Data Protection: Germany

Size: px
Start display at page:

Download "Data Protection: Germany"

Transcription

1 Page 1 of 18 Data Protection: Germany Resource type: Article: know-how Status: Law stated as at 01-Mar-2009 Jurisdiction: Germany A Q&A guide to data protection in Germany. Stephan Rippert and Katharina A Weimer, Reed Smith LLP Regulation 1. What national law(s) apply to the collection and use of personal data? If applicable, has Directive 95/46/EC on data protection (Data Protection Directive) been implemented? Directive 95/46/EC on data protection (Data Protection Directive) was implemented in Germany throu gh the Federal Data Protection Act (Bundesdatenschutzgesetz (DPA)). The DPA is the primary legislation regulating the collection and use of personal data. At state level, each state has enacted data protection regulations covering the collection and use of personal data by public bodies of the states. Collection and use of personal data in specific areas is regulated by area-specific secondary legislation. These areas include: Telemedia Act (Telemediengesetz (TMG)). Telecommunications Act (Telekommunikationsgesetz (TKG)). German Social Code (Sozialgesetzbuch (SGB)). Interstate Broadcast Treaty (Rundfunkstaatsvertrag (RStV)). The objective of the DPA is to give individuals rights over their personal information and to require anyone who handles personal data to comply with the regulations of the DPA. The DPA differentiates between the collecting and use of personal data by public authorities and by private persons. In case a public entity acts as data controller, the handling of personal data is mainly regulated by state legislation with the DPA serving as a default regulation. 2. To whom do the rules apply (EU: data controller)? A "data controller" is defined as any person or body that collects, processes or uses personal data on its own behalf, or instructing others to do so on its behalf (section 3(7), DPA). Data controllers can be public bodies, and private legal or natural persons. Data controllers do not need to hold or process data themselves. They may instruct a third party with the processing of personal data (see Question 15). 3. What data is regulated (EU: personal data)?

2 Page 2 of 18 The data protection regulations apply to personal data, which is defined as any information concerning the personal or factual circumstances of an identified or identifiable individual (section 3(1), DPA). Therefore, any information which is linkable to an individual is considered personal data. Information can be linked to an individual if the connection to the individual can be made through the data itself or with the help of other information which is or is likely to be available to the data controller. Data which may be unidentifiable for a data controller (for example, because of anonymisation) and therefore not protected under the DPA may well be linkable to an individual for another data controller if the other data controller has the key for allocating the data to the individual. Personal data includes: Name, birthday and family relationships. Contact details such as street address, address and telephone number. Insurance number, bank details, religious affiliation and medical data. The DPA provides special protection for sensitive personal data which are more susceptible to abuse. This includes data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and the processing of data concerning health or sex life (section 3(9), DPA). 4. What acts are regulated (EU: processing)? The DPA regulates all stages of handling of personal data, from collection to deletion of data, under which (section 3, DPA): "Collection" means the acquisition of data on the data subject. "Processing" means the storage, modification, transfer, blocking and erasure of personal data. "Use" means any utilisation of personal data other than processing. For private-entity data controllers, the DPA only applies in case of automatic data processing (section 3(2), DPA) or in cases where the data processing is not automatic but data is processed in or from a file system or collected for it. "Automatic data processing" means the collection, processing or use of personal data using automatic data processing means. In contrast, a non-automatic file system means any structured set of personal data which is accessible according to specific criteria, whether centralised, decentralised, or dispersed on a functional or geographical basis. 5. What is the jurisdictional scope of the rules?

3 Page 3 of 18 The jurisdictional scope of the DPA is regulated in section 1(5) of the DPA. The DPA is applicable to data controllers in Germany who process data in Germany. A data controller outside Germany, but within the EU or the European Economic Area (EEA), who processes or uses personal data in Germany is not subject to the DPA. If such data is collected through a German branch, the DPA is applicable. Data controllers outside the EU or the EEA who collect, process or use personal data in Germany are subject to the DPA, regardless of whether they employ any technical equipment in Germany for such handling of personal data. This does not apply if data carriers are used only for transit purposes through Germany. 6. What are the main exemptions (if any)? The data protection provisions do not apply if personal data is collected, processed or used for solely personal or familial purposes (section 1(2), DPA), or if the data subject itself has publicised that data. Also the regulations do not apply to the extent personal data are collected, processed or used by other means than data processing systems and nonautomatic file systems (see Question 4). Personal data can be obtained without the initial consent of the individual if data is used for the: Safeguarding of rightful interests of a third party. Prevention of risks for the national or public security. Prosecution of crimes. Purposes of marketing in case the data is summarised in a list and there are no reasons to suspect that the data subject has an overriding interest in the exclusion of the transfer of use. 7. Is notification or registration required before processing data? If so, please provide brief details. Although the DPA generally requires notification of the data protection authority before beginning automatic data processing (section 4d, DPA), this rule does not apply if the data controller: Has appointed a data protection officer. Handles personal data for its own purposes, provided that not more than nine employees are occupied with handling personal data and either: the data subject's consent has been obtained;

4 Page 4 of 18 the collecting, processing or use of personal data serves the purposes of a contract or of a quasi-contractual fiduciary relationship with the data subject. The exceptions do not apply where data is collected through automatic processing for the purpose of transfer or anonymised transfer on a professional basis. If notification is required, it must include (section 4e, DPA): Name and business name of the data controller. Owners, board members, managing directors, or other managers appointed by law or the company's by-laws, and the persons placed in charge of data processing. Address of the data controller. Purposes of collecting, processing or use of personal data. A description of the groups of data subjects and the appurtenant data or categories of data. Recipients or categories of recipients, to whom the data may be transferred. Standard periods for the erasure of data. Any planned data transfer to third countries. A general description enabling the data protection authority to preliminarily assess whether the measures taken pursuant to section 9 of the DPA are adequate to ensure the safety of the processing. The data controller must also notify the data protection authority on any changes to the above information (section 4e sentence 2, DPA). If the automatic processing entails specific risks for the rights and freedoms of the data subject, it is subject to review before commencement. Such risks are deemed to exist in particular in cases where sensitive personal data are processed, and in cases where the processing of personal data is intended to help evaluate the personality of the data subject, including performance, capabilities or behaviour. The review must be carried out by the data protection officer of the data controller. Main data protection rules and principles 8. What are the main obligations imposed on data controllers to ensure that data is processed properly?

