Guidance note: Charitable Incorporated Organisation (CIO) status as it relates to the registration of service providers

Size: px
Start display at page:

Download "Guidance note: Charitable Incorporated Organisation (CIO) status as it relates to the registration of service providers"

Transcription

1 Guidance note: Charitable Incorporated Organisation (CIO) status as it relates to the registration of service providers Mae'r fflurflen hwn hefyd ar gael yn Gymraeg/This document is also available in Welsh [PG18/740e] Guidance note on CIO status 06/2018 1

2 Contents Summary... 3 Background... 3 Registration as an individual or as an organised body... 3 Implications for registration... 4 Registration scenario #1 an individual registered person... 4 Registration scenario #2 a limited company or charitable company which gains status as a CIO... 5 Registration scenario #3 unincorporated association which gains status as a CIO... 6 What we do with the information we receive from you [PG18/740e] Guidance note on CIO status 06/2018 2

3 Summary This guidance note has been developed to provide inspectors, registered providers and umbrella organisations with advice on Charitable Incorporated Organisation (CIO) status as it relates to the registration of service providers. The information in this guidance note has been confirmed as legally correct by Welsh Government Legal Services. Background A Charitable Incorporated Organisation is a new form of legal entity designed for non-profit organisations in the United Kingdom. CIOs have a legal personality which means they have the ability to conduct business in their own name, and limited liability so that their members and trustees do not have to contribute in the event of financial loss. CIO status is not restricted to any particular sector and CIW may have to deal with cases where adult or children s services providers are seeking or have achieved CIO status. CIW will need to consider whether the existing registration remains correct or whether the identity of the registered entity is changed by gaining CIO status. CIW is aware that umbrella groups representing a range of child care and play service providers are supporting child care and play services to seek registration with the Charities Commission as a CIO. CIW inspectors need to be aware of the implications of such a change. This guidance seeks to provide some indicators to assist inspectors and registered persons in knowing whether the correct legal entity is registered. CIW needs to ensure that: We correctly identify services where a CIO is in place; We correctly identify whether this has any implications for the existing registered provider s registration; We take appropriate action to ensure the correct legal entity is registered, and The advice we provide about the registration implications of an individual or organisation gaining CIO status is consistent across Wales. Registration as an individual or as an organised body In deciding whether an application to register as an individual or organisation is needed, CIW will consider who makes key decision regarding the operation of the service: Who is able to enter directly into employment contracts with staff; an individual person or a committee/board of Trustees? [PG18/740e] Guidance note on CIO status 06/2018 3

4 Who has control over the premises in which the service is conducted (whether as tenant or owner) an individual or committee? Does the individual themselves have a contract of employment with a committee/board of trustees? Who is able to take disciplinary action regarding the individual registered person, including decision to suspend or dismiss from employment? In whose name are the employee and public liability insurances? Who is accountable for any liabilities which may arise? If the answer to any of these points is the committee/board of trustees then CIW may consider that the service is being carried on by the committee or board of trustees and not an individual. An application to register as an organisation would therefore be required, and if they have CIO status then the application should be as a CIO. This list is not exhaustive; there may be other considerations that assist CIW to reach a conclusion Implications for registration If a service is a not-for-profit organisation and plans to or has gained status as a CIO, contact with CIW is advised if: The current registered person is an individual The current registered person is a limited company The current registered company is a charitable company The current registered provider is an unincorporated association. Registration scenario #1 an individual registered person This would be where the certificate of registration named a specific person as the registered person. This may include several individuals each named as the registered person for the same service. Alongside the individuals, there is an organised body a committee or board of trustees that govern the operation of the service. The organised body (committee or board of trustees) gain status as a CIO. This means they would have an identity as an organisation through registration as a CIO by the Charities Commission. An application to register the CIO as provider of the service will be required if: The service is carried on (see checklist above) by an organised body. [PG18/740e] Guidance note on CIO status 06/2018 4

