This information accompanies the online data sharing best practice guidance commissioned by ACE

Size: px
Start display at page:

Download "This information accompanies the online data sharing best practice guidance commissioned by ACE"

Transcription

1 Data Protection - What the regulations say This information accompanies the online data sharing best practice guidance commissioned by ACE The guidance cannot be relied upon as legal advice. This document gives guidance as to how to follow best practice. Organisations should follow the guidance, but as compliance is context sensitive, the Information Commissioner s Office must judge any complaint on its own merits, and organisations in need of context or situation specific legal advice should seek it from an appropriately qualified source. Introduction This information sets out the relevant elements and obligations of the regulations governing the use of data for marketing and audience development purposes. It relates to each stage of the data journey including data collection, permissions gathering, storage, sharing and uses. For further resources, visit the Information Commissioner s Office website. 1.1 Brief introduction to the UK data protection regime Background The Data Protection Act 1998 (the DPA ) implemented the EU Directive 95/46/EEC on the protection of individuals with regard to the processing of personal data and on the free movement of such data. This replaced the UK's previous Data Protection Act 1984 in its entirety. The overarching purpose of the EU Data Directive was to introduce an extensive data protection regime by imposing broad obligations on those who collect personal data, as well as conferring broad rights on individuals about whom data is collected. Data Protection - What the regulations say 1 of 19

2 Key definitions used by the DPA A brief review of some of the key terms used by the DPA is probably helpful: Data Controller The person who alone, jointly or in common with other people determines the purposes, and the manner, in which any personal data is processed. A party may be a Data Controller, even if the information concerned is held by somebody else. There can be more than one Data Controller in respect of a piece of data. Most, if not all, of the principal obligations in the DPA fall to the Data Controller. In the cultural sector this is commonly (but not exclusively) an organisation managing ticketing transactions, most often the presenting venue. Data Processor A data processor processes personal data only on behalf of a data controller. Data Subject Any individual about whom personal data is processed. Personal Data Personal data is data relating to living individuals who can be identified from that data, or from that data and other information which is in the possession of, or is likely to come into the possession of, the data controller. Data is also defined in the DPA as information which is being processed by means of equipment that operates automatically in response to instructions given for that purpose, or is recorded with the intention that it should be processed by means of such equipment. The DPA therefore applies to automated data, such as that stored on a computer. It also extends to certain manual records. Data Protection - What the regulations say 2 of 19

3 The DPA imposes some additional obligations on the Data Controller in relation to sensitive personal data. Sensitive personal data is data which relates to race, political opinions, health, sexual life, religious and other similar belief, trade union membership and/or criminal records. The data protection principles The DPA requires the Data Controller to comply with eight data protection principles, which are set out in a schedule to the Act. The eight principles are as follows: Data must be processed fairly and lawfully. Data must be obtained only for specified lawful purposes and not further processed in a manner which is incompatible with those purposes. Data must be adequate, relevant and not excessive in relation to the purposes for which it is processed. Data must be accurate and, where necessary, kept up to date. Data must not be kept for longer than is necessary. Data must be processed in accordance with the rights of Data Subjects under the DPA. Appropriate technical and organisational security measures must be taken to prevent unauthorised or unlawful processing, accidental loss of or destruction or damage to personal data. Personal data must not be transferred outside the EEA unless the destination country ensures an adequate level of protection for the rights of the data subject in relation to the processing of personal data. The Privacy and Electronic Communications (EC Directive) Regulations 2003 ( PECR ) The PECR are not relevant to all data protection matters but the Regulations do complement the DPA by giving more specific rights in respect of electronic communications. The PECR principally cover the following areas: Marketing by electronic means, including marketing calls, texts, s and faxes. Data Protection - What the regulations say 3 of 19

4 The use of cookies or similar technologies that track information about people accessing a website or other electronic service. Security of public electronic communications services. Privacy of customers using communications networks or services as regards traffic and location data, itemised billing, line identification services (e.g. caller ID and call return) and directory listings. In short, the PECR restrict unsolicited marketing by phone, fax, , text or other electronic message. The rules are generally stricter for marketing to individuals than for marketing to companies. Specific consent is required in order to send unsolicited direct marketing to someone. 2.1 The Data Journey an overview of the law As data is legitimately put to practical use by cultural organisations it passes through several stages of a journey - from collection, to use, via permissions gathering, storage and sharing. This diagram charts the journey, highlighting at each stage factors which the legislation governing the use of data touches upon. Cultural organisations which collect, store, use or share their customers personal information should be familiar with their obligations at each stage. The following sections of this document set out the relevant regulations that apply at each stage. For example, when collecting data from their patrons, organisations should be aware of what constitutes personal data; what does and does not fall under the provisions of the regulations that protect the rights of the person to whom that data belongs, the data subjects. It is imperative that the organisations collecting the data gain the right permissions from the data subjects at this stage. This ensures the data can be processed and put to use legitimately and in compliance with good practice. Patrons must be given adequate notification of the intended uses of their data. The process for providing this and the content of notification statements will need to change according to Data Protection - What the regulations say 4 of 19

5 the context in which the data is being collected, and in relation to the particular communication channels to be used. It is important to note that there are certain items of information about individuals that constitute sensitive data (as defined by the regulations). These have specific implications and obligations for data controllers. The regulations also address the manner in which data is stored and maintained to ensure that it is kept securely and that it remains clean and relevant. The potential to then use or share data is wholly governed by notifications given and the permissions obtained. 3.1 Collecting data overview There are various different channels through which arts organisations may interact with their audiences, and at which data may regularly be collected from those audiences. Principally, these points tend to be focused around the point of sale for event tickets, which may happen in person over the counter, over the telephone or online. Data is also regularly collected through audience surveys. The specific context determines to some extent the type of data that will most likely be collected from the audience. It also determines the specific means in which information notifications can be given to the audience that explain why the data is being collected and how it will be used. For example, over the counter transactions allow staff to talk to customers about how their information is being used, and in which returning customers can also be recognised and their records looked up to attach the new transaction, saving the need to repeatedly ask for certain information about the customer. In online transactions, however, there is a specific need and opportunity to build into the booking procedure processes which first recognise returning customers, and then present (or not) the necessary Data Protection - What the regulations say 5 of 19