5 Page 5 of 18 Any data collection, processing and use of personal data requires the consent of the individual or a statutory permission legitimising each individual act for the specific purpose for which it is carried out. Further, any data processing is subject to the following principles: Data avoidance and data minimisation (section 3a, DPA). The design and use of data processing systems must aim to collect, process and use as little personal data as possible, and only to the extent the specific data is required. If possible, pseudonymisation and anonymisation must be used. Principle of purpose limitation. Personal data may not be collected without first determining the specific purpose for the collection. It may only be used for the specific purpose for which it was originally collected. Any other processing is prohibited. Data secrecy. Data controllers are required to keep personal data confidential both externally and internally. "Externally" means that data controllers cannot disclose or transmit the data to other parties, even if they are companies of the same group. Internally means that only those employees are granted access to the data who require it; such access must be limited to the scope of the specific purpose. Transparency. Data processing must be as transparent as possible concerning the concerned data subject. This requires that: the data controller must inform the individual on the collection, processing, and use, its purpose, the identity of the data controller, and any contemplated transfers of data and the appurtenant recipients; consent by the data subject must be given freely and be based on sufficient information (see Question 9); the data subject has the right to access and rectify its personal data. 9. Is the consent of data subjects required before processing personal data? If so: What rules are there regarding the form and content of consent? Would online consent suffice? Are there any special rules regarding the giving of consent by minors? Collection, processing and use of personal data require the consent of the data subject unless it can be based on a statutory permission. Consent must be given on an informed and voluntary basis. The individual can, at any time, withdraw its consent with or without reason. Form and Content of Consent

6 Page 6 of 18 Consent must be given in writing unless exceptions apply (section 4a(1) sentence 3, DPA). Exceptions include telephone surveys or data processing for scientific research if the purpose of the research would be materially impaired by requiring written consent. Written consent also includes consent in electronic form with an electronic signature (section 126a, Civil Code). If consent forms part of other written documents, that is, in general terms and conditions or employment agreements, the consent must be made visually distinguishable in its appearance (section 4a(1), sentence 4, DPA). Consent is subject to the following requirements: It must be based on the free decision of the individual. This can be problematic in relationships of dependency between the data subject and the data controller, such as employment relationships. The requirement of voluntary consent includes the prohibition of linking the provision of services to the collection of data which is not needed for the specific purpose. The data subject must be informed of the purpose of the intended data collection, processing and use. In specific circumstances or on request, the data subject must be informed of the consequences of withholding the consent, if any (section 4a(1), sentence 2, DPA). The individual must be informed concerning the data collected and processed and, if passing on those data, the respective conditions. If personal data is transmitted to recipients outside the EU, the data subjects must be informed of the processing requirements applicable in that receiving country and on the associated risks. If sensitive data is collected, processed or used, the consent has to specifically refer to these data (section 4a(3), DPA). Online consent For dealings on the internet, collection, processing and use of personal data is also regulated by the TMG and the TKG. Consent can be obtained electronically, subject to the above content requirements, if the data controller ensures that: The data subject has declared its consent knowingly and unequivocally, Consent is recorded. The data subject can access the content of its consent at any time. The data subject can revoke its consent for the future at any time. It is disputed whether electronic consent requires an electronic signature in accordance with

7 Page 7 of 18 the definition of "electronic form" (section 126a, Civil Code). For practicability reasons, it is common practice to provide for consent by indicating a respective icon on the computer screen. Consent by minors The DPA does not specifically address consent by minors. Consent can be given by minors if they have the required capacity to understand the consequences of consent. Such capacity cannot be affixed to a certain age but must be determined individually, with a view to the processing for which the consent is required. In several instances (for example, certain areas of education, employment or medical treatment), minors can be capable of making their own decisions. Consent given by a minor in these areas is therefore likely to be valid. However, data controllers should be cautious when obtaining consent from minors. 10. If there is no consent, on what other grounds (if any) can processing be justified? In the absence of consent, processing of personal data can be justified by statutory provisions. The collection, storage, modification and transfer of personal data or their use for business purposes is admissible if: It serves the purpose of a contract or a quasi-contractual fiduciary relationship with the data subject, (section 28(1) no.1, DPA). It is necessary to safeguard legitimate interests of the data controller and there is no reason to assume that the data subject's interest meriting protection in the exclusion of the processing or use outweighs the data controller s legitimate interest (section 28(1) no. 2, DPA). The data is publicly accessible or the data controller would be entitled to publish it, unless the data subject's legitimate interest in the exclusion of the processing or use outweights the legitimate interests of the data controller (section 28 (1) no.,3 DPA). Transmission or use for other than the originally contemplated purposes is permissible (section 28 (3) no. 3, DPA) if: It is required to safeguard the legitimate interests of a third party. It is required for the prevention of risks for the national security or public safety, or for the prosecution of crimes. It is required for purposes of advertisement, marketing and polling if the data refers to members of a certain group of persons and is summarised in lists or other forms and there is no reason to assume that the individual has an overriding interest in the exclusion of the transmission or use.

8 Page 8 of 18 It is required in the interest of a research organisation for the conduct of scientific research, and the interest in the conduct of this research materially outweighs the data subject's interests, and the purpose of the research cannot be reached by other means, or only with unreasonable effort. Section 29 of the DPA gives statutory permission for trade businesses dealing with data collection and storage for the purpose of transmission. Such use of data is permissible if this serves advertisement, credit agency business, address dealing or marketing and polling surveys, provided that: There is no reason to assume that the data subject has an overriding interest. The data can be collected from publicly available sources or the data controller would be permitted to publish it, unless the data subject's interest meriting protection in the exclusion of the collection, storage or modification obviously takes precedence. Under these circumstances the transmission is permissible if: The recipient has substantiated a legitimate interest in knowledge of the data. The data are summarised data in the sense of section 28(3) no. 3 of the DPA. The government intends to implement changes to the DPA in The draft bill, if passed, will introduce a limitation on the use of personal data for advertising, marketing and polling purposes to the extent that it will be limited to advertising for the data controller's company. This means that addresses can no longer be sold to other companies unless the data controller has obtained the data subject's specific consent to this. 11. Do special rules apply in the case of certain types of personal data, for example sensitive data? If so, please provide brief details. Sensitive personal data includes data relating to: Racial and ethnic origin. Political opinions. Religious or philosophical convictions. Union membership. Health.