5 The organised body gains status as a CIO. An application to register the CIO as provider of the service will not be required if: The existing registered person is an individual and holds decision making responsibility for the factors identified above. CIW will provide advice about registration requirements to any individual where it appears to us that the individual does not hold decision making responsibility relevant to the carrying on of the service. CIW is aware that there are a number of child care and play services (e.g. cylchoedd meithrin) or adult services where the registered person/provider is an individual even though there may be an organised body governing the service. In child care and play services this registration may have pre-dated the legislative changes that allowed unincorporated associations to register; in adult services this may relate to services which are carried on by a board of trustees (for example) and where the legislation does not allow application to register as provider by an unincorporated organisation. Where the existing registered person does not hold decision making responsibility then an application to register as an organisation will be required. An application to register as an organisation must be made to CIW within 28 days of registration as a CIO, and a Responsible Individual must be nominated as part of this application. Registration scenario #2 a limited company or charitable company which gains status as a CIO This would be where the registration certificate names a limited company or a charitable limited company as the registered provider. When changing from a limited company or a charitable company to a CIO, the newly created CIO will have its own separate legal identity. An application to register the CIO as provider of the service will therefore be required as: In the case of a charitable limited company, the pre-existing charitable company will be dissolved once all its assets have been transferred to the CIO, and removed from the register. The legal entity registered as provider will therefore no longer exist. In the case of a limited company, the existing registration of the limited company will be changed by the change in status of the organisation into a CIO. [PG18/740e] Guidance note on CIO status 06/2018 5

6 Registration scenario #3 unincorporated association which gains status as a CIO This would be where the registration certificate names the committee or board of trustees as the registered person. An application to register the CIO as provider of the service will be required if: A previously unincorporated association changes its status with the Charities Commission to a CIO, therefore a new legal entity with responsibility for carrying on the service is created. The unincorporated association (which was registered with CIW) would no longer exist and so a new registration with CIW in the name of the CIO would be required. What we do with the information we receive from you. We process any personal and/or sensitive information we hold about you fairly and lawfully, and we only ask for such information where it is necessary for us to carry out our role. For more information about how we process your personal data, and your rights in relation to this, please see our Privacy Notice at or contact us for a paper copy. [PG18/740e] Guidance note on CIO status 06/2018 6

Made In Hackney Data Protection Policy Last Updated:

Made In Hackney Data Protection Policy Last Updated: Made In Hackney Data Protection Policy Last Updated: 16.05.2018 Definitions Charity GDPR Responsible Person Register of Systems Made In Hackney (MIH), a registered charity. means the General Data Protection

More information

UWC International Data Protection Policy

UWC International Data Protection Policy UWC International Data Protection Policy 1. Introduction This policy sets out UWC International s organisational approach to data protection. UWC International is committed to protecting the privacy of

More information

Clubs template privacy notice wording

Clubs template privacy notice wording Clubs template privacy notice wording This template sets out the headings required under GDPR. Where possible, we have sought to include options for different categories of data subject and include examples.

More information

What you ll need to sign up to a PayPal Charity or Not-for-profit account. Click the button that applies to you

What you ll need to sign up to a PayPal Charity or Not-for-profit account. Click the button that applies to you What you ll need to sign up to a PayPal Charity or Not-for-profit account OR Click the button that applies to you Sign up as a charity Before you start First, you should choose a primary account holder,

More information

INFORMATION SECURITY AND RISK POLICY

INFORMATION SECURITY AND RISK POLICY INFORMATION SECURITY AND RISK POLICY 1 of 12 POLICY REFERENCE INFORMATION SHEET Document Title Document Reference Number Information Security and Risk Policy P/096/CO/03/11 Version Number V02.00 Status:

More information

Corporate Information Security Policy

Corporate Information Security Policy Overview Sets out the high-level controls that the BBC will put in place to protect BBC staff, audiences and information. Audience Anyone who has access to BBC Information Systems however they are employed

More information

sportscotland Clubs template privacy notice wording

sportscotland Clubs template privacy notice wording sportscotland Clubs template privacy notice wording Drafting Note: This template sets out the headings required under the GDPR. Where possible, we have sought to include options for different categories

More information

Guidance Note: Professional Qualifications (Investment Business)

Guidance Note: Professional Qualifications (Investment Business) 1 Background 1.1 Section 3.3 of the Codes of Practice for Investment Business (the Codes of Practice ) requires a registered person to assess and monitor the competence of its employees. Section 3.3.5