6 notifications, and permission gathering mechanisms as appropriate to the individual. Aspects of Data Protection legislation address the type of data that may be collected, its storage and management and the reasons for collecting it. The legislation also covers the information that should be given to the customer and the permissions that must be sought from the customer in relation to how the data will be used. The different contexts in which data is collected are sometimes governed by different pieces of legislation. The following is an overview of the legal obligations in relation to the collection of data. 3.2 The law relating to data collection The moment you collect data from a customer, this constitutes processing under the DPA. The point at which the data is obtained from the customer (and even beforehand) is arguably the most important part of the data journey. This is because what is agreed with the data subject at the point of data collection will largely govern what can and must happen to the data thereafter. In order to comply with the first data protection principle (fairness and lawfulness), the law requires that the data subject is provided with the following (as a minimum): The identity of the organisation that controls the processing; The purpose(s) for which the data will be processed; and Any further information necessary in the circumstances to ensure the fair processing of the data. If you propose to share the data you are collecting, you should also explain to the data subject who you are going to share the data with (be it a particular organisation or a type of organisation) and why you are going to share the data. The most common and effective way of providing the data subject with any or all the above information is by way of a privacy notice. If the Data Protection - What the regulations say 6 of 19

7 data is going to be used in a way in which the data subject can expect, it is generally enough to simply make the privacy notice available for the data subject to access. However, if you are doing any of the following then you should actively communicate the privacy notice to the data subject: Sharing sensitive personal data Sharing is likely to be unexpected or objectionable Sharing the data, or not sharing it, will have a significant effect on the individual The sharing is particularly widespread, involving organisations individuals might not expect; or the sharing is being carried out for a range of different purposes. Examples of active communication are sending a letter, reading out the privacy notice or sending an . The third data protection principle also requires that the data collected be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. This principle is best complied with prior to collecting the data, by giving thought to what information you require from the data subject in order to meet the objectives that the data is to be used for, such as information customers of a forthcoming show to sell tickets. You should then take no more data than is necessary for that purpose(s). 4.1 Permissions overview The basic principles of the Data Protection Act say that people should know who is processing their personal information and for what purposes, what the results will be and that people should be able to agree to what happens to their personal information. Therefore, how data from customer records can be used for marketing and audience development purposes, rely entirely on; The circumstances in which the data in the records was captured The notifications given to the customer at the time The permissions obtained Data Protection - What the regulations say 7 of 19

8 Good practice dictates that the permissions sought should be specific about who is going to be using the customers data and specific about what they are using it for. It s therefore important that the notifications given to customers are clearly presented at the right point of the customer interaction and that they allow the organisation to safely use the data for the required purpose. Opt in or Out? Sometimes there can be confusion about whether customers are expected to opt-in or opt-out of certain uses of their personal information. Past good practice guidance has also highlighted some specific circumstances in which organisations can reasonably assume that customers have opted-in, or in which there is a soft opt-in (which may be assumed because the appropriate notifications have been made), but in which a particular permission has not explicitly been sought. These situations can be complicated further when both a presenting venue and a touring company wish to share and use the same customer data. Moreover, the appropriate application of these assumptions are precise to the context in which the transaction is taking place. In simple terms, this section explains what the law says customers need to know and agree to about how their data is going to be used. It also sets out what the law says about the types of use for which permission must be sought, and also what the legislation says must be done to enable organisations to share customers personal information. The guidance then details the practicalities which should be followed to enable organisations to gain the right permissions to enable them to use and share their customer data whilst ensuring compliance with the legislation. 4.2 The law relating to permissions Data Protection - What the regulations say 8 of 19

9 There is a fundamental difference between: Informing a data subject how you are going to use their data Getting the data subject s consent to that use. There is no definition of consent in the DPA. However, the accepted definition is any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed." Meaning you need to be clear about the use of the data to the customer at the specific data collection point. The consent given by the data subject must also be unambiguous. The DPA sets out a number of grounds on which the lawfulness of the processing can be established. One of those grounds is consent. As such, if the data subject gives consent to the processing of their data then the lawfulness element of the first data protection principle is adhered to. When should consent be obtained? There is an element of unresolved conflict here between the UK and EU positions. The position adopted by the EU Article 29 s Working Party on the definition of consent, is that consent should be obtained prior to any data processing unless any of the other legitimising grounds in the DPA apply. What constitutes valid consent? Freely given consent This means that: The data subject has a real choice about whether to consent to what the data controller wants to do with the data; and there is no risk of deception, intimidation, coercion or significant negative consequences if the data subject does not consent. Specific consent Data Protection - What the regulations say 9 of 19

10 In order to be specific, consent must be given with respect to the type of personal data that is processed and the exact purpose for which it is processed. Different aspects of the processing must be clearly identified. Blanket consent for an open-ended set of processing activities is not sufficient. For example, you cannot simply share information with every touring company because you have specific agreement for one. This means that the consent obtained must refer clearly and precisely to both the scope and the consequences of the data processing. If the data controller proposes to use the same data for a purpose which is somewhat different to the purpose covered by the original consent, then it may be possible to rely on the original consent so long as the subsequent processing falls within the reasonable expectation of the data subject at the time the consent was given. Informed Consent The most effective way of ensuring that informed consent can be given by the data subject is for the data controller to express the information in a clear and understandable way. The information should also be readily accessible (this links to active communication that was discussed in 3.2 in relation to permissions). Unambiguous consent In short, this means that the indication by which the data subject signifies their agreement to the data processing must leave no doubt about the fact that the data subject does in fact agree to that processing. Consent and the rest of the DPA It is important to note that obtaining consent from the data subject does not relieve the data controller of the other obligations imposed by the DPA. The data protection principles still apply to data that has been obtained when the legitimising ground for processing is consent. 5.1 Data storage overview Data Protection - What the regulations say 10 of 19