9 Page 9 of 18 Sex life. If a data controller wishes to collect or process sensitive personal data, it must either obtain the data subject's explicit consent to such collection or processing, or it must rely on the specific provisions permitting the collection and processing of these special categories of personal data. Collection, processing and use of personal data for own purposes is only permissible if: This is necessary for the protection of vital interests of the data subject or a third party, if the data subject is unable to give his consent because of physical or legal grounds. The data subject has made these data publicly available. This is necessary to assert, execute or defend legal claims and there is no reason to assume that the data subject's interest meriting protection in the collection, processing or use takes precedence. This is necessary for the purpose of scientific research, which is subject to further requirements. Further, collection of sensitive personal data is permissible if it is required for certain medical purposes and the processing is carried out by medical personnel, which is subject to respective obligations of secrecy. In addition, transmission and use of sensitive personal data are permissible for the prevention of risks for national security and public safety, and for the prosecution of material crimes. Rights of individuals 12. What information should be provided to data subjects at the point of collection of the personal data? The data controller must ensure that the data subject is provided with: The identity of the data controller. The purpose of collection, processing and use. The categories of recipients if the data subject does not have to expect transmission to these recipients. Where data is collected directly from the data subject based on a provision requiring the data subject to provide the information, or if the provision of the information is a requirement for the granting of legal advantages, the data subject must be informed of this. Otherwise, it

10 Page 10 of 18 must be informed of the voluntary nature of the provision of information (section 4(3), DPA). 13. What other specific rights (such as a right of access to personal data or the right to object to processing) are granted to data subjects? On initial collection of personal data without the data subject's knowledge, the data subject must be informed of the (section 33, DPA): Storage as such. Identity of the data controller. Type of data stored. Purposes of collection, processing and use. Potential recipients of the data. In addition, the data subject has the following rights: Right to request information (sections 19 and 34, DPA). This includes information on the data stored concerning his person, including the respective data source, the recipient or the categories of recipients, and the purpose of the data storage. Right of correction in case of incorrect data (sections 20(1) and 35(1), DPA). Right of erasure. The data has to be erased if: the storage is illegal; the data includes information about the person's racial or ethnic origin, political opinions, religious or philosophical convictions, union membership, health or sex life, criminal actions or administrative offences, and the correctness of this information cannot be proven by the data controller; the data was processed for the data controller's own purposes and knowledge of the data is no longer required to achieve the purpose of storage; the data is processed as a business for the purpose of transfer and a review at each end of the fourth calendar year beginning with the initial storage reveals that further storage is not required (section 35(2), BDSG). Right of blocking (section 35(3), DPA). Instead of erasure, the blocking of data can be requested if erasure:

11 Page 11 of 18 is not possible because of legal, statutory or contractual retention periods; may impair interests meriting protection of the data subject; is not possible or only with unreasonable effort, because of the specific nature of storage (sections 20(3) and 35(3), DPA). Personal data must also be blocked if the correctness is contested by the data subject and neither their correctness nor their incorrectness can be proven. Right to object to the collection, processing and use of personal data for advertisement and for marketing/polling purposes. Security requirements 14. What security requirements are imposed in relation to personal data? Data controllers and data processors must implement technical and organisational measures required under section 9 of the DPA. The main goals are to provide for the availability of services, functions and files, and authenticity and integrity of data. The arrangements are only required if the investment is in reasonable proportion to the contemplated security purpose. This does not release the data controller/data processor from its obligation to implement safety measures if their implementation entails high costs. Rather, a data controller or processor does not have to implement the highest technological standard but only the standard which can reasonably be required. The annex to section 9 of the DPA requires: Control of access to the data processing equipment and systems. Control of access authorisation. Control of data transfer. Retroactive input control. Control of processing in compliance with instructions. Availability control, that is, protection of data from destruction and loss. Separation of data collected for different purposes. To meet these requirements, the applicable methods include protocols, random examinations, use of passwords, security management, function separation, archival storage

12 Page 12 of 18 and virus blocking. Processing by third parties 15. What additional requirements (if any) apply where a third party processes the data on behalf of the data controller? Data processing by a third party on behalf of the data controller is explicitly regulated in the DPA (section 11, DPA). It requires: A written agreement between the data controller and the data processor. It must describe the agreed data processing services in detail, that is: the individual tasks; the technical and organisational data security measures (in accordance with the annex to section 9 of the DPA (see Question 14)); potential sub-processing, if applicable, and allow for respective arrangements with sub-processors. That the data processor must be strictly bound to follow the data controller's processing instructions. In the absence of this: the data processor will be classified as a data controller itself and assumes all responsibilities under the DPA; the transfer of the data from the data controller to the data processor would not be privileged and would require either consent or a statutory permission by the individual. If a data processor acts beyond the data controller's instructions or at its own discretion when processing the data, it is automatically held to be a data controller. The data transfer from the data controller to the data processor is regarded as an internal process and therefore does not require the individual's consent. Data processing through a data processor must be differentiated from the outsourcing of a function. Privileged data processing is not given if the recipient of data assumes its own legal responsibility in relation to the function for which the data is processed. The differentiation is particularly difficult in relation to centralised HR management in company groups. If the individual group company retains the right to make its own personnel decisions, including data processing decisions, the relationship is likely to be that of data processor-data controller. In contrast, if the central HR management makes the decisions, the entire function is likely to be outsourced.

13 Page 13 of 18 International transfer of data 16. What rules govern the transfer of data outside your jurisdiction? Data transfers outside Germany must pass two tests: Requirements for any transfer. Any data transfer constitutes processing of personal data and requires the consent of the individual or a statutory permission (see Questions 9 and 10). Requirements for transfer outside the EEA. Data transfer outside the EEA is prohibited if the data subject has a legitimate interest in the prevention of the data transfer (sections 4b(1) and (2), DPA). Such legitimate interest is statutorily assumed if and where the recipient does not provide for a level of protection adequate to the protection in the EEA. If the recipient's country of residence provides for an adequate level of protection, it can generally be inferred that the recipient abides by the regulations of its country of residence and therefore maintains an adequate level of protection unless there are indications to the opposite. The European Commission (Commission) has made findings that the following countries offer an adequate level of protection: Argentina; Canada (subject to certain conditions); Guernsey; Isle of Man; Switzerland. The transfer of data outside the EEA is further allowed in the following cases: As data transfer to a recipient in the US if the recipient has agreed to comply with the Safe Harbour Principles. The parties use the model contracts authorised by the Commission. The execution of a model contract either between two data controllers or between a data controller and a data processor provides for an adequate level of protection with regard to the specific recipient (section 4c(2), DPA). A company group can implement binding corporate rules to legitimise the transfer of personal data between the group companies. There is currently a dispute about whether binding corporate rules require approval by the respective national data protection authorities of each country of residence of the individual group companies. To ensure that data transfers are legitimate, data controllers should co-operate with the competent