More information

DATA PROTECTION POLICY THE HOLST GROUP

DATA PROTECTION POLICY THE HOLST GROUP DATA PROTECTION POLICY THE HOLST GROUP INTRODUCTION The purpose of this document is to provide a concise policy regarding the data protection obligations of The Holst Group. The Holst Group is a data controller

More information

RVC DATA PROTECTION POLICY

RVC DATA PROTECTION POLICY RVC DATA PROTECTION POLICY POLICY and PROCEDURES Responsibility of Data Protection Officer Review Date July 2019 Approved by CEC Author D.Hardyman-Rice CONTENTS PAGE 1) Policy Statement 3 2) Key definitions

More information

Online Filing Guide for Charities and Professional Fundraisers

Online Filing Guide for Charities and Professional Fundraisers South Carolina Secretary of State Online Filing Guide for Charities and Professional Fundraisers April 2010 1205 Pendleton Street, Suite 525 Columbia, South Carolina 29201 www.sos.sc.gov Charitable Organizations

More information

Whiteinch and Scotstoun Housing Association and WS Property Management Ltd. Privacy Policy

Whiteinch and Scotstoun Housing Association and WS Property Management Ltd. Privacy Policy Whiteinch and Scotstoun Housing Association and WS Property Management Ltd. Privacy Policy We are committed to ensuring your privacy is protected and our collection and use of your personal information

More information

CNPD Course: Data Protection Basics

CNPD Course: Data Protection Basics CNPD Course: Data Protection Basics Presentation of Luxembourg s data protection authority Esch-sur-Alzette (Belval) Dani Jeitz 4-6 July 2017 Legal department Introduction to data protection 1. Introduction

More information

CERTIFICATION OF CONSTRUCTION (ELECTRICAL INSTALLATIONS TO BS 7671) SCHEME GUIDE. SBSC Scottish Building Serv ices Certification

CERTIFICATION OF CONSTRUCTION (ELECTRICAL INSTALLATIONS TO BS 7671) SCHEME GUIDE. SBSC Scottish Building Serv ices Certification CERTIFICATION OF CONSTRUCTION (ELECTRICAL INSTALLATIONS TO BS 7671) SCHEME GUIDE SBSC Scottish Building Serv ices Certification www.niceic.com www.select.org.uk GUIDE TO THE SCHEME FOR CERTIFICATION OF

More information

Government Privacy. Julie Smith McEwen, CIPP/G, CISSP Principal Information Systems Privacy and Security Engineer

Government Privacy. Julie Smith McEwen, CIPP/G, CISSP Principal Information Systems Privacy and Security Engineer IAPP Privacy Certification Certified Information Privacy Professional/Government (CIPP/G) Government Privacy Julie Smith McEwen, CIPP/G, CISSP Principal Information Systems Privacy and Security Engineer

More information

Managing Jurisdictional Risks for Public Cloud Services

Managing Jurisdictional Risks for Public Cloud Services Managing Jurisdictional Risks for Public Cloud Services Version 1.0 July 2017 1 Contents Executive summary 3 Definitions 4 Assessing jurisdictional risk 5 Commonly-used jurisdictions 8 2 Executive summary

More information

Vistra International Expansion Limited PRIVACY NOTICE

Vistra International Expansion Limited PRIVACY NOTICE Effective Date: from 25 May 2018 Vistra International Expansion Limited PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal

More information

The British Museum. Data Protection Code of Practise. 1 Introduction

The British Museum. Data Protection Code of Practise. 1 Introduction The Data Protection Code of Practice 1 Introduction 1.1 The 1998 Data Protection Act is aimed at ensuring a balance between individuals rights to privacy and the lawful processing of personal data undertaken

More information

Information Governance Incident Reporting Procedure

Information Governance Incident Reporting Procedure Information Governance Incident Reporting Procedure : 3.0 Ratified by: NHS Bury CCG Quality and Risk Committee Date ratified: 15 th February 2016 Name of originator /author (s): Responsible Committee /

More information

Data Privacy for Multinationals: How to Build and Implement a Compliance Plan

Data Privacy for Multinationals: How to Build and Implement a Compliance Plan Data Privacy for Multinationals: How to Build and Implement a Compliance Plan Augusta Speiser is responsible for guiding DENTSPLY Internationals efforts relating to ethics and compliance worldwide with