11 With arts organisations collecting, processing and using increasing volumes of customer data, it is important to consider what data is stored how and where it is stored and managed to ensure compliance with the Act s stipulations on the adequacy and accuracy of data. The Act is also concerned with the security of data, to ensure it cannot be accessed or processed by anyone without permission to do so and to ensure the safety and integrity of data in the event that it is shared with any third parties. 5.2 The law relating to data storage The seventh data protection principle states that organisations that process personal data must take "appropriate technical and organisational measures" to protect that data against unauthorised or unlawful processing and against accidental loss or destruction of, or damage to personal data. It is important to understand that the requirements of the Data Protection Act go beyond the way information is stored or transmitted. The seventh data protection principle relates to the security of every aspect of the processing of personal data. The DPA 1998 does not define appropriate technical and organisational measures. However, the interpretive provisions of the Act state that, in order to comply with the seventh data protection principle, data controllers must take into account the state of technical development and the cost of implementing such measures. A data controller must also take reasonable steps to ensure the reliability of any employees who have access to personal data. Additionally, the data controller is responsible for ensuring that any data processor it employs takes the necessary steps to ensure the controller s compliance with the seventh data protection principle. Overall, the security measures adopted must ensure a level of security appropriate to both: The harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage of personal data; and the nature of the personal data to be protected. Data Protection - What the regulations say 11 of 19

12 In terms of what organisations should do if there is a breach, organisations would be well advised to have a data breach response plan in place to enable them to respond to a data breach swiftly and effectively. The Information Commissioner suggests that in order to appropriately manage a breach of security, an organisation should: Adopt a recovery plan, including damage limitation. Carry out an assessment of any ongoing risks associated with the breach. Consider whether a breach of security should be notified, who should be notified and what information should be given, including specific advice to individuals on the steps they can take to protect themselves. Evaluate the cause of a breach and the effectiveness of its response to it. The fifth data protection principle (data should be kept no longer than is necessary) is also important to bear in mind in terms of a Data Controller s obligations as far as storage is concerned. 6.1 Data sharing overview The sharing of customer information is permitted in compliance with the Data Protection Act, provided that the appropriate procedures have been followed. It is absolutely the case that venues can share customer data with touring companies, (and vice versa) should they wish to, as long as the customer has received the appropriate notifications at the appropriate time, and the relevant permissions have been obtained. Arts organisations appear to discuss the ownership of customer records, but what should be understood is that the customer owns their data, and the law puts them in charge of granting permissions for its usage. Data Protection - What the regulations say 12 of 19

13 No organisation is an owner of the data, but is responsible for controlling the use of the data they have in their customer records in accordance with the customer s wishes and the relevant regulations. The customer is the first party in transactions, and the organisation they are transacting with is the second party; in the case of ticket purchases the organisation actually selling the ticket and directly receiving the income is the second party. The second party is the Data Controller and must manage the arrangements for data sharing and any practicalities to obtain additional permissions. 6.2 The law relating to data sharing Data sharing essentially relates to the disclosure of data between parties. Sometimes, the disclosure of data within an organisation can even constitute sharing data for the purposes of the DPA. Sharing data can be systematic, ad-hoc or on a one-off basis. In a data-sharing context, it is important to recall that there can be more than one Data Controller in respect of the same item of data. In the context of a venue sharing data with a touring company, both parties will likely be Data Controllers. Analysis of prospective data sharing What is the reason for sharing the data? Identifying the objective of sharing data is central to dealing with the data in a way which complies with the DPA, especially the first data protection principle. Without knowing the aim of disclosing the data, one cannot properly analyse the process with a view to verifying that it is compliant. Privacy Impact Assessments Although it is not a specific requirement of the DPA, it is considered good practice for organisations that are intending to share data (whether as the discloser or the recipient) to carry out a privacy impact assessment (a PIA ). Data Protection - What the regulations say 13 of 19

14 The PIA should seek to address the risks of sharing the data and the risks of not sharing it. This would include weighing up the potential benefits that the data sharing might bring to society and individuals against the negative effects or likelihood of damage, distress or embarrassment to individuals and the potential harm to an organisation's reputation if the information is incorrectly shared or not shared at all. The types of issues that might be addressed as part of a PIA are: What information needs to be shared? Does all of the data that you hold about a person need to be shared with the third party in order to achieve the objective that the disclosure is designed to achieve? Who requires access to the shared personal data? Does the party with whom you are proposing to share the data need it or do they just want it? When should it be shared? How should it be shared? Consider the security framework relating to how the data is to be disclosed and then stored by the receiving party. What risk(s) does the data sharing pose? For example, is any individual likely to be damaged by it? Is any individual likely to object? Might it undermine individuals trust in the organisations that keep records about them? Could the objective be achieved without sharing the data or by anonymising it? Processing the data In accordance with the first data protection principle, one of a number of conditions needs to be satisfied in relation to processing the data. The relevant conditions are as follows: The data subject has given their consent to the processing of their data. Where personal data is shared by way of a legitimising condition other than that of consent, it is recommended good practice to keep a record of the basis upon which it is shared. Data Protection - What the regulations say 14 of 19

15 The processing is necessary in relation to a contract which the data subject has entered into or because the data subject has asked for something to be done so they can enter into a contract. The processing is necessary because of a legal obligation that applies to the party proposing to disclose the data (except an obligation imposed by a contract). The processing is necessary to protect the individual s vital interests (effectively cases of life or death). The processing is necessary for administering justice, or for exercising statutory, governmental, or other public functions. The processing is in accordance with the legitimate interests condition. The legitimate interests condition provides grounds to process personal data in a situation where an organisation needs to do so for the purpose of its own legitimate interests or the legitimate interests of the third party that the information is disclosed to. This condition cannot be satisfied if the processing prejudices the rights and freedoms or other legitimate interests of the data subject. Whilst it is feasible to rely on any of the above conditions, it is obviously preferable to obtain the consent of the data subject to the processing and sharing of their data (for more on this, please refer to the chapter regarding the collection of the data). Fair and Lawful processing of data in a sharing context Although these two elements of the first data protection principle are of general application, they perhaps come into sharper focus in a data sharing context. As such, it may be useful to consider both elements separately. Fairness The DPA does not define what is fair. However, in circumstances where the data is obtained directly from the data subject the DPA states that personal data is only fairly obtained if the data controller provides the data subject with certain fair processing information about how, why and by whom their personal data is to be processed (see the chapter regarding permissions ). Data Protection - What the regulations say 15 of 19