14 Page 14 of 18 data protection authority. The requirements of section 4c, DPA are fulfilled. The transfer of personal data to recipients who do not provide an adequate level of protection is permitted if: the data subject has given its free and informed consent; the transfer is necessary for the performance of a contract between the data subject and the data controller or for the performance of pre-contractual measures initiated by the data subject; the transfer is necessary for the conclusion or performance of a contract which the data controller has concluded or will conclude with a third party in the data subject s interest; the transfer is necessary to safeguard an important public interest or for the assertion, execution or defence of legal claims before a court; the transfer is necessary to safeguard vital interests of the data subject; the transfer is executed from a register for information of the public (subject to certain conditions). The recipient has to be informed that the data may only be processed in connection with the underlying reason of the transfer. 17. Are data transfer agreements contemplated or in use? Have any standard forms or precedents been approved by national authorities? The Commission has approved three sets of standard contractual clauses to provide an adequate level of protection between the data transmitter and the recipient. Two sets deal with the situation of two data controllers, while the third set specifically regulates the relationship between a data controller and a data processor located outside the EEA. It is possible to include the model clauses in another agreement, but to gain the benefit from these clauses, they must be implemented without modifications. It is also possible to obtain the data protection authority's approval for individual data transfers or specific kinds of data transfers if the data controller can prove sufficient guarantees for the protection of the personal rights (section 4c(2), DPA). Such guarantees can in particular be provided for by: Contractual arrangements other than the EU model clauses. Binding corporate rules.

15 Page 15 of Is a data transfer agreement sufficient to legitimise transfer, or must additional requirements (such as the need to obtain consent) be satisfied? In addition to the data transfer agreement, the general requirements of legal data processing must also be met (see Question 16), that is, either consent or a statutory permission of the transfer itself is required. 19. Does the relevant national regulator need to approve the data transfer agreement? If so, please provide brief details. Transfers under the EU model contracts as well as under the US Safe Harbour Program do not require approval of the relevant data protection authority. Individual agreements do require the approval by the regulator. With binding corporate rules, there is dispute about whether they are subject to approval or not (see Question 16). This also applies to standard contractual clauses that have been modified by the parties. A data controller should therefore liaise with the competent data protection authority to determine its obligations regarding approval. A formal approval procedure is not in place. Enforcement and sanctions 20. What are the enforcement powers of the national regulator? The competent data protection authority can: Impose administrative fines. Give orders to remedy technical or organisational faults in the data processing or prohibit the use of specific procedures if the faults are not remedied. Recall the data protection officer from its position in case the data protection officer does not have the required competences or reliability. Audit the data controller's premises. 21. What are the sanctions and remedies for non-compliance with the data protection laws? To what extent are the laws actively enforced? The DPA provides for three different kinds of sanctions for non-compliance with its provisions: Administrative fines Violation of formality requirements can be punished by a fine of up to EUR25,000 (about

16 Page 16 of 18 US$31,700). Examples of such violations include the failure to timely submit a notification of the data processing to the competent data protection authority or failure to appoint a data protection officer. If the offender violates material provisions, that is, if he processes personal data without authorisation, fines of up to EUR250,000 (about US$316,900) can be imposed. According to the draft bill, the fines will be increased to EUR50,000 (about US$63,400) and EUR300,000 (approx. US$380,200) respectively. Criminal prosecution If the above offences are committed for compensation or with an intention to enrich oneself or a third person, or to harm a third person, the offender may be subject to imprisonment of up to two years or to monetary fines (section 44 DPA). Other administrative sanctions In case of violations of the DPA or other data protection provisions, the competent data protection authority can inform the respective data subject and can visit the data controller's site for audit and inspection purposes. The authority may review: Business documents. The index of procedures. The stored personal data. The data processing programmes. In addition, it can recourse to the measures explained in Question 20. Damages In addition, data subjects whose rights have been infringed can claim damages. Section 7 of the DPA provides for a claim for damages of a data subject who suffers damage because of the data controller's illegitimate or incorrect collection, processing or use of the individual's personal data, unless the data controller has observed the necessary diligence. The regulatory authority In Germany, each state has a regulatory authority in addition to the federal authority. Federal public entities are subject to the supervision of the federal data protection authority while state public entities and private sector data controllers are subject to the supervision of the authority of the state in which they reside. Most states differentiate between the control over public data controllers and non-public data controllers. W The names and addresses of the data protection authorities are available under

17 Page 17 of 18 Main areas of responsibility. The data protection authorities are the supervisory authorities for all data controllers. They are responsible for enforcing the DPA and other legislation containing data protection regulations. In addition they are the main contact for queries from all persons/entities handling personal data and they encourage co-operation. Contributor details Stephan Rippert Reed Smith LLP, Munich office T +49 (0) F +49 (0) E srippert@reedsmith.com W Areas of practice/expertise. Stephan Rippert is a corporate partner and responsible for the practice group Advertising, Technology and Media of the German office of Reed Smith. Stephan advises international and national companies on transactional and commercial issues. He is member of the worldwide Data Privacy Group of Reed Smith. The Data Privacy Group reaches across geographies and industries. The group draws on the skills and expertise of lawyers around the globe, advising clients in the financial services, insurance, health care, technology, information management, and other industries on all issues including data privacy, data protection, data transfer, regulatory and policy issues as well as litigation management. Katharina A Weimer Reed Smith LLP, Munich office T +49 (0) F +49 (0) E kweimer@reedsmith.com W Areas of practice/expertise. Katharina A Weimer is an associate at Reed Smith in Munich. As member of the Data Privacy Group she focuses on national and cross-border data protection and privacy matters. Resource information

18 Page 18 of 18 Resource ID: Law stated date: 01-Mar-2009 Products: PLC Commercial, PLC Public Sector, PLC Law Department, PLC Cross-border Handbooks\2009\Data Protection 2009/10, PLC IPIT & Communications, PLC Cross-border Series: Country Q&A( ) Related content Topics Cross-border: IP&IT ( Data protection ( Topics from other jurisdictions Public sector ( Legal & Commercial Publishing Limited ( Terms of use ( 0884) and privacy policy ( Subscription enquiries +44 (0) or The reference after links to resources on our site (e.g ) is to the PLC Reference ID. This will include any PDF or Word versions of articles.