More information

Subject: Kier Group plc Data Protection Policy

Subject: Kier Group plc Data Protection Policy Kier Group plc Data Protection Policy Subject: Kier Group plc Data Protection Policy Author: Compliance Document type: Policy Authorised by: Kier General Counsel & Company Secretary Version 3 Effective

More information

A checklist for the new 990 requirements:

A checklist for the new 990 requirements: A checklist for the new 990 requirements: 1.) a mission statement or a description of the organizations most significant activities: 2.) the number of voting members in the organization s governing body

More information

Protecting Your Business: Best Practices for Implementing a Legally Compliant Cybersecurity Program Trivalent Solutions Expo June 19, 2014

Protecting Your Business: Best Practices for Implementing a Legally Compliant Cybersecurity Program Trivalent Solutions Expo June 19, 2014 Protecting Your Business: Best Practices for Implementing a Legally Compliant Cybersecurity Program Trivalent Solutions Expo June 19, 2014 2014, Mika Meyers Beckett & Jones PLC All Rights Reserved Presented

More information

Data protection. A brief guide to notification

Data protection. A brief guide to notification Data protection A brief guide to notification Contents 3 Contents Introduction What is the Data Protection Act 1998? 4 Frequently asked questions 6 Notification exemptions 10 A self-assessment guide 10

More information

GDPR is coming in less than 2 months Are you ready?

GDPR is coming in less than 2 months Are you ready? GDPR is coming in less than 2 months Are you ready? Charles-Albert Helleputte Partner, Brussels +32 2 551 5982 chelleputte@mayerbrown.com 30 March 2018 2 GDPR is everywhere... You were invited by UNICEO

More information

DATA PROTECTION SELF-ASSESSMENT TOOL. Protecture:

DATA PROTECTION SELF-ASSESSMENT TOOL. Protecture: DATA PROTECTION SELF-ASSESSMENT TOOL Protecture: 0203 691 5731 Instructions for use touches many varied aspects of an organisation. Across six key areas, the self-assessment notes where a decision should

More information

Data Privacy for Multinationals: How to Build and Implement a Compliance Plan

Data Privacy for Multinationals: How to Build and Implement a Compliance Plan Data Privacy for Multinationals: How to Build and Implement a Compliance Plan Augusta Speiser is responsible for guiding DENTSPLY Internationals efforts relating to ethics and compliance worldwide with

More information

Federated Authentication for E-Infrastructures

Federated Authentication for E-Infrastructures Federated Authentication for E-Infrastructures A growing challenge for on-line e-infrastructures is to manage an increasing number of user accounts, ensuring that accounts are only used by their intended

More information

WELCOME ISO/IEC 27001:2017 Information Briefing

WELCOME ISO/IEC 27001:2017 Information Briefing WELCOME ISO/IEC 27001:2017 Information Briefing Denis Ryan C.I.S.S.P NSAI Lead Auditor Running Order 1. Market survey 2. Why ISO 27001 3. Requirements of ISO 27001 4. Annex A 5. Registration process 6.

More information

Privacy Policy Wealth Elements Pty Ltd

Privacy Policy Wealth Elements Pty Ltd Page 1 of 6 Privacy Policy Wealth Elements Pty Ltd Our Commitment to you Wealth Elements Pty Ltd is committed to providing you with the highest levels of client service. We recognise that your privacy

More information

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION Document Control Owner: Distribution List: Data Protection Officer Relevant individuals who access, use, store or

More information

VISTRA ZURICH AG - PRIVACY NOTICE

VISTRA ZURICH AG - PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA ZURICH AG - PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

User Guide Maintain Trustees, Connections and External Advisors

User Guide Maintain Trustees, Connections and External Advisors Fields marked with a red asterisk are mandatory and must be completed. User Guide Maintain Trustees, Connections and External Advisors Use this form to update, add or remove charity trustees, or to update

More information

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

Policy & Procedure Privacy Policy

Policy & Procedure Privacy Policy NUMBER POL 050 PAGES 12 VERSION V3.8 CREATED: LAST MODIFIED: REVISION: 05/11/2009 06/06/2018 06/06/2019 DOCUMENTS: Authority to Exchange Information Media Authority Student Staff Privacy Agreement REFERENCES:

More information

VISTRA MONACO PRIVACY NOTICE

VISTRA MONACO PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA MONACO PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights in

More information

Castle View Primary School Data Protection Policy

Castle View Primary School Data Protection Policy Castle View Primary School Data Protection Policy Aims The Headteacher and Governors of the school intend to comply fully with the requirements and principles of the Data Protection Act 1998. All staff

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Introduction Stewart Watt & Co. is law firm and provides legal advice and assistance to its clients. It is regulated by the Law Society of Scotland. The personal data that Stewart

More information

UCSU Student and Applicant Data Privacy Statement

UCSU Student and Applicant Data Privacy Statement UCSU Student and Applicant Data Privacy Statement Version number: 1.0 Policy Owner: Data Protection Officer Last Revised: May 2018 Review Date: July 2018 This document is to be reviewed biannually (January

More information

Organisation Registration Form

Organisation Registration Form Organisation Registration Form Organisation Details 1 Name of organisation/group 2 Type of Organisation (please circle) Voluntary/ Statutory/ Private/ Government 3 Website address 4 General / main organisation

More information

The New Data Protection Law a Basic Guide

The New Data Protection Law a Basic Guide The New Data Protection Law a Basic Guide The new Data Protection Law and how it affects fundraising. DRF Group Ltd has prepared this basic guide to the main provisions of the new Data Protection Act as

More information

Archive Legislation: archiving in the United Kingdom. The key laws that affect your business

Archive Legislation:  archiving in the United Kingdom. The key laws that affect your business Archive Legislation: Email archiving in the United Kingdom The key laws that affect your business Contents Laws regulating archiving, who they apply to and the penalties 3 Who is affected? 3 All private

More information

AIRMIC ENTERPRISE RISK MANAGEMENT FORUM

AIRMIC ENTERPRISE RISK MANAGEMENT FORUM AIRMIC ENTERPRISE RISK MANAGEMENT FORUM Date 10 November 2016 Name Nick Gibbons Position, PARTNER BLM T: 0207 457 3567 E: Nick.Gibbons@blmlaw.com SUMMARY Cyber crime is now a daily reality Every business

More information

DATA SECURITY - DATA PROTECTION ACT

DATA SECURITY - DATA PROTECTION ACT DATA SECURITY - DATA PROTECTION ACT Data Security - Data Protection Act Many businesses are totally reliant on the data stored on their PCs, laptops, networks, mobile devices and in the cloud. Some of

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Introduction The purpose of this document is to provide a concise policy regarding the data protection obligations of Youth Work Ireland. Youth Work Ireland is a data controller

More information

The Data Protection Act 1998 Clare Hall Data Protection Policy

The Data Protection Act 1998 Clare Hall Data Protection Policy The Data Protection Act 1998 Clare Hall Data Protection Policy Introduction This document is a guide to the main requirements of the new Data Protection Act (DPA) that came into force on 24th October 2001.

More information

NOT PROTECTIVELY MARKED SUPPLIER REGISTRATION FORM

NOT PROTECTIVELY MARKED SUPPLIER REGISTRATION FORM SUPPLIER REGISTRATION FORM Thank you for taking the time to complete the Horizon Supplier Registration form. Please contact suppliers@horizonnuclearpower.com if additional assistance is required. Highlighted

More information

Privacy Notice. General Information Protection Regulation ( GDPR )

Privacy Notice. General Information Protection Regulation ( GDPR ) Privacy Notice General Information Protection Regulation ( GDPR ) Please read the following information carefully. This privacy notice contains information about the information collected, stored and otherwise

More information

Federated authentication for e-infrastructures

Federated authentication for e-infrastructures Federated authentication for e-infrastructures 5 September 2014 Federated Authentication for E-Infrastructures Jisc Published under the CC BY 4.0 licence creativecommons.org/licenses/by/4.0/ Contents Introduction

More information

7 th Darlington Sea Scouts G.D.P.R. STATEMENT AND POLICY

7 th Darlington Sea Scouts G.D.P.R. STATEMENT AND POLICY 7 th Darlington Sea Scouts Eastbourne Hall Cobden Street DL1 4JF www.7thdarlingtonseascouts.org.uk 01670 856123 07771 415936 gsl@7thdarlingtonseascouts.org.uk G.D.P.R. STATEMENT AND POLICY Version (3)