16 This information is usually given by the data controller by way of a privacy notice (see 3.2). In the context of data sharing, the privacy notice should contain (in addition to the matters identified above): Details of the data controller s identity; Information regarding how the data is to be used including why the data is to be shared in the way proposed and which organisations the data is to be shared with (in respect of this latter point, information could just be given regarding the type of organisation that the data controller may share the data with). More broadly, fairness in a data sharing context means that personal data should be shared in a way that is reasonable, that individuals would be likely to expect and would be unlikely to object to. In particular, and importantly, the data subject should not be deceived or misled about the purpose for which their data is to be processed. Lawfulness Processing data in a lawful way has two main strands to it: (i) Data must only be dealt with according to the law; (ii) Processing of the data must be premised on one of the legitimising conditions (see above). What if there is a change to the original circumstances in which the data was collected? In this context, data controllers should be aware that any new additional data sharing arrangements must comply with the second data protection principle (data must be obtained only for specified lawful purposes and not further processed in a manner which is incompatible with those purposes). In short therefore, the data must not be processed for a purpose other than that for which it was originally collected or one that is not incompatible with it. To establish whether a further processing operation is compatible with the original purpose, the data controller must carry out a compatibility assessment. The processing of personal data in a way that is incompatible with the purpose specified at collection is unlawful and therefore not permitted. Data Protection - What the regulations say 16 of 19

17 It is important to note here that a data controller cannot simply consider the further processing as a new processing activity and therefore rely on a different legitimising condition. For example, if the data controller originally relied on a consent as the lawful basis on which the data was to be processed, but the proposed secondary processing is for a purpose outside of the scope of the original consent, the data controller cannot then rely on the legitimate interests condition in order to legitimise the further processing. There are some exceptions to this, the most relevant one in our context being that the further processing of data for research purposes is permitted even if research was not the original purpose for which the data was obtained. Data Standards It is important to have governance procedures in place to ensure the quality of the data that you hold, especially if you are planning to share the data. It is worth recalling the third (data must be adequate, relevant and not excessive in relation to the purposes for which it is processed), fourth (data must be accurate and, where necessary, kept up to date) and fifth (data must not be kept for longer than is necessary) data protection principles in this context. For example, if one is sharing data then consideration should be given to what data is necessary to share (in order to comply with the third data protection principle). Data sharing agreements There is no formal legal requirement for the parties to a data sharing arrangement to enter into a written agreement. The Information Commissioner s Office Data Sharing Code says that drafting and adhering to a data sharing agreement will not in itself provide any safety from action under the DPA but the ICO will take it into account if it receives a complaint about an organisation's data sharing activities. 7.1 Overview of data uses As we have noted, the potential for organisations to use (and share) customers personal information for contact purposes is dependent Data Protection - What the regulations say 17 of 19

18 entirely on the notifications that were given to the customer and the permissions obtained from them. 7.2 The law relating to data uses The uses to which the data can be put will depend upon the condition which legitimises the processing of the data (for example, consent or the legitimate interests condition). Suffice is to say that whatever the condition relied on that legitimises the processing, the use to which the data is put must (subject to what is written below regarding exemptions) comply with that legitimising condition. There are, however, exemptions to certain of the DPA s obligations that may enable the data controller to deal with the data in a way that would, but for the exemption, be inconsistent with certain parts of the Act. For the purposes of this DPA guidance we will focus on the exemption relating to research. Research exemption There is no definition of research in the DPA, but it does include statistical analysis. The first point to note is that the research exemption only exempts the Data Controller from complying with the second and fifth data protection principles and Section 7 of the Data Protection Act. The remaining principles of the DPA apply to the data even if it is used for research purposes. As such, the data controller must still have a legitimising condition in relation to processing the data in order to render the processing lawful, as required by the first data protection principle. Researchers often rely on the legitimate interests condition when seeking to satisfy the first data protection principle regarding research or statistical analysis so that further consent from the data subject is not required in order to conduct the research. There is no blanket rule that this approach is satisfactory; a case-by-case analysis must be undertaken. More stringent conditions continue to apply if the data is sensitive personal data. Data Protection - What the regulations say 18 of 19

19 With regards the application of the research exemption, the second data protection principle states that data must be obtained only for specified lawful purposes and not further processed in a manner which is incompatible with those purposes. However, further processing which is only for research purposes and which has not been expressly authorised by the data subject is not incompatible with the second data protection principle so long as the following two conditions are met: The data is not processed to support measures or decisions with respect to particular individuals The data is not processed in such a way that substantial damage or substantial distress is, or is likely to be, caused to any data subject. Additionally, if the data is used for research purposes then: It can be kept indefinitely in connection with the research purpose (whereas the fifth data protection principle usually requires data to be kept by the data controller for no longer than is necessary); and The data is exempt from the data subject s right to access their own data so long as the conditions referred to above are met and the results of the research or any resulting statistics are not made available in a form which identifies the data subject(s). Data Protection - What the regulations say 19 of 19

Subject: Kier Group plc Data Protection Policy

Subject: Kier Group plc Data Protection Policy Kier Group plc Data Protection Policy Subject: Kier Group plc Data Protection Policy Author: Compliance Document type: Policy Authorised by: Kier General Counsel & Company Secretary Version 3 Effective

More information

DATA PROTECTION POLICY THE HOLST GROUP

DATA PROTECTION POLICY THE HOLST GROUP DATA PROTECTION POLICY THE HOLST GROUP INTRODUCTION The purpose of this document is to provide a concise policy regarding the data protection obligations of The Holst Group. The Holst Group is a data controller

More information

Introductory guide to data sharing. lewissilkin.com

Introductory guide to data sharing. lewissilkin.com Introductory guide to data sharing lewissilkin.com Executive Summary Most organisations carry out some form of data sharing, whether it be data sharing between organisations within the group or with external

More information

UWC International Data Protection Policy

UWC International Data Protection Policy UWC International Data Protection Policy 1. Introduction This policy sets out UWC International s organisational approach to data protection. UWC International is committed to protecting the privacy of

More information

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY 1. Statement of Policy (Guardian) needs to collect and use certain types of information about the Individuals or Service Users with whom they come into contact in order to carry on our work. This personal

