Information Management Compliance and Data protection.



Similar documents
Presentation by: Dr. Nathalie Moreno Partner. Cloud Computing and Data Protection: an Update 4 October 2012

OUTSOURCING, HOSTING AND DATA PRIVACY ISSUES

Ethical hotlines and whistleblowing ensuring businesses are not in conflict with local laws

HOW TO HANDLE A WHISTLEBLOWER REPORT IN THE EU

Data protection issues on an EU outsourcing

Employment & HR Support Package

Whether you are a practising

The eighth data protection principle and international data transfers

Article 29 Working Party Issues Opinion on Cloud Computing

Align Technology. Data Protection Binding Corporate Rules Processor Policy Align Technology, Inc. All rights reserved.

pharmaceutical & biotechnology

UTech Services Compliance, Auditing, Risk, and Security (CARS) Team Charter

Financial Services Guidance Note Outsourcing

GUIDELINE ON THE APPLICATION OF THE OUTSOURCING REQUIREMENTS UNDER THE FSA RULES IMPLEMENTING MIFID AND THE CRD IN THE UK

Procurement Capability Standards

Resolving IP and Technology Disputes Through WIPO ADR. Getting back to business

CLOUD COMPUTING Contractual and data protection aspects

Christine M. Frye, CIPP/US, CIPM, Chief Privacy Officer, Bank of America

Carey Group l Monaco Private Client Services

INTERNATIONAL SOS. Data Protection Policy. Version 1.05

Managing Outsourcing Arrangements

GUIDANCE NOTE ON OUTSOURCING

GSK Public policy positions

The Data Protection Landscape. Before and after GDPR: General Data Protection Regulation

The Cloud and Cross-Border Risks - Singapore

Forensic Services. Third Party Risks. March 2013

THE FORTY RECOMMENDATIONS OF THE FINANCIAL ACTION TASK FORCE ON MONEY LAUNDERING

Life Sciences & Healthcare

Care Providers Protecting your organisation, supporting its success. Risk Management Insurance Employee Benefits Investment Management

the paris office Elizabeth Naud and Luc Poux, architects

Legal Considerations: Best Practice Overview. EMPLOYMENT GROUP: DLA Piper UK LLP

Critical Infrastructure Private Guarding Company Requirements Checklist

TRANSPORT FOR LONDON (TfL) LOW EMISSIONS CERTIFICATE (LEC) GUIDANCE NOTES FOR THE COMPANY AUDIT PROCESS. LEC (Company Audit) Guidance Notes

PLANNING & FORENSIC DELAY ANALYSIS

Agreement for 2015 S Corporation Income Tax Preparation

Our specialist insurance services for Professionals risks

1. Introduction. The laws of any jurisdiction other than England & Wales Taxes or duties Financial investment.

Rouse. The right mix of intellectual property specialists.

Overview Pricing & Features Summary

EU Directive on Network and Information Security SWD(2013) 31 & SWD(2013) 32. A call for views and evidence

About The Sales Training Consultancy. Online Brochure

Draft WGIG Issues Paper on E-Commerce

LEGAL BRANDSTOCK LEGAL EXPERT ADVICE FOR ALL IP MATTERS

CFPB Readiness Series: Compliant Vendor Management Overview

INTERNATIONAL EMPLOYMENT GROUP. Employment Services in Oman

Under European law teleradiology is both a health service and an information society service.

Policy Statement. Employee privacy, data protection and human resources. Prepared by the Commission on E-Business, IT and Telecoms. I.

J O B S P E C I F I C A T I O N

Copyright, Language, and Version Notice The official language of this [Certification Protocol] is English. The current version of the [Certification

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS

How To Get A Tax Adviser

Mitigating and managing cyber risk: ten issues to consider

Delivering Global Ediscovery Successfully. Emily A. Cobb, Ropes & Gray Andrew Szczech, Kroll Ontrack Thomas Sely, Kroll Ontrack

Measured development Construction and Engineering Training Supplement Guide

OUR CUSTOMERS. Exciting, beautifully designed, excellent quality clothing and homeware that reflects the aspirations and means of our customers

Agency and Distributorship Agreements.DOC. Agency and Distributorship Agreements

Hong Kong Proposes Margin and Risk Mitigation Standards for Non-Centrally Cleared OTC Derivatives

WHAT MATTERS MOST TO CORPORATE COUNSEL IN E-DISCOVERY MANAGEMENT. Presenting the results from BDO s inaugural Inside E-Discovery Survey

Wealth Management. Instinctively global

Delivering Compliance in the Cloud TM

Private Health Insurance Intermediaries. Document 2: Self-Audit Questionnaire. Version 2

Guides & Advice. Our Employment Service

U.S. Inbound Tax Services

Outsourcing Contracts Insights

CONSULTATION ON A POSSIBLE STATUTE FOR A EUROPEAN PRIVATE COMPANY (EPC)

ABDULAZIZ ALASSAF & PARTNERS LAW FIRM A Leading Legal Practice based in the Kingdom of Saudi Arabia

Contracting for International Outsourcing

Cyber and data Policy wording

STL Microsoft SharePoint Consulting and Support Services

The potential legal consequences of a personal data breach

THOMSON IP MANAGER KNOWING IS INGENIOUS

CEREDIGION COUNTY COUNCIL - LEARNING SERVICES SERVICE LEVEL AGREEMENT GOVERNOR SUPPORT SERVICES

NOS. Supply Chain Management Occupational Standards

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

Align Technology. Data Protection Binding Corporate Rules Controller Policy Align Technology, Inc. All rights reserved.