More information

DCU Guide to Subject Access Requests. Under Irish Data Protection Legislation

DCU Guide to Subject Access Requests. Under Irish Data Protection Legislation DCU Guide to Subject Access Requests Under Irish Data Protection Legislation Context Under section 4 of the Irish Data Protection Acts 1988 & 2003 an individual, on making a written request to DCU, may

More information

Information Governance Incident Reporting Policy

Information Governance Incident Reporting Policy Information Governance Incident Reporting Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 29 th November 2017 Name of originator

More information

INDEPENDENT REGISTERED REPRESENTATIVE ANNUAL CERTIFICATION

INDEPENDENT REGISTERED REPRESENTATIVE ANNUAL CERTIFICATION IMS Securities, Inc. Member FINRA/SIPC IMS Financial Advisors, Inc. INDEPENDENT REGISTERED REPRESENTATIVE ANNUAL CERTIFICATION The Firm and you are subject to a multitude of laws and regulations governing

More information

World Wide Jobs Ltd t/a Findmyexpert.com Privacy Policy 12 th April 2018

World Wide Jobs Ltd t/a Findmyexpert.com Privacy Policy 12 th April 2018 World Wide Jobs Ltd t/a Findmyexpert.com Privacy Policy 12 th April 2018 We understand that you are aware of and care about your own personal privacy interests and we take that seriously. This Privacy

More information

UUEAS Privacy policy - Members

UUEAS Privacy policy - Members UUEAS Privacy policy - Members The Union of UEA Students (The Union) is an independent charity, whose primary goal is to represent the students at the University of East Anglia. Every student at UEA is

More information

User Guide for Conflict of Interest Individual Filers

User Guide for Conflict of Interest Individual Filers User Guide for Conflict of Interest Individual Filers State Officers and Employees A new officer or employee working in a disclosure designated position must submit a Statement of Economic Interests as

More information

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017 Data Protection should be part of every company s or organisation s DNA Do you process

More information

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

VISTRA (CYPRUS) LTD. PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA (CYPRUS) LTD. PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

Data Privacy Breach Policy and Procedure

Data Privacy Breach Policy and Procedure Data Privacy Breach Policy and Procedure Document Information Last revision date: April 16, 2018 Adopted date: Next review: January 1 Annually Overview A privacy breach is an action that results in an

More information

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk CURTIS BANKS LIMITED Privacy Information Notice curtisbanks.co.uk Contents Section Page 1 Who we are 3 2 Why we need to collect, use and process personal information 3 3 The information we may collect,

More information

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. I. OBJECTIVE ebay s goal is to apply uniform, adequate and global data protection

More information

VISTRA NETHERLANDS PRIVACY NOTICE

VISTRA NETHERLANDS PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA NETHERLANDS PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

Qualification Specification

Qualification Specification BCS Level 1 Award in e-safety March 2018 This is a United Kingdom government regulated qualification which is administered and approved by one or more of the following: Ofqual, Qualification in Wales,

More information

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive IT Governance ISO/IEC 27001:2013 ISMS Implementation Service description Protect Comply Thrive 100% guaranteed ISO 27001 certification with the global experts With the IT Governance ISO 27001 Implementation

More information

The Role of the Data Protection Officer

The Role of the Data Protection Officer The Role of the Data Protection Officer Adrian Ross LLB (Hons), MBA GRC Consultant IT Governance Ltd 28 July 2016 www.itgovernance.co.uk Introduction Adrian Ross GRC consultant Infrastructure services

More information

Data Protection policy (GDPR)

Data Protection policy (GDPR) Data Protection policy (GDPR) This is the statement of general policy and arrangements for: Overall and final responsibility for health and safety is that of: Day-to-day responsibility for ensuring this

More information

GDPR: A QUICK OVERVIEW

GDPR: A QUICK OVERVIEW GDPR: A QUICK OVERVIEW 2018 Get ready now. 29 June 2017 Presenters Charles Barley Director, Risk Advisory Services Charles Barley, Jr. is responsible for the delivery of governance, risk and compliance