More information

DATA PROTECTION IN RESEARCH

DATA PROTECTION IN RESEARCH DATA PROTECTION IN RESEARCH Document control Applicable to: All employees and research students Date first approved February 2006 Date first amended May 2015 Date last amended May 2015 Approved by Approval

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Introduction The purpose of this document is to provide a concise policy regarding the data protection obligations of Youth Work Ireland. Youth Work Ireland is a data controller

More information

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION Document Control Owner: Distribution List: Data Protection Officer Relevant individuals who access, use, store or

More information

UWTSD Group Data Protection Policy

UWTSD Group Data Protection Policy UWTSD Group Data Protection Policy Contents Clause Page 1. Policy statement... 1 2. About this policy... 1 3. Definition of data protection terms... 1 4. Data protection principles..3 5. Fair and lawful

More information

Islam21c.com Data Protection and Privacy Policy

Islam21c.com Data Protection and Privacy Policy Islam21c.com Data Protection and Privacy Policy Purpose of this policy The purpose of this policy is to communicate to staff, volunteers, donors, non-donors, supporters and clients of Islam21c the approach

More information

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2 COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September 2018 Table of Contents 1. Scope, Purpose and Application to Employees 2 2. Reference Documents 2 3. Definitions 3 4. Data Protection Principles

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

The British Museum. Data Protection Code of Practise. 1 Introduction

The British Museum. Data Protection Code of Practise. 1 Introduction The Data Protection Code of Practice 1 Introduction 1.1 The 1998 Data Protection Act is aimed at ensuring a balance between individuals rights to privacy and the lawful processing of personal data undertaken

More information

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Introduction Stewart Watt & Co. is law firm and provides legal advice and assistance to its clients. It is regulated by the Law Society of Scotland. The personal data that Stewart

More information

Rights of Individuals under the General Data Protection Regulation

Rights of Individuals under the General Data Protection Regulation Rights of Individuals under the General Data Protection Regulation 2018 Contents Introduction... 2 Glossary... 3 Personal data... 3 Processing... 3 Data Protection Commission... 3 Data Controller... 3

More information

UUEAS Privacy policy - Members

UUEAS Privacy policy - Members UUEAS Privacy policy - Members The Union of UEA Students (The Union) is an independent charity, whose primary goal is to represent the students at the University of East Anglia. Every student at UEA is

More information

HOW WE USE YOUR INFORMATION

HOW WE USE YOUR INFORMATION HOW WE USE YOUR INFORMATION Herold Mediatel Ltd compiles the Gibraltar Telephone Directory on behalf of Gibtelecom. Every care is taken to render this Directory as accurate as possible but neither Herold

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Data Protection Policy Version 3.00 May 2018 For more information, please contact: Technical Team T: 01903 228100 / 01903 550242 E: info@24x.com Page 1 The Data Protection Law...

More information

Privacy and Data Protection Policy

Privacy and Data Protection Policy Privacy and Data Protection Policy Introduction 1. The Ripple Pond is committed to ensuring the secure and safe management of personal data held by the Charity in relation to Beneficiaries, Staff, Trustees,

More information

ADMA Briefing Summary March

ADMA Briefing Summary March ADMA Briefing Summary March 2013 www.adma.com.au Privacy issues are being reviewed globally. In most cases, technological changes are driving the demand for reforms and Australia is no exception. From

More information

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ). PRIVACY POLICY Data Protection Policy 1. Introduction This Data Protection Policy (this Policy ) sets out how Brital Foods Limited ( we, us, our ) handle the Personal Data we Process in the course of our

More information

A Homeopath Registered Homeopath

A Homeopath Registered Homeopath A Homeopath Registered Homeopath DATA PROTECTION POLICY Scope of the policy This policy applies to the work of homeopath A Homeopath (hereafter referred to as AH ). The policy sets out the requirements

More information

Brasenose College ICT Systems Privacy Notice (v1.2)

Brasenose College ICT Systems Privacy Notice (v1.2) Brasenose College ICT Systems Privacy Notice (v1.2) A summary of what this notice explains Brasenose College is committed to protecting the privacy and security of personal data. This notice applies to

More information

Creative Funding Solutions Limited Data Protection Policy

Creative Funding Solutions Limited Data Protection Policy Creative Funding Solutions Limited Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

General Data Protection Regulation (GDPR) Key Facts & FAQ s

General Data Protection Regulation (GDPR) Key Facts & FAQ s General Data Protection Regulation (GDPR) Key Facts & FAQ s GDPR comes into force on 25 May 2018 GDPR replaces the Data Protection Act 1998. The main principles are much the same as those in the current

More information

Element Finance Solutions Ltd Data Protection Policy

Element Finance Solutions Ltd Data Protection Policy Element Finance Solutions Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

Requirements for a Managed System

Requirements for a Managed System GDPR Essentials Requirements for a Managed System QG Publication 6 th July 17 Document No. QG 0201/4.3 Requirements for a Managed GDPR System The General Data Protection Regulation GDPR will apply in the

More information

Technical Requirements of the GDPR

Technical Requirements of the GDPR Technical Requirements of the GDPR Purpose The purpose of this white paper is to list in detail all the technological requirements mandated by the new General Data Protection Regulation (GDPR) laws with

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY 1 Your Data Protection Responsibilities DATA PROTECTION POLICY 1.1 Everyone has rights with regard to how their personal data is handled. Personal data is any information that a person can be identified

More information

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy DEPARTMENT OF JUSTICE AND EQUALITY Data Protection Policy May 2018 Contents Page 1. Introduction 3 2. Scope 3 3. Data Protection Principles 4 4. GDPR - Rights of data subjects 6 5. Responsibilities of

More information

Little Blue Studio. Data Protection and Security Policy. Updated May 2018

Little Blue Studio. Data Protection and Security Policy. Updated May 2018 Little Blue Studio Data Protection and Security Policy Updated May 2018 Contents Introduction... 3 Purpose... 3 Application... 3 General Data Protection Regulation (GDPR)... 3 Handling personal information,

More information

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov Contributed by Djingov, Gouginski, Kyutchukov & Velichkov General I Data Protection Laws National Legislation General data protection laws The Personal Data Protection Act implemented the Data Protection