Transcription:

Information Management Compliance and Data protection. Technology, Media & Telecommunications

Information is the life blood of every business. Yet how you use that information is increasingly regulated. With business reputation and criminal liability at stake, you need advisers who understand the IT industry and privacy regulation around the world. Linklaters has a remarkable track record in advising on privacy issues. We have helped many international businesses on the most complex aspects of their privacy compliance. Our ability to see issues from the client s point of view combined with our technical knowledge of the IT sector have been key factors in these successful projects. We have carefully trained and recruited specialists who understand the issues affecting your business and the dynamics shaping privacy regulation. We act on a global basis, across all industry sectors, including for large consumer facing and financial services organisations in addressing their data privacy issues. tremendous expertise most notably in data protection UK Chambers 2005, IT

Core capabilities Project management We help clients with: - National and cross-border projects, e.g. check up and compliance projects to ensure you benefit from the full potential of personal information with minimal risk of disruption to your business and processes. - Practical compliance strategies, project management and template documents to facilitate ongoing steady-state compliance, e.g. controller-controller and controller-processor agreements, online and offline privacy policies and notices, and compliance checklists - Bespoke advice, e.g. subject access, online and offline CRM and marketing, surveillance and monitoring - Disputes and enforcement action Multinational data protection compliance projects involve the implementation of new procedures and documents in multiple jurisdictions. For in-house counsel, these project management tasks can become overwhelming. Linklaters has developed a series of tools, including through use of our web based client extranet, Clients@linklaters, to simplify and speed up the management process. Privacy compliance reviews and advice Privacy strategy development Disputes e-learning Compliance templates Recent projects include: - Advising a leading Spanish based insurer on a novel data aggregation project and liaising with the Spanish data protection regulator in relation to it. - Carrying out a four month review for one of the UK s largest consumer facing businesses, delivering a set of high level and detailed compliance steps, including necessary organisational changes, and assisting in the implementation of a change management programme. - Carrying out a multinational compliance review for a leading US investment bank in 16 jurisdictions. - Advising a Belgian based multinational financial services company on its data privacy compliance. Recent work includes: - Working with the UK s OIC regulator on a pilot project to evaluate the use of binding corporate rules as an international data flow compliance method. - Developing a unique approach to international data privacy compliance for a multinational investment bank, resolving competing bank regulatory, taxation and data privacy issues. - Devising an international data protection compliance strategy for a multinational hotel chain operating in more than 45 jurisdictions. Where data privacy issues go wrong, disputes can rapidly escalate out of control. Regulators have far reaching powers, including freezing databases and imposing substantial fines. Linklaters have assisted in the successful resolution of disputes with: - OIC (UK regulator) - APD (Spanish regulator) - CNIL (French regulator) - GIODO (Polish regulator) and others. We have also advised on civil disputes in a number of jurisdictions. e-learning provides organisations with a unique combination of quality training, auditability and visibility. Not only are staff trained in a consistent manner, but training completion and success can be monitored. Finally, it provides excellent visibility of data protection compliance within your organisation and with regulators. Linklaters is currently working with a leader in e-learning solutions to develop customised elearning data protection training packages. Pilot projects are underway. If you would like to be involved, please let us know. In the course of advising clients on data privacy compliance projects around the world, Linklaters has developed a suite of more than 20 template documents to assist clients in the creation of compliant processes and procedures. Those documents include: - Privacy Policies - Employee Handbook templates - Security Polices

Recent experience includes advising: A global investment bank on a complex client data aggregation project, involving ten jurisdictions and financial services, confidentiality, data protection and intellectual property advice in relation to a client database which continuously aggregated and anonymised data. protection, privacy, direct marketing and on-line competition laws and regulations made this project particularly challenging. A major credit card company on a cross-border compliance audit. The project involves dealing with European member banks as well as the client s US headquarters. On the transfer of personal data, transfer within EU and to US, safe harbour regulation, drafting of data protection agreements (controller-controller, controller-processor) and lobbying with EU Article 29 Working Party, including important aspects of cross-border data flow with regard to sensitive data. The Big Four plus Two accounting firms on areas of significant potential conflicts between the requirements of the US Sarbanes-Oxley Act 2002 and the laws and regulations of various jurisdictions outside the US, including data protection, confidentiality and banking secrecy regulations. Failure to comply with the requirements of the Sarbanes-Oxley Act 2002 would prevent the accounting firms from carrying out audits of clients with reporting obligations to the Securities and Exchange Commission, so managing the areas of conflict is critical to their operations. A major hotel chain on a global data protection compliance project involving 48 jurisdictions, and more than 200 legal entities collectively handling data in respect of just over 1.3 million people. This involves co-ordinating delivery of advice, both with Linklaters offices and more than 35 external advisers, carried out using Linklaters extranet, Clients@Linklaters. A major investment bank on data protection arising from new technologies and international coordination. A leading international car rental company on a cross-border data protection audit. This included compliance with data protection law with respect to the collection, processing and use of employees personal data and customers personal data. A global financial institution on data protection compliance in relation to all its data processing and storage activities in over 20 jurisdictions. A major European Internet bank on data protection issues, including the transfer of data in connection with two different customer royalty/bonus schemes. A US credit card group on establishing a global corporate credit card scheme. A leading US media and entertainment company on a global CRM project, including advice on data protection, direct marketing and online competitions. The global nature of the project and complexity of various e-commerce, data Preparation of a European Economic Area and United States-wide data protection compliance manual for multi-national banking and finance industry business practices.

Giving us the commercial advantage Global Chambers 2003 page