More information

ING Public Key Infrastructure Technical Certificate Policy

ING Public Key Infrastructure Technical Certificate Policy ING Public Key Infrastructure Technical Certificate Policy Version 5.4 - November 2015 Commissioned by ING PKI Policy Approval Authority (PAA) Additional copies Document version General Of this document

More information

PS 176 Removable Media Policy

PS 176 Removable Media Policy PS 176 Removable Media Policy December 2013 Version 2.0 Statement of legislative compliance This document has been drafted to comply with the general and specific duties in the Equality Act 2010; Data

More information

Computer and Internet Use Policy

Computer and Internet Use Policy Computer and Internet Use Policy Author Simon Allan Date Written Autumn 2015 Review Date Autumn 2018 Date Ratified by the Governing Body Autumn 2015 Computer and Internet Use Policy Outline/Overview This

More information

TERMS AND CONDITIONS

TERMS AND CONDITIONS TERMS AND CONDITIONS BACKGROUND: This agreement applies as between you, the User of this Website and NWM, the owner(s) of this Website. Your agreement to comply with and be bound by these terms and conditions

More information

Breach Notification Assessment Tool

Breach Notification Assessment Tool Breach Notification Assessment Tool December 2006 Information and Privacy Commissioner of Ontario David Loukidelis Commissioner Ann Cavoukian, Ph.D. Commissioner This document is for general information

More information

Motorola Mobility Binding Corporate Rules (BCRs)

Motorola Mobility Binding Corporate Rules (BCRs) Motorola Mobility Binding Corporate Rules (BCRs) Introduction These Binding Privacy Rules ( Rules ) explain how the Motorola Mobility group ( Motorola Mobility ) respects the privacy rights of its customers,

More information

Data Protection Annual Report 2000/2001

Data Protection Annual Report 2000/2001 Data Protection Annual Report 2000/2001 The year has been a busy one for the University s Data Protection Officer and Data Protection Administrator. Working within UWB Subject Access Requests The DP Officer

More information

Data Protection Privacy Notice

Data Protection Privacy Notice PETA Limited Page 1 of 7 Data Protection Privacy Notice PETA Limited provides a range of services to both members of the public and to those employed within business. To enable us to provide a service,

More information

Government Resolution No of February 15, Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security

Government Resolution No of February 15, Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security Government Resolution No. 2443 of February 15, 2015 33 rd Government of Israel Benjamin Netanyahu Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security It is hereby resolved:

More information

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 ISO / IEC 27001:2005 A brief introduction Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 Information Information is an asset which, like other important business assets, has value

More information

Complaints, compliments and suggestions

Complaints, compliments and suggestions About us Complaints, compliments and suggestions 2 About us Large print format available If someone in your household needs this information in large print or as an audio recording please contact our Customer

More information

Privacy Notice For Our Customers And Contacts

Privacy Notice For Our Customers And Contacts Privacy Notice For Our Customers And Contacts What Is The Purpose Of This Notice? This notice applies to all businesses operating within The Alumasc Group plc group of Companies (the Group ), as follows:

More information

The Opt-Out Register for Fax and Telephone - Guidance for Marketers

The Opt-Out Register for Fax and Telephone - Guidance for Marketers The Opt-Out Register for Fax and Telephone - Guidance for Marketers Guidance Note 11/13 17 th December 2013 Gibraltar Regulatory Authority Data Protection Division Suite 603, Europort Gibraltar Telephone

More information

GDPR - Are you ready?

GDPR - Are you ready? GDPR - Are you ready? Anne-Marie Bohan and Michael Finn 24 March 2018 Matheson Ranked Ireland s Most Innovative Law Firm Financial Times 2017 International Firm in the Americas International Tax Review

More information

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager.