More information

Made In Hackney Data Protection Policy Last Updated:

Made In Hackney Data Protection Policy Last Updated: Made In Hackney Data Protection Policy Last Updated: 16.05.2018 Definitions Charity GDPR Responsible Person Register of Systems Made In Hackney (MIH), a registered charity. means the General Data Protection

More information

Data Protection Policy

Data Protection Policy The Worshipful Company of Framework Knitters Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act 1998 (DPA) [UK] For information on this

More information

Frequently Asked Questions

Frequently Asked Questions Frequently Asked Questions After having undertaken a period of research within recreational cricket, this document is aimed at addressing the frequently asked questions from cricket Clubs, Leagues, Boards

More information

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts POLICY STATEMENT Adkin is committed to protecting and respecting the privacy of all of our clients. This Policy

More information

Motorola Mobility Binding Corporate Rules (BCRs)

Motorola Mobility Binding Corporate Rules (BCRs) Motorola Mobility Binding Corporate Rules (BCRs) Introduction These Binding Privacy Rules ( Rules ) explain how the Motorola Mobility group ( Motorola Mobility ) respects the privacy rights of its customers,

More information

INNOVENT LEASING LIMITED. Privacy Notice

INNOVENT LEASING LIMITED. Privacy Notice INNOVENT LEASING LIMITED Privacy Notice Table of Contents Topic Page number KEY SUMMARY 2 ABOUT US AND THIS NOTICE 3 USEFUL WORDS AND PHRASES 4 WHAT INFORMATION DO WE COLLECT? 4 WHY DO WE PROCESS YOUR

More information

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy knows that your privacy is important to you. Below is our privacy policy for collecting, using, securing, protecting and sharing your

More information

PRIVACY STATEMENT. The Island with Bear Grylls (the Programme ) Introduction and main purposes

PRIVACY STATEMENT. The Island with Bear Grylls (the Programme ) Introduction and main purposes PRIVACY STATEMENT The Island with Bear Grylls (the Programme ) Introduction and main purposes Shine TV Limited ("Company" or "we, us, our") is the data controller in respect of your personal data and will

More information

PRIVACY POLICY. 3.1 This policy does not apply to the collection, holding, use or disclosure of personal information that is an employee record.

PRIVACY POLICY. 3.1 This policy does not apply to the collection, holding, use or disclosure of personal information that is an employee record. 1. Introduction 1.1 From time to time Business & Risk Solutions Pty Ltd ("the Company") is required to collect, hold, use and/or disclose personal information relating to individuals (including, but not

More information

NWQ Capital Management Pty Ltd. Privacy Policy. March 2017 v2

NWQ Capital Management Pty Ltd. Privacy Policy. March 2017 v2 NWQ Capital Management Pty Ltd Privacy Policy March 2017 Page 1 of 8 Privacy and Spam Policy NWQ Capital Management Pty Ltd s Commitment NWQ Capital Management Pty Ltd (NWQ) is committed to providing you

More information

1 Privacy Statement INDEX

1 Privacy Statement INDEX INDEX 1 Privacy Statement Mphasis is committed to protecting the personal information of its customers, employees, suppliers, contractors and business associates. Personal information includes data related

More information

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal What is GDPR? GDPR (General Data Protection Regulation) is Europe s new privacy law. Adopted in April 2016, it replaces the 1995 Data Protection Directive and marks the biggest change in data protection

More information

Privacy notice. Last updated: 25 May 2018

Privacy notice. Last updated: 25 May 2018 Privacy notice Last updated: 25 May 2018 www.courtprice.co.uk ('Website') is provided by Courtprice Limited ('we'/'us'/'our'). In doing so, we may be in a position to receive and process personal information

More information

This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant.

This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant. GDPR and BMC Clubs Lawful basis for Processing Personal Data This article will explain how your club can lawfully process personal data and show steps you can take to ensure that your club is GDPR compliant.

More information

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR).

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR). MBNL Landlord Privacy Notice This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR). SUMMARY This Privacy Notice applies to: users of our website

More information

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017 Data Protection should be part of every company s or organisation s DNA Do you process

More information

Cayman Islands Data Protection Law Guide Book

Cayman Islands Data Protection Law Guide Book Cayman Islands Data Protection Law Guide Book 2017 Guide Book Cayman Islands Data Protection Law, 2017 1. Background and Overview On 27 March 2017 the Data Protection Law, 2017 (Law) was passed by the

More information

Data protection. Data protection. Kacper Szkalej 1. Structure. Data protection. Media Law, KTH. Definition? Data protection = data processing rules

Data protection. Data protection. Kacper Szkalej 1. Structure. Data protection. Media Law, KTH. Definition? Data protection = data processing rules Data protection Media Law, KTH Kacper Szkalej, LL.M. kacper.szkalej@jur.uu.se Structure Background Legal framework EU National Administrative framework Data Protection Authorities The Internet and social

More information

WIT Diverse Campus Services Ltd. Data Protection Policy

WIT Diverse Campus Services Ltd. Data Protection Policy WIT Diverse Campus Services Ltd. Data Protection Policy Introduction WIT Diverse Campus Services Limited and/or its associated companies ( us or we ) have created this privacy statement to demonstrate

More information

TINOPOLIS PRIVACY NOTICE

TINOPOLIS PRIVACY NOTICE TINOPOLIS PRIVACY NOTICE 1. About us Tinopolis Group is an international media producer and distributor with a significant presence in the global media marketplace as further described on our website at

More information

Data Protection Policy

Data Protection Policy Introduction In order to; provide education, training, assessment and qualifications to its customers and clients, promote its services, maintain its own accounts and records and support and manage its

More information

Cardiff University Security & Portering Services (SECTY) CCTV Code of Practice

Cardiff University Security & Portering Services (SECTY) CCTV Code of Practice Cardiff University Security & Portering Services (SECTY) CCTV Code of Practice Document history Author(s) Date S Gamlin 23/05/2018 Revision / Number Date Amendment Name Approved by BI annual revision Date

More information

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ):

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ): Privacy Policy Introduction Ikano S.A. ( Ikano ) respects your privacy and is committed to protect your Personal Data by being compliant with this privacy policy ( Policy ). In addition to Ikano, this