Subject: Kier Group plc Data Protection Policy

Subject: Kier Group plc Data Protection Policy Kier Group plc Data Protection Policy Subject: Kier Group plc Data Protection Policy Author: Compliance Document type: Policy Authorised by: Kier General Counsel & Company Secretary Version 3 Effective

More information

Monthly news and analysis of data protection and privacy issues from around the world. Volume 9, Number 9 September 2009

Monthly news and analysis of data protection and privacy issues from around the world. Volume 9, Number 9 September 2009 Reproduced with permission from World Data Protection Report, null, 09/01/2009. Copyright 2009 by The Bureau of National Affairs, Inc. (800-372-1033) http://www.bna.com BNA International X World Data Protection

More information

DATA PROTECTION LAWS OF THE WORLD. Germany

DATA PROTECTION LAWS OF THE WORLD. Germany DATA PROTECTION LAWS OF THE WORLD Germany Downloaded: 25 November 2017 GERMANY Last modified 26 January 2017 LAW The main legal source of data protection in Germany is the Federal Data Protection Act (

More information

Motorola Mobility Binding Corporate Rules (BCRs)

Motorola Mobility Binding Corporate Rules (BCRs) Motorola Mobility Binding Corporate Rules (BCRs) Introduction These Binding Privacy Rules ( Rules ) explain how the Motorola Mobility group ( Motorola Mobility ) respects the privacy rights of its customers,

More information

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION Document Control Owner: Distribution List: Data Protection Officer Relevant individuals who access, use, store or

More information

CROSS-BORDER HANDBOOKS 1

CROSS-BORDER HANDBOOKS  1 Data Protection 2009/10 Austria Austria Dr Ferdinand Graf, Graf & Pitkowitz Rechtsanwälte GmbH Regulation 1. What national law(s) apply to the collection and use of personal data? If applicable, has Directive

More information

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ):

Within the meanings of applicable data protection law (in particular EU Regulation 2016/679, the GDPR ): Privacy Policy Introduction Ikano S.A. ( Ikano ) respects your privacy and is committed to protect your Personal Data by being compliant with this privacy policy ( Policy ). In addition to Ikano, this

More information

Cognizant Careers Portal Privacy Policy ( Policy )

Cognizant Careers Portal Privacy Policy ( Policy ) Cognizant Careers Portal Privacy Policy ( Policy ) Date: 22 March 2017 Introduction This Careers Portal Privacy Policy ("Policy") applies to the Careers portal on the Cognizant website accessed via www.cognizant.com/careers

More information

UWTSD Group Data Protection Policy

UWTSD Group Data Protection Policy UWTSD Group Data Protection Policy Contents Clause Page 1. Policy statement... 1 2. About this policy... 1 3. Definition of data protection terms... 1 4. Data protection principles..3 5. Fair and lawful

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Data Protection Policy Version 3.00 May 2018 For more information, please contact: Technical Team T: 01903 228100 / 01903 550242 E: info@24x.com Page 1 The Data Protection Law...

More information

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov

Contributed by Djingov, Gouginski, Kyutchukov & Velichkov Contributed by Djingov, Gouginski, Kyutchukov & Velichkov General I Data Protection Laws National Legislation General data protection laws The Personal Data Protection Act implemented the Data Protection

More information

Rights of Individuals under the General Data Protection Regulation

Rights of Individuals under the General Data Protection Regulation Rights of Individuals under the General Data Protection Regulation 2018 Contents Introduction... 2 Glossary... 3 Personal data... 3 Processing... 3 Data Protection Commission... 3 Data Controller... 3

More information

Privacy Policy. Data Controller - the entity that determines the purposes, conditions and means of the processing of personal data

Privacy Policy. Data Controller - the entity that determines the purposes, conditions and means of the processing of personal data Privacy Policy Datacenter.com (referred to as we, us, our, Datacenter or the Company ) is committed to protecting your privacy and handling your data in an open and transparent manner. The personal data

More information

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2 COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September 2018 Table of Contents 1. Scope, Purpose and Application to Employees 2 2. Reference Documents 2 3. Definitions 3 4. Data Protection Principles

More information

CNH Industrial Privacy Policy. This Privacy Policy relates to our use of any personal information you provide to us.

CNH Industrial Privacy Policy. This Privacy Policy relates to our use of any personal information you provide to us. CNH Industrial Privacy Policy General Terms The CNH Industrial Group appreciates your interest in its products and your visit to this website. The protection of your privacy in the processing of your personal

More information

Privacy Policy GENERAL

Privacy Policy GENERAL Privacy Policy GENERAL This document sets out what information Springhill Care Group Ltd collects from visitors, how it uses the information, how it protects the information and your rights. Springhill

More information

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy.

USER CORPORATE RULES. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. These User Corporate Rules are available to Users at any time via a link accessible in the applicable Service Privacy Policy. I. OBJECTIVE ebay s goal is to apply uniform, adequate and global data protection

More information

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY VIACOM INC. PRIVACY SHIELD PRIVACY POLICY Last Modified and Effective as of October 23, 2017 Viacom respects individuals privacy, and strives to collect, use and disclose personal information in a manner

More information

Liechtenstein. General I Data Protection Laws. Contributed by Wanger Advokaturbüro. National Legislation. National Regulatory Authority.

Liechtenstein. General I Data Protection Laws. Contributed by Wanger Advokaturbüro. National Legislation. National Regulatory Authority. Contributed by Wanger Advokaturbüro General I Data Protection Laws National Legislation General data protection laws The Data Protection Act (the DPA ) dated 14 March 2002 and the relevant Ordinance on

More information

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2

Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy... 1 EU-U.S. Privacy Shield Policy... 2 Privacy Policy knows that your privacy is important to you. Below is our privacy policy for collecting, using, securing, protecting and sharing your

More information

Privacy Notice - General Data Protection Regulation ( GDPR )

Privacy Notice - General Data Protection Regulation ( GDPR ) THIS PRIVACY NOTICE APPLIES TO ANY PERSON WHO INSTRUCTS AN INDIVIDUAL BARRISTER AT 12 OLD SQUARE CHAMBERS EITHER DIRECTLY OR THROUGH A SOLICITOR OR WHO ASKS THE INDIVIDUAL BARRISTER FOR A REFERENCE Privacy

More information

Islam21c.com Data Protection and Privacy Policy

Islam21c.com Data Protection and Privacy Policy Islam21c.com Data Protection and Privacy Policy Purpose of this policy The purpose of this policy is to communicate to staff, volunteers, donors, non-donors, supporters and clients of Islam21c the approach

More information

the processing of personal data relating to him or her.

the processing of personal data relating to him or her. Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the Hotel & Pensionat Björkelund. The use of

More information

UWC International Data Protection Policy

UWC International Data Protection Policy UWC International Data Protection Policy 1. Introduction This policy sets out UWC International s organisational approach to data protection. UWC International is committed to protecting the privacy of

More information

DISCLOSURE ON THE PROCESSING OF PERSONAL DATA LAST REVISION DATE: 25 MAY 2018

DISCLOSURE ON THE PROCESSING OF PERSONAL DATA LAST REVISION DATE: 25 MAY 2018 DISCLOSURE ON THE PROCESSING OF PERSONAL DATA LAST REVISION DATE: 25 MAY 2018 Introduction This disclosure on the processing of personal data (hereinafter, the "Disclosure") is provided pursuant to Art.