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager. London School of Economics & Political Science IT Services Policy Remote Access Policy Jethro Perkins Information Security Manager Summary This document outlines the controls from ISO27002 that relate

More information

SCHEME OF DELEGATION (Based on the model produced to the National Governors Association)

SCHEME OF DELEGATION (Based on the model produced to the National Governors Association) SCHEME OF DELEGATION (Based on the model produced to the National Association) THE PURPOSE OF A SCHEME OF DELEGATION: A scheme of delegation (SoD) is the key document defining which functions have been

More information

GDPR SUBJECT ACCESS REQUESTS PROCEDURE

GDPR SUBJECT ACCESS REQUESTS PROCEDURE SIMON BALLE ALL-THROUGH SCHOOL GDPR SUBJECT ACCESS REQUESTS PROCEDURE First Issue: April 2018 Next Review: April 2020 Committee Responsible: Personnel and/or Student SUBJECT ACCESS REQUESTS (SAR) INTRODUCTION

More information

CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION

CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION Introduction The IFFO RS Certification Programme is a third party, independent and accredited

More information

EIT Health UK-Ireland Privacy Policy

EIT Health UK-Ireland Privacy Policy EIT Health UK-Ireland Privacy Policy This policy describes how EIT Health UK-Ireland uses your personal information, how we protect your privacy, and your rights regarding your information. We promise

More information

LG Inform - LG Inform Plus Powers and Duties Help Guide. January 2017

LG Inform - LG Inform Plus Powers and Duties Help Guide. January 2017 LG Inform - LG Inform Plus Powers Records LG Inform and Retention Plus Duties Help Guide Powers and Duties Help Guide January 2017 February 2017 1 This document outlines the process behind utilising the

More information

Cyber Crime Seminar 8 December 2015

Cyber Crime Seminar 8 December 2015 Cyber Crime Seminar Cyber Security & Financial Services in a changing regulatory landscape John Salmon Partner, Pinsent Masons LLP @uktisa Cyber Security and Financial Services: A changing regulatory landscape

More information

Level 1 Internet Safety for IT Users ( )

Level 1 Internet Safety for IT Users ( ) Level 1 Internet Safety for IT Users (7574-135) ITQ (QCF) Assignment guide for Candidates Assignment B www.cityandguilds.com November 2011 Version 1.0 About City & Guilds City & Guilds is the UK s leading

More information

Data protection register your organisation

Data protection register your organisation Data protection register your organisation This form is for organisations (we use this term to include all data controllers, including sole traders, companies, and MPs) that need to register with the ICO

More information

Information security guidance for schools

Information security guidance for schools Information security guidance for schools Guidance Guidance document no: 206/2016 Date of issue: August 2016 Replaces guidance document no: 186/2015 Information security guidance for schools Audience All

More information

Data Protection Policy

Data Protection Policy The Worshipful Company of Framework Knitters Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act 1998 (DPA) [UK] For information on this

More information

Data Processor Agreement

Data Processor Agreement Data Processor Agreement Data Controller: Customer located within the EU (the Data Controller ) and Data Processor: European Representative Company: ONE.COM (B-one FZ-LLC) One.com A/S Reg.no. Reg.no. 19.958

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management INTERNATIONAL STANDARD ISO/IEC 17799 Second edition 2005-06-15 Information technology Security techniques Code of practice for information security management Technologies de l'information Techniques de

More information

Care Recruitment Matters Limited Privacy Notice

Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited (CRM) is a specialist recruitment agency, sourcing permanent candidates for companies focused in the Health and Social Care

More information

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC Auditing and Monitoring for HIPAA Compliance HCCA COMPLIANCE INSTITUTE 2003 April, 2003 Presented by: Suzie Draper Sheryl Vacca, CHC 1 The Elements of Corporate Compliance Program There are seven key elements

More information

SWBCCG Pol 18. Information Governance handbook

SWBCCG Pol 18. Information Governance handbook SWBCCG Pol 18 Information Governance handbook 1 SWBCCG Pol 18 Information Reader Box Directorate Purpose Document Purpose Document Name Author Sandwell and West Birmingham CCG Guidance Procedures Information

More information

Online CRB Disclosure Application System

Online CRB Disclosure Application System Online CRB Disclosure Application System Applicant s Guidance on Completing an Online Criminal Records Bureau Disclosure (CRB) Introduction Babcock International Support Services Ltd acts as an umbrella

More information

Data Safety and Information Security

Data Safety and Information Security Data Safety and Information Security Guidance for meetings A link to an electronic copy of this document is available at www.quaker.org.uk/clerks, 2014 This replaces all previous editions Published by

More information