More information

Privacy Notice. General Information Protection Regulation ( GDPR )

Privacy Notice. General Information Protection Regulation ( GDPR ) Privacy Notice General Information Protection Regulation ( GDPR ) Please read the following information carefully. This privacy notice contains information about the information collected, stored and otherwise

More information

Xpress Super may collect and hold the following personal information about you: contact details including addresses and phone numbers;

Xpress Super may collect and hold the following personal information about you: contact details including addresses and phone numbers; 65 Gilbert Street, Adelaide SA 5000 Tel: 1300 216 890 Fax: 08 8221 6552 Australian Financial Services Licence: 430962 Privacy Policy This Privacy Policy was last updated on 27 February 2017. Our Commitment

More information

Commercial Vehicle Mobile ANPR Policy

Commercial Vehicle Mobile ANPR Policy Commercial Vehicle Mobile ANPR Policy Road Safety Authority May 2015 Mobile ANPR System Data Protection Policy This document sets out the policy of the Road Safety Authority (the Authority ) regarding

More information

Privacy Policy GENERAL

Privacy Policy GENERAL Privacy Policy GENERAL This document sets out what information Springhill Care Group Ltd collects from visitors, how it uses the information, how it protects the information and your rights. Springhill

More information

THE DATA PROTECTION ACT (1998) AND YOUR CLUB/COUNTY ASSOCIATION

THE DATA PROTECTION ACT (1998) AND YOUR CLUB/COUNTY ASSOCIATION THE DATA PROTECTION ACT (1998) AND YOUR CLUB/COUNTY ASSOCIATION October 2010 (Revised October 2014) Guidance THE DATA PROTECTION ACT 1998 ( THE ACT ) AND YOUR CLUB/COUNTY ASSOCIATION WHY IS THE ACT IMPORTANT?

More information

Privacy Notice - General Data Protection Regulation ( GDPR )

Privacy Notice - General Data Protection Regulation ( GDPR ) THIS PRIVACY NOTICE APPLIES TO ANY PERSON WHO INSTRUCTS AN INDIVIDUAL BARRISTER AT 12 OLD SQUARE CHAMBERS EITHER DIRECTLY OR THROUGH A SOLICITOR OR WHO ASKS THE INDIVIDUAL BARRISTER FOR A REFERENCE Privacy

More information

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. I. OBJECTIVE ebay s goal is to apply uniform, adequate and global data protection

More information

The Data Protection Act 1998 and the Use of Personal Data for IT Administration

The Data Protection Act 1998 and the Use of Personal Data for IT Administration Introduction The Data Protection Act 1998 and the Use of Personal Data for IT Administration 1. This document has been drawn up to provide guidance to University IT staff who need to use real data about

More information

DATA SECURITY - DATA PROTECTION ACT

DATA SECURITY - DATA PROTECTION ACT DATA SECURITY - DATA PROTECTION ACT Data Security - Data Protection Act Many businesses are totally reliant on the data stored on their PCs, laptops, networks, mobile devices and in the cloud. Some of

More information

Data Protection. Code of Conduct for Cloud Infrastructure Service Providers

Data Protection. Code of Conduct for Cloud Infrastructure Service Providers Data Protection Code of Conduct for Cloud Infrastructure Service Providers 27 JANUARY 2017 Introduction... 3 1 Structure of the Code... 5 2 Purpose... 6 3 Scope... 7 4 Data Protection Requirements... 9

More information

Badminton England - Data protection Guidance for clubs and counties.

Badminton England - Data protection Guidance for clubs and counties. Badminton England - Data protection Guidance for clubs and counties. This leaflet is intended to provide general guidance for clubs and counties with respect to data protection. It does not however capture

More information

Site Builder Privacy and Data Protection Policy

Site Builder Privacy and Data Protection Policy Site Builder Privacy and Data Protection Policy This policy applies to the work of the Third Age Trust s Site Builder Team. The policy sets out the approach of the Team in managing personal information

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Introduction WIT Diverse Campus Services Limited (herein after referred to as DCS) and/or its associated companies ( us or we ) have created this privacy statement to demonstrate

More information

the processing of personal data relating to him or her.

the processing of personal data relating to him or her. Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the Hotel & Pensionat Björkelund. The use of

More information

Privacy Policy Statement Last update 25 th May 2018.

Privacy Policy Statement Last update 25 th May 2018. Privacy Policy Statement Last update 25 th May 2018. Introduction We want our customers to receive a prompt, efficient and courteous service that is delivered in a positive and transparent manner. The

More information

BELLISSIMA BEAUTY SALON PRIVACY NOTICE

BELLISSIMA BEAUTY SALON PRIVACY NOTICE BELLISSIMA BEAUTY SALON PRIVACY NOTICE Bellissima Beauty Salon( Bellissima, we or us ) are committed to protecting your privacy, including online, and in the transparent use of any information you give

More information

Privacy Policy Inhouse Manager Ltd

Privacy Policy Inhouse Manager Ltd Privacy Policy Inhouse Manager Ltd April 2018 This privacy statement is designed to tell you about our practices regarding the collection, use and disclosure of information held by Inhouse Manager Ltd.

More information

SCHOOL SUPPLIERS. What schools should be asking!

SCHOOL SUPPLIERS. What schools should be asking! SCHOOL SUPPLIERS What schools should be asking! Page:1 School supplier compliance The General Data Protection Regulation (GDPR) comes into force on 25 May 2018 and will be applied into UK law via the updated

More information

General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of

General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General

More information

- GDPR (General Data Protection Regulation) is the new Data Protection Regulation of the European Union;

- GDPR (General Data Protection Regulation) is the new Data Protection Regulation of the European Union; PRIVACY NOTICE INTRODUCTION During the operation of the website data controller processes the data of persons registered on the website in order to be able to provide them with adequate services. Service

More information

M T BUCKLEY & Co Chartered Accountants

M T BUCKLEY & Co Chartered Accountants M T BUCKLEY & Co Chartered Accountants 2 Beulah Walk, Woldingham, Caterham, Surrey CR3 7LL Telephone: 01883 650420 Mobile: 07876 030622 1. PURPOSE OF THIS POLICY PRIVACY POLICY This policy describes how

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Introduction 1 In undertaking the business of the University of Stirling, we all create, gather, store and process large amounts of data on a variety of data subjects such as on

More information

The Data Protection Act 1998 Clare Hall Data Protection Policy

The Data Protection Act 1998 Clare Hall Data Protection Policy The Data Protection Act 1998 Clare Hall Data Protection Policy Introduction This document is a guide to the main requirements of the new Data Protection Act (DPA) that came into force on 24th October 2001.

More information

RVC DATA PROTECTION POLICY

RVC DATA PROTECTION POLICY RVC DATA PROTECTION POLICY POLICY and PROCEDURES Responsibility of Data Protection Officer Review Date July 2019 Approved by CEC Author D.Hardyman-Rice CONTENTS PAGE 1) Policy Statement 3 2) Key definitions

More information

Jefferies EMEA Privacy Notice

Jefferies EMEA Privacy Notice Jefferies International Limited Vintners Place 68 Upper Thames St London United Kingdom Jefferies EMEA Privacy Notice 1. Introduction This Privacy Notice explains what we do with your personal data. It

More information

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to Suzanne Dibble 2018. Copyright in this document belongs to Suzanne Dibble. You may not copy or use it for any purpose unless you have purchased this template document from Suzanne Dibble. You may not allow

More information

What personal data or information do we collect? The personal information we collect may include:

What personal data or information do we collect? The personal information we collect may include: Privacy and Cookies At Knowledge Skills & Attitude Limited, we take your privacy seriously and this privacy statement explains what personal data or information we collect from you and from people who

More information

Data Breach Notification: what EU law means for your information security strategy

Data Breach Notification: what EU law means for your information security strategy Data Breach Notification: what EU law means for your information security strategy Olivier Proust December 8, 2011 Hunton & Williams LLP Key points 1. Introduction 2. Overview of data breach requirements

More information

Cognizant Careers Portal Privacy Policy ( Policy )

Cognizant Careers Portal Privacy Policy ( Policy ) Cognizant Careers Portal Privacy Policy ( Policy ) Date: 22 March 2017 Introduction This Careers Portal Privacy Policy ("Policy") applies to the Careers portal on the Cognizant website accessed via www.cognizant.com/careers

More information

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH PRIVACY NOTICE Curv360 is a part of the Project Better Energy Limited group of companies and is a controller of any personal data you provide. We respect your data and your privacy is important to us.

More information

Polemic is a business involved in the collection of personal data in the course of its business activities and on behalf of its clients.

Polemic is a business involved in the collection of personal data in the course of its business activities and on behalf of its clients. Privacy policy 1 Background This document sets out the policy of Polemic Forensic ABN 60 392 752 759 ( Polemic ) relating to the protection of the privacy of personal information. Polemic is a business

More information

Contract Services Europe

Contract Services Europe Contract Services Europe Procedure for Handling of Page 1 of 10 1. INTRODUCTION This procedure document supplements the data request and subject access request (SAR) provisions set out in DPS Contract

More information

DATA PROTECTION ISACA MALTA CHAPTER BIENNIAL CONFERENCE Saviour Cachia Commissioner for Information and Data Protection

DATA PROTECTION ISACA MALTA CHAPTER BIENNIAL CONFERENCE Saviour Cachia Commissioner for Information and Data Protection DATA PROTECTION ISACA MALTA CHAPTER BIENNIAL CONFERENCE 2016 Saviour Cachia Commissioner for Information and Data Protection Conception of DPA Council of Europe ETS 108 Convention on the protection of

More information

TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE

TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE TERMS & CONDITIONS PLEASE READ THESE TERMS AND CONDITIONS CAREFULLY BEFORE USING THE SITE 1. General The term PPS refers to: Professional Provident Society Holdings Trust, (The Holding Trust); Professional

More information

Our Data Protection Officer is Andrew Garrett, Operations Manager

Our Data Protection Officer is Andrew Garrett, Operations Manager Construction Youth Trust Privacy Notice We are committed to protecting your personal information Construction Youth Trust is committed to respecting and keeping safe any personal information you share

More information

This Privacy Policy applies if you're a customer, employee or use any of our services, visit our website, , call or write to us.

This Privacy Policy applies if you're a customer, employee or use any of our services, visit our website,  , call or write to us. Privacy Policy Background This policy explains when and why we collect personal information about you; how we use it, the conditions under which we may disclose it to others and how we keep it secure.

More information

Office of John Howell MP Data Protection Policy

Office of John Howell MP Data Protection Policy Office of John Howell MP Data Protection Policy This document outlines how the Office of John Howell MP processes and manages personal data. The Office of John Howell includes John Howell MP and staff

More information

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms:

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms: Last updated: 20/04/2018 Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of VITO (Vlakwa). The

More information

PRIVACY POLICY. 1. Introduction

PRIVACY POLICY. 1. Introduction PRIVACY POLICY 1. Introduction 1.1. The Pinewood Studios Group is committed to protecting and respecting your privacy. This privacy policy (together with our Website Terms of Use and Cookies Policy) (Privacy

More information

The West End Community Trust Privacy Policy

The West End Community Trust Privacy Policy The West End Community Trust Privacy Policy We are committed to protecting your personal information and being transparent about what we do with it, however you interact with us. We are therefore committed

More information

In this Policy the following terms shall have the following meanings:

In this Policy the following terms shall have the following meanings: NJR TRADING LTD understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone who visits this website, https://bar-tonic.

More information

Strasbourg, 21 December / décembre 2017

Strasbourg, 21 December / décembre 2017 Strasbourg, 21 December / décembre 2017 T-PD(2017)20Rev CONSULTATIVE COMMITTEE OF THE CONVENTION FOR THE PROTECTION OF INDIVIDUALS WITH REGARD TO AUTOMATIC PROCESSING OF PERSONAL DATA COMITÉ CONSULTATIF

More information

Data protection policy

Data protection policy Data protection policy Context and overview Introduction The ASHA Centre needs to gather and use certain information about individuals. These can include customers, suppliers, business contacts, employees

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement ( DPA ) is entered into between: A. The company stated in the Subscription Agreement (as defined below) ( Data Controller ) and B. Umbraco A/S Haubergsvej

More information