More information

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ). PRIVACY POLICY Data Protection Policy 1. Introduction This Data Protection Policy (this Policy ) sets out how Brital Foods Limited ( we, us, our ) handle the Personal Data we Process in the course of our

More information

Privacy Notice. General Information Protection Regulation ( GDPR )

Privacy Notice. General Information Protection Regulation ( GDPR ) Privacy Notice General Information Protection Regulation ( GDPR ) Please read the following information carefully. This privacy notice contains information about the information collected, stored and otherwise

More information

Technical Requirements of the GDPR

Technical Requirements of the GDPR Technical Requirements of the GDPR Purpose The purpose of this white paper is to list in detail all the technological requirements mandated by the new General Data Protection Regulation (GDPR) laws with

More information

Privacy Shield Policy

Privacy Shield Policy Privacy Shield Policy Catalyst Repository Systems, Inc. (Catalyst) has adopted this Privacy Shield Policy ("Policy") to establish and maintain an adequate level of Personal Data privacy protection. This

More information

Cayman Islands Data Protection Law Guide Book

Cayman Islands Data Protection Law Guide Book Cayman Islands Data Protection Law Guide Book 2017 Guide Book Cayman Islands Data Protection Law, 2017 1. Background and Overview On 27 March 2017 the Data Protection Law, 2017 (Law) was passed by the

More information

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms:

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms: Last updated: 20/04/2018 Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of VITO (Vlakwa). The

More information

Privacy Policy CARGOWAYS Logistik & Transport GmbH

Privacy Policy CARGOWAYS Logistik & Transport GmbH Privacy Policy CARGOWAYS Logistik & Transport GmbH We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the CARGOWAYS

More information

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1

Catalent Inc. Privacy Policy v.1 Effective Date: May 25, 2018 Page 1 Catalent, Inc. Privacy Policy, effective May 25, 2018 1. This Policy This Privacy Policy (this Policy ) is issued by Catalent, Inc. on behalf of itself and its domestic and international subsidiaries and

More information

DATA PROTECTION POLICY THE HOLST GROUP

DATA PROTECTION POLICY THE HOLST GROUP DATA PROTECTION POLICY THE HOLST GROUP INTRODUCTION The purpose of this document is to provide a concise policy regarding the data protection obligations of The Holst Group. The Holst Group is a data controller

More information

Cognizant Careers Portal Terms of Use and Privacy Policy ( Policy )

Cognizant Careers Portal Terms of Use and Privacy Policy ( Policy ) Cognizant Careers Portal Terms of Use and Privacy Policy ( Policy ) Introduction This Policy applies to the Careers portal on the Cognizant website accessed via www.cognizant.com/careers ("Site"), which

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Introduction Stewart Watt & Co. is law firm and provides legal advice and assistance to its clients. It is regulated by the Law Society of Scotland. The personal data that Stewart

More information

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready? European Union (EU) General Data Protection Regulation (GDPR) Do you handle EU residents personal data? The GDPR update is coming May 25, 2018. Are you ready? What do you need to do? Governance and Accountability

More information

The British Museum. Data Protection Code of Practise. 1 Introduction

The British Museum. Data Protection Code of Practise. 1 Introduction The Data Protection Code of Practice 1 Introduction 1.1 The 1998 Data Protection Act is aimed at ensuring a balance between individuals rights to privacy and the lawful processing of personal data undertaken

More information

1 Privacy Statement INDEX

1 Privacy Statement INDEX INDEX 1 Privacy Statement Mphasis is committed to protecting the personal information of its customers, employees, suppliers, contractors and business associates. Personal information includes data related

More information

WEBSITE PRIVACY POLICY

WEBSITE PRIVACY POLICY WEBSITE PRIVACY POLICY INTRODUCTION Welcome to the Octopus Group s privacy policy ( Privacy Policy ) Octopus Group respects your privacy and is committed doing the right thing when it comes to protecting

More information

INNOVENT LEASING LIMITED. Privacy Notice

INNOVENT LEASING LIMITED. Privacy Notice INNOVENT LEASING LIMITED Privacy Notice Table of Contents Topic Page number KEY SUMMARY 2 ABOUT US AND THIS NOTICE 3 USEFUL WORDS AND PHRASES 4 WHAT INFORMATION DO WE COLLECT? 4 WHY DO WE PROCESS YOUR

More information

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy DEPARTMENT OF JUSTICE AND EQUALITY Data Protection Policy May 2018 Contents Page 1. Introduction 3 2. Scope 3 3. Data Protection Principles 4 4. GDPR - Rights of data subjects 6 5. Responsibilities of

More information

PRINCIPLES OF PROTECTION OF PERSONAL DATA (GDPR) WITH EFFICIENCY FROM

PRINCIPLES OF PROTECTION OF PERSONAL DATA (GDPR) WITH EFFICIENCY FROM PRINCIPLES OF PROTECTION OF PERSONAL DATA (GDPR) WITH EFFICIENCY FROM 25.5.2018 Through our Privacy Policy ("Policy"), we inform the entities of the data we process our personal data, as well as all the

More information

Data Processing Agreement DPA

Data Processing Agreement DPA Data Processing Agreement DPA between Clinic Org. no. «Controller». and Calpro AS Org. nr. 966 291 281. «Processor» If the parties have executed a Data Management Agreement, the Date Management Agreement

More information

PRIVACY NOTICE Olenex Sarl

PRIVACY NOTICE Olenex Sarl PRIVACY NOTICE Olenex Sarl 5-24-2018 PRIVACY NOTICE GENERAL This Online Privacy Notice ( Notice ) provides you with important information about how Olenex processes your personal data, particularly in

More information

INFORMATION TO BE GIVEN 2

INFORMATION TO BE GIVEN 2 (To be filled out in the EDPS' office) REGISTER NUMBER: 1423 (To be filled out in the EDPS' office) NOTIFICATION FOR PRIOR CHECKING DATE OF SUBMISSION: 03/01/2017 CASE NUMBER: 2017-0015 INSTITUTION: ESMA

More information

Brasenose College ICT Systems Privacy Notice (v1.2)

Brasenose College ICT Systems Privacy Notice (v1.2) Brasenose College ICT Systems Privacy Notice (v1.2) A summary of what this notice explains Brasenose College is committed to protecting the privacy and security of personal data. This notice applies to

More information

General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of

General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of General Data Protection Regulation BT s amendments to the proposed Regulation on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General

More information

Creative Funding Solutions Limited Data Protection Policy

Creative Funding Solutions Limited Data Protection Policy Creative Funding Solutions Limited Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts POLICY STATEMENT Adkin is committed to protecting and respecting the privacy of all of our clients. This Policy

More information

Privacy Policy Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH 1. Definitions

Privacy Policy Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH Kühnreich & Meixner GmbH 1. Definitions Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the Kühnreich & Meixner GmbH. The use of the

More information

Jefferies EMEA Privacy Notice

Jefferies EMEA Privacy Notice Jefferies International Limited Vintners Place 68 Upper Thames St London United Kingdom Jefferies EMEA Privacy Notice 1. Introduction This Privacy Notice explains what we do with your personal data. It

More information

GLOBAL DATA PROTECTION POLICY

GLOBAL DATA PROTECTION POLICY GLOBAL DATA PROTECTION POLICY BRS UK Version 1.0 TABLE OF CONTENTS SCOPE 2 COLLECTION AND PROCESSING USE OF YOUR PERSONAL DATA 2 Compliance with the European data protection law and any additional applicable

More information

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR).

MBNL Landlord Privacy Notice. This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR). MBNL Landlord Privacy Notice This notice sets out how we handle landlord personal data as part of our General Data Protection policies (GDPR). SUMMARY This Privacy Notice applies to: users of our website

More information

Privacy Statement for Use of the Certification Service of Swisscom (sales name: "All-in Signing Service")

Privacy Statement for Use of the Certification Service of Swisscom (sales name: All-in Signing Service) Swisscom (sales name: "All-in Signing Service") General Privacy is a matter of trust, and your trust is important to us. Handling personal data in a responsible and legally compliant manner is a top priority

More information

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017 Data Protection should be part of every company s or organisation s DNA Do you process

More information

PRIVACY POLICY PRIVACY POLICY

PRIVACY POLICY PRIVACY POLICY PRIVACY POLICY 1 A. GENERAL PART 1.1. COLLECTION AND PROCESSING OF USER DATA Within the scope of the availability of the website hosted in www.alpinushotel.com and of the services and communications made

More information

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY

Guardian Electrical Compliance Ltd DATA PROTECTION GDPR REGULATIONS POLICY 1. Statement of Policy (Guardian) needs to collect and use certain types of information about the Individuals or Service Users with whom they come into contact in order to carry on our work. This personal

More information

HF Markets SA (Pty) Ltd Protection of Personal Information Policy

HF Markets SA (Pty) Ltd Protection of Personal Information Policy Protection of Personal Information Policy Protection of Personal Information Policy This privacy statement covers the website www.hotforex.co.za, and all its related subdomains that are registered and

More information

Privacy Policy Effective May 25 th 2018

Privacy Policy Effective May 25 th 2018 Privacy Policy Effective May 25 th 2018 1. General Information 1.1 This policy ( Privacy Policy ) explains what information Safety Management Systems, 2. Scope Inc. and its subsidiaries ( SMS ), it s brand

More information

HOW WE USE YOUR INFORMATION

HOW WE USE YOUR INFORMATION HOW WE USE YOUR INFORMATION Herold Mediatel Ltd compiles the Gibraltar Telephone Directory on behalf of Gibtelecom. Every care is taken to render this Directory as accurate as possible but neither Herold

More information

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk CURTIS BANKS LIMITED Privacy Information Notice curtisbanks.co.uk Contents Section Page 1 Who we are 3 2 Why we need to collect, use and process personal information 3 3 The information we may collect,

More information

Austria. Jakob Widner Graf & Pitkowitz Rechtsanwälte GmbH. Country Q&A. Data Protection 2011/12. Country Q&A. Regulation

Austria. Jakob Widner Graf & Pitkowitz Rechtsanwälte GmbH. Country Q&A. Data Protection 2011/12. Country Q&A. Regulation Austria Jakob Widner Graf & Pitkowitz Rechtsanwälte GmbH www.practicallaw.com/0-502-0328 Regulation 4. What acts are regulated (EU: processing)? 1. What national law(s) regulate the collection and use

More information

Data Processor Agreement

Data Processor Agreement Data Processor Agreement Data Controller: Customer located within the EU (the Data Controller ) and Data Processor: European Representative Company: ONE.COM (B-one FZ-LLC) One.com A/S Reg.no. Reg.no. 19.958

More information

PRIVACY NOTICE STORM RECRUITMENT UNIT 11, 2 ND FLOOR CHARLESLAND CENTRE, GREYSTONES, CO. WICKLOW 1. INTRODUCTION

PRIVACY NOTICE STORM RECRUITMENT UNIT 11, 2 ND FLOOR CHARLESLAND CENTRE, GREYSTONES, CO. WICKLOW 1. INTRODUCTION PRIVACY NOTICE STORM RECRUITMENT UNIT 11, 2 ND FLOOR CHARLESLAND CENTRE, GREYSTONES, CO. WICKLOW 1. INTRODUCTION 1.1 STORM RECRUITMENT is strongly committed to protecting your Personal Data. This Privacy

More information

Privacy Notice - Stora Enso s Customer and Sales Register. 1 Controller

Privacy Notice - Stora Enso s Customer and Sales Register. 1 Controller Privacy Notice - Stora Enso s Customer and Sales Register Date 29.1.2018 1 2 Purpose of this privacy notice is to provide the persons communicating with Stora Enso or otherwise registered in Stora Enso

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement Merchant (the "Data Controller") and Nets (the "Data Processor") (separately referred to as a Party and collectively the Parties ) have concluded this DATA PROCESSING AGREEMENT

More information

Privacy Notice - Stora Enso s Supplier and Stakeholder Register. 1 Purpose

Privacy Notice - Stora Enso s Supplier and Stakeholder Register. 1 Purpose Privacy Notice - Stora Enso s Supplier and Stakeholder Register Date 29.1.2018 1 Purpose Purpose of this privacy notice is to provide the persons communicating with Stora Enso in the role of a supplier

More information

Privacy Policy. Company registry number: Budapest, Gönczy Pál utca em. Homepage: contact: Phone:

Privacy Policy. Company registry number: Budapest, Gönczy Pál utca em. Homepage:  contact: Phone: Privacy Policy 1. Introduction Your complete satisfaction and confidence in Flow Hostel are absolutely essential to us. In order to meet your expectations, we have set up a customer privacy protection

More information

Legal compliance requests for social networks, as shown by greydate.com, a mock social community network site, based on German law / EC Directives

Legal compliance requests for social networks, as shown by greydate.com, a mock social community network site, based on German law / EC Directives Legal compliance requests for social networks, as shown by greydate.com, a mock social community network site, based on German law / EC Directives by Oliver M. Habel, PhD, teclegal Habel Rechtsanwälte

More information

Element Finance Solutions Ltd Data Protection Policy

Element Finance Solutions Ltd Data Protection Policy Element Finance Solutions Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

CROSS-BORDER HANDBOOKS 1

CROSS-BORDER HANDBOOKS   1 Belgium Belgium Steven De Schrijver and Jan Dhont, Lorenz www.practicallaw.com/1-385-8611 Regulation 1. What national law(s) apply to the collection and use of personal data? If applicable, has Directive

More information

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal

This guide is for informational purposes only. Please do not treat it as a substitute of a professional legal What is GDPR? GDPR (General Data Protection Regulation) is Europe s new privacy law. Adopted in April 2016, it replaces the 1995 Data Protection Directive and marks the biggest change in data protection

More information

CliniSys Website Privacy Policy

CliniSys Website Privacy Policy CliniSys Website Privacy Policy Version 1.0 Document Information Prepared for: Users of the CliniSys Website Prepared by: CliniSys Solutions Limited Date: 13 February 2018 Contact Details: Matthew Fouracre,

More information

Privacy Policy. 1. Definitions

Privacy Policy. 1. Definitions Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the Austro Control. The use of the Internet

More information

In this data protection declaration, we use, inter alia, the following terms:

In this data protection declaration, we use, inter alia, the following terms: Privacy Policy We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of Z&J Technologies GmbH. The use of the Internet

More information

Privacy Policy. MIPS Website Privacy Policy. Document Information. Contact Details. Version 1.0 Version date March 2018.

Privacy Policy. MIPS Website Privacy Policy. Document Information. Contact Details. Version 1.0 Version date March 2018. Privacy Policy MIPS Website Privacy Policy Version 1.0 Version date March 2018 Document Information Prepared for Users of MIPS websites Prepared by MIPS NV Date 27/02/2018 Contact Details Joffrey WILLEM

More information

Talenom Plc. Description of Data Protection and Descriptions of Registers

Talenom Plc. Description of Data Protection and Descriptions of Registers Talenom Plc. Description of Data Protection and Descriptions of Registers TALENOM DESCRIPTION OF DATA PROTECTION Last updated 14 March 2018 Scope Limitations Data protection principles Personal data Registers

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement ( DPA ) is entered into between: A. The company stated in the Subscription Agreement (as defined below) ( Data Controller ) and B. Umbraco A/S Haubergsvej

More information

1 About GfK and the Survey What are personal data? Use of personal data How we share personal data... 3

1 About GfK and the Survey What are personal data? Use of personal data How we share personal data... 3 Privacy Notice For ad-hoc CAWI (without target list) V1.0 June 4, 2018 Contents 1 About GfK and the Survey... 2 2 What are personal data?... 2 3 Use of personal data... 2 4 How we share personal data...

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

If you have any questions about this notice, please contact the Head Master.

If you have any questions about this notice, please contact the Head Master. Parent Privacy Notice Introduction This notice is to help you understand how and why we collect personal information about you and what we do with that information. It also explains the decisions that

More information

GLOBAL DATA PROTECTION POLICY

GLOBAL DATA PROTECTION POLICY GLOBAL DATA PROTECTION POLICY Last update: April 2nd, 2018 SCOPE 3 COLLECTION AND PROCESSING USE OF YOUR PERSONAL DATA 3 Compliance with the European Data Protection Law and any additional applicable data

More information

Privacy Policy. This document describes the privacy policy of United TLD Holdco Ltd (T/A Rightside Registry).

Privacy Policy. This document describes the privacy policy of United TLD Holdco Ltd (T/A Rightside Registry). This document describes the privacy policy of United TLD Holdco Ltd (T/A Rightside Registry). September 2016 Copyright 2016 Rightside Group, Ltd. United TLD Holdco Ltd. t/a Rightside Registry (UTLDH) is

More information

Online Ad-hoc Privacy Notice

Online Ad-hoc Privacy Notice Online Ad-hoc Privacy Notice Last revised: 24 May 2018 Table of contents 1 About us and our Surveys... 2 2 What is personal data?... 2 3 Use of personal data... 2 3.1 Categories of personal data that are

More information

DATA PROTECTION IN RESEARCH

DATA PROTECTION IN RESEARCH DATA PROTECTION IN RESEARCH Document control Applicable to: All employees and research students Date first approved February 2006 Date first amended May 2015 Date last amended May 2015 Approved by Approval

More information

Data Processing Agreement for Oracle Cloud Services

Data Processing Agreement for Oracle Cloud Services Data Processing Agreement for Oracle Cloud Services Version January 12, 2018 1. Scope, Order of Precedence and Term 1.1 This data processing agreement (the Data Processing Agreement ) applies to Oracle

More information

Legal notice and Privacy policy

Legal notice and Privacy policy Legal notice and Privacy policy We appreciate your interest in us. Below you will find information of legal relevance when visiting this website. In addition, you will find our Privacy Policy, which explains

More information

Data Privacy Policy. of Eisenmann Übersetzungsteam - Suzanne Eisenmann - translation team

Data Privacy Policy. of Eisenmann Übersetzungsteam - Suzanne Eisenmann - translation team Data Privacy Policy of Eisenmann Übersetzungsteam - Suzanne Eisenmann - translation team We are delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority

More information

BIOEVENTS PRIVACY POLICY

BIOEVENTS PRIVACY POLICY BIOEVENTS PRIVACY POLICY At Bioevents, your privacy is important. Below you will find our privacy policy, which covers all personally identifiable data shared through Bioevents websites. Our privacy policy

More information

Data Protection. Code of Conduct for Cloud Infrastructure Service Providers

Data Protection. Code of Conduct for Cloud Infrastructure Service Providers Data Protection Code of Conduct for Cloud Infrastructure Service Providers 27 JANUARY 2017 Introduction... 3 1 Structure of the Code... 5 2 Purpose... 6 3 Scope... 7 4 Data Protection Requirements... 9

More information

DATA PRIVACY & PROTECTION POLICY POLICY INFORMATION WE COLLECT AND RECEIVE. Quality Management System

DATA PRIVACY & PROTECTION POLICY POLICY INFORMATION WE COLLECT AND RECEIVE. Quality Management System DATA PRIVACY & PROTECTION POLICY POLICY This Data Privacy & Protection Policy applies to ELMO Software Limited s Cloud HR & Payroll applications and platform (collectively, the Services ), elmosoftware.com.au

More information

What personal data or information do we collect? The personal information we collect may include:

What personal data or information do we collect? The personal information we collect may include: Privacy and Cