kevin Stark - ExactTarget Maltie Maraj - ExactTarget Nicholas Merker - Ice Miller BIOS Kevin Stark: Product Manager at ExactTarget. Focused on data security,

More information

Article 29 Working Party Issues Opinion on Cloud Computing

Article 29 Working Party Issues Opinion on Cloud Computing Client Alert Global Regulatory Enforcement If you have questions or would like additional information on the material covered in this Alert, please contact one of the authors: Cynthia O Donoghue Partner,

More information

The Role and Function of a Data Protection Officer in the European Commission s Proposed General Data Protection Regulation. Initial Discussion Paper

The Role and Function of a Data Protection Officer in the European Commission s Proposed General Data Protection Regulation. Initial Discussion Paper The Role and Function of a Data Protection Officer in the European Commission s Proposed General Data Protection Regulation 1. Introduction Initial Discussion Paper The data protection officer ( DPO )

More information

COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS

COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS EUROPEAN COMMISSION Brussels, XXX [ ](2011) XXX draft COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS

More information

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved.

Align Technology. Data Protection Binding Corporate Rules Controller Policy. 2014 Align Technology, Inc. All rights reserved. Align Technology Data Protection Binding Corporate Rules Controller Policy Contents INTRODUCTION 3 PART I: BACKGROUND AND ACTIONS 4 PART II: CONTROLLER OBLIGATIONS 6 PART III: APPENDICES 13 2 P a g e INTRODUCTION

More information

General Protocol relating to the collaboration of the insurance supervisory authorities of the Member States of the European Union March 2008

General Protocol relating to the collaboration of the insurance supervisory authorities of the Member States of the European Union March 2008 CEIOPS-DOC-07/08 General Protocol relating to the collaboration of the insurance supervisory authorities of the Member States of the European Union March 2008 CEIOPS e.v. - Westhafenplatz 1 60327 Frankfurt

More information

CONSULTATION ON A POSSIBLE STATUTE FOR A EUROPEAN PRIVATE COMPANY (EPC)

CONSULTATION ON A POSSIBLE STATUTE FOR A EUROPEAN PRIVATE COMPANY (EPC) EUROPEAN COMMISSION Internal Market and Services DG MARKT/ 19.07.2007 CONSULTATION ON A POSSIBLE STATUTE FOR A EUROPEAN PRIVATE COMPANY (EPC) Consultation by the Services of the Internal Market Directorate

More information

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

PRESIDENT S DECISION No. 40. of 27 August 2013. Regarding Data Protection at the European University Institute. (EUI Data Protection Policy) PRESIDENT S DECISION No. 40 of 27 August 2013 Regarding Data Protection at the European University Institute (EUI Data Protection Policy) THE PRESIDENT OF THE EUROPEAN UNIVERSITY INSTITUTE, Having regard

More information

Johnson Controls Privacy Notice

Johnson Controls Privacy Notice Johnson Controls Privacy Notice Johnson Controls, Inc. and its affiliated companies (collectively Johnson Controls, we, us or our) care about your privacy and are committed to protecting your personal

More information

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini

Personal data and cloud computing, the cloud now has a standard. by Luca Bolognini Personal data and cloud computing, the cloud now has a standard by Luca Bolognini Lawyer, President of the Italian Institute for Privacy and Data Valorization, founding partner ICT Legal Consulting Last

More information

Principles of Best Practice applicable to the distribution of Life Insurance Products on a Cross-border Basis within the EU or a Third Country

Principles of Best Practice applicable to the distribution of Life Insurance Products on a Cross-border Basis within the EU or a Third Country 2015 Principles of Best Practice applicable to the distribution of Life Insurance Products on a Cross-border Basis within the EU or a Third Country 1 Principles of Best Practice applicable to the distribution

More information

AlixPartners, LLP. General Data Protection Statement

AlixPartners, LLP. General Data Protection Statement AlixPartners, LLP General Data Protection Statement GENERAL DATA PROTECTION STATEMENT 1. INTRODUCTION 1.1 AlixPartners, LLP ( AlixPartners ) is committed to fulfilling its obligations under the data protection

More information

OSRAM BCR Binding Corporate Rules ( BCR ) for OSRAM Group Companies and Adopting Companies for the protection of personal data

OSRAM BCR Binding Corporate Rules ( BCR ) for OSRAM Group Companies and Adopting Companies for the protection of personal data OSRAM BCR Binding Corporate Rules ( BCR ) for OSRAM Group Companies and Adopting Companies for the protection of personal data Terms Adopting company an OSRAM associated company in Germany or overseas

More information

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation The Data Protection Landscape Before and after GDPR: General Data Protection Regulation Data Protection regulations across Europe Current regulations & guidance European Directives 95/46/EC (Data Protection)

More information

Recommendations for companies planning to use Cloud computing services

Recommendations for companies planning to use Cloud computing services Recommendations for companies planning to use Cloud computing services From a legal standpoint, CNIL finds that Cloud computing raises a number of difficulties with regard to compliance with the legislation

More information

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS As a world leader in electronic commerce and payment services, First Data Corporation and its subsidiaries ( First Data entity or entities ),

More information

I. Personal data and its use in the business to business environment.

I. Personal data and its use in the business to business environment. RESPONSE FROM THE DIRECT MARKETING ASSOCIATION (UK) LTD. TO THE EUROPEAN COMMISSION'S CONSULTATION ON THE IMPLEMENTATION OF DIRECTIVE 95/46 EC ON THE PROTECTION OF INDIVIDUALS WITH REGARD TO THE PROCESSING

More information

Under European law teleradiology is both a health service and an information society service.

Under European law teleradiology is both a health service and an information society service. ESR statement on the European Commission Staff Working Document on the applicability of the existing EU legal framework to telemedicine services (SWD 2012/413). The European Society of Radiology (ESR)

More information

GUIDANCE NOTE ON THE CONCEPT OF RELIANCE

GUIDANCE NOTE ON THE CONCEPT OF RELIANCE Final version of 23/02/2009 COCOF 09/0002/01-EN EUROPEAN COMMISSION DIRECTORATE-GENERAL REGIONAL POLICY GUIDANCE NOTE ON THE CONCEPT OF RELIANCE ON THE WORK OF OTHER AUDITORS DISCLAIMER This is a Working

More information

Merchants and Trade - Act No 28/2001 on electronic signatures

Merchants and Trade - Act No 28/2001 on electronic signatures This is an official translation. The original Icelandic text published in the Law Gazette is the authoritative text. Merchants and Trade - Act No 28/2001 on electronic signatures Chapter I Objectives and

More information

Corporate Governance Developments in Greece

Corporate Governance Developments in Greece Corporate Governance Developments in Greece, Managing Partner, Tsibanoulis & Partners 1. Background The following presentation examines the Corporate Governance rules for listed companies according to

More information

Privacy vs Data Protection. PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems

Privacy vs Data Protection. PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems Privacy vs Data Protection PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems Introduction The terms privacy and data protection are often used interchangeable In reality they

More information

QUESTIONNAIRE ON CONTRACT RULES FOR ONLINE PURCHASES OF DIGITAL CONTENT AND TANGIBLE GOODS

QUESTIONNAIRE ON CONTRACT RULES FOR ONLINE PURCHASES OF DIGITAL CONTENT AND TANGIBLE GOODS QUESTIONNAIRE ON CONTRACT RULES FOR ONLINE PURCHASES OF DIGITAL CONTENT AND TANGIBLE GOODS Information about the respondent 1. Please enter your full name OR the name of the organisation / company / institution

More information

Appendix A Data Protection and Marketing Regulatory Considerations for the European Union

Appendix A Data Protection and Marketing Regulatory Considerations for the European Union Appendix A Data Protection and Marketing Regulatory Considerations for the European Union Notes: Soft opt-in rules, denoted with a * within the consent for marketing columns below, generally allow marketing

More information

Safe Harbour Agreement no longer a valid basis for EEA to US transfers of personal data

Safe Harbour Agreement no longer a valid basis for EEA to US transfers of personal data Jisc Safe Harbour NOTE ON THE COURT OF JUSTICE OF THE EUROPEAN UNION'S JUDGMENT ON 'SAFE HARBOUR' ARRANGEMENTS FOR THE TRANSFER OF PERSONAL DATA FROM THE EEA TO THE USA KEY POINTS Safe Harbour Agreement

More information

SUPERVISORY AND REGULATORY GUIDELINES: PU48-0809 GUIDELINES ON MINIMUM STANDARDS FOR THE OUTSOURCING OF MATERIAL FUNCTIONS

SUPERVISORY AND REGULATORY GUIDELINES: PU48-0809 GUIDELINES ON MINIMUM STANDARDS FOR THE OUTSOURCING OF MATERIAL FUNCTIONS SUPERVISORY AND REGULATORY GUIDELINES: PU48-0809 ISSUED: 4 th May 2004 REVISED: 27 th August 2009 GUIDELINES ON MINIMUM STANDARDS FOR THE OUTSOURCING OF MATERIAL FUNCTIONS I. INTRODUCTION The Central Bank

More information

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries Sopra HR Software as a Data Processor Sopra HR Software, 2014 / Ref. : 20141120-101114-m 1/32 1.

More information

Act on Payment Services

Act on Payment Services Act on Payment Services No. 120 27 September 2011 Entered into force 1 December 2011. EEA Agreement: Annex IX, Directive 2007/64/EC. Amended by Act No. 17/2013 (entered into force on 1 April 2013; EEA

More information

BANKING UNIT BANKING RULES OUTSOURCING BY CREDIT INSTITUTIONS AUTHORISED UNDER THE BANKING ACT 1994

BANKING UNIT BANKING RULES OUTSOURCING BY CREDIT INSTITUTIONS AUTHORISED UNDER THE BANKING ACT 1994 BANKING UNIT BANKING RULES OUTSOURCING BY CREDIT INSTITUTIONS AUTHORISED UNDER THE BANKING ACT 1994 Ref: BR/14/2009 OUTSOURCING BY CREDIT INSTITUTIONS AUTHORISED UNDER THE BANKING ACT 1994 INTRODUCTION

More information

ACT on Payment Services 1 ) 2 ) of 19 August 2011. Part 1 General Provisions

ACT on Payment Services 1 ) 2 ) of 19 August 2011. Part 1 General Provisions ACT on Payment Services 1 ) 2 ) of 19 August 2011 Part 1 General Provisions Article 1. This Act sets out rules for the provision of payment services, including: 1) the conditions for provision of payment

More information

NOTICE ON OUTSOURCING

NOTICE ON OUTSOURCING CONSULTATION PAPER P018-2014 SEPTEMBER 2014 NOTICE ON OUTSOURCING PREFACE 1 MAS first issued the Guidelines on Outsourcing in 2004 1 ( Guidelines ) to promote sound risk management practices for the outsourcing

More information

Overview of Employment and Employee Privacy Laws and Key Trends in Austria

Overview of Employment and Employee Privacy Laws and Key Trends in Austria P a g e 1 Privacy Interviews with Experts August 2011 Toronto / Washington DC / Brussels www.nymity.com Rainer Knyrim Attorney and Partner Preslmayr Attorneys at Law Vienna, Austria Overview of Employment

More information

Position of the retail and wholesale sector on the Draft Data Protection Regulation in view of the trilogue 2015

Position of the retail and wholesale sector on the Draft Data Protection Regulation in view of the trilogue 2015 2 September 2015 Position of the retail and wholesale sector on the Draft Data Protection Regulation in view of the trilogue 2015 We support the efforts of EU legislators to create a harmonised data protection

More information

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING

CPNI VIEWPOINT 01/2010 CLOUD COMPUTING CPNI VIEWPOINT 01/2010 CLOUD COMPUTING MARCH 2010 Acknowledgements This viewpoint is based upon a research document compiled on behalf of CPNI by Deloitte. The findings presented here have been subjected

More information

The Legal Pitfalls of Failing to Develop Secure Cloud Services

The Legal Pitfalls of Failing to Develop Secure Cloud Services SESSION ID: CSV-R03 The Legal Pitfalls of Failing to Develop Secure Cloud Services Cristin Goodwin Senior Attorney, Trustworthy Computing & Regulatory Affairs Microsoft Corporation Edward McNicholas Global

More information

This letter is to provide you with our views on the minimum criteria for the impact assessment and subsequent legislative proposal.

This letter is to provide you with our views on the minimum criteria for the impact assessment and subsequent legislative proposal. Dear Commissioner Malmström, As you know, we have been closely involved in consultations with the European Commission with regard to the impact assessment on, and probable review of, the Data Retention

More information

Finding your balance Top tips for successful HR delivery in multiple countries across Europe

Finding your balance Top tips for successful HR delivery in multiple countries across Europe Perspectives Finding your balance Top tips for successful HR delivery in multiple countries across Europe ...organisations are striving for a more standardised approach across all their business locations

More information

CONSULTATION PAPER ON HIGH LEVEL PRINCIPLES ON OUTSOURCING COVER NOTE

CONSULTATION PAPER ON HIGH LEVEL PRINCIPLES ON OUTSOURCING COVER NOTE CEBS CP 02 April 2004 COMMITTEE OF EUROPEAN BANKING SUPERVISORS CONSULTATION PAPER ON HIGH LEVEL PRINCIPLES ON OUTSOURCING COVER NOTE Introduction 1. European banking supervisors began work in 2002 on

More information

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL EUROPEAN COMMISSION Brussels, 9.12.2015 COM(2015) 627 final 2015/0284 (COD) Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on ensuring the cross-border portability of online content

More information

Mexico. Rodolfo Trampe, Jorge Díaz, José Palomar and Carlos López. Von Wobeser y Sierra, S.C.

Mexico. Rodolfo Trampe, Jorge Díaz, José Palomar and Carlos López. Von Wobeser y Sierra, S.C. Mexico Rodolfo Trampe, Jorge Díaz, José Palomar and Carlos López Market overview 1 What kinds of outsourcing take place in your jurisdiction? In Mexico, a subcontracting regime (understood as the regime

More information

Basel Committee on Banking Supervision. Consolidated KYC Risk Management

Basel Committee on Banking Supervision. Consolidated KYC Risk Management Basel Committee on Banking Supervision Consolidated KYC Risk Management October 2004 Table of contents Introduction...4 Global process for managing KYC risks...5 Risk management...5 Customer acceptance

More information

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person.

Personal information, for purposes of this Policy, includes any information which relates to an identified or an identifiable person. PART I: INTRODUCTION AND BACKGROUND Purpose This Data Protection Binding Corporate Rules Policy ( Policy ) establishes the approach of Fluor to compliance with European data protection law and specifically

More information

How To Limit Tax Competition In Swissitzerland

How To Limit Tax Competition In Swissitzerland Robert Waldburger University of St. Gallen Tax competition in Europe National Report Switzerland I. General aspects of the domestic tax situation 1. The notion of 'tax competition' in domestic legal and

More information

Data Processing Agreement for Oracle Cloud Services

Data Processing Agreement for Oracle Cloud Services Data Processing Agreement for Oracle Cloud Services Version December 1, 2013 1. Scope and order of precedence This is an agreement concerning the Processing of Personal Data as part of Oracle s Cloud Services

More information

Statement on the general concept of the European Union towards Data Protection by Aktion Freiheit statt Angst e.v.; EU Register ID 17019643006-45

Statement on the general concept of the European Union towards Data Protection by Aktion Freiheit statt Angst e.v.; EU Register ID 17019643006-45 Berlin, 10. Januar 2011 Aktion Freiheit statt Angst Rochstr. 3 Directorate-General Justice Unit C3 Data protection European Commission B - 1049 Brussels Statement on the general concept of the European

More information

Bylaws of the Supervisory Board of K+S Aktiengesellschaft. Version of 21 November 2012 The German Version is binding.

Bylaws of the Supervisory Board of K+S Aktiengesellschaft. Version of 21 November 2012 The German Version is binding. Bylaws of the Supervisory Board of K+S Aktiengesellschaft Version of 21 November 2012 The German Version is binding. Page 2 1 Position and Responsibility The Supervisory Board performs its functions in

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 00658/13/EN WP 204 Explanatory Document on the Processor Binding Corporate Rules Adopted on 19 April 2013 This Working Party was set up under Article 29 of Directive

More information

Data transfers in the Cloud

Data transfers in the Cloud Data transfers in the Cloud Rapporteur: Emmanuelle Bartoli Meeting date: 28 th March 2014 1 The purpose of this document is to explore options for how contracts between Cloud providers and consumers and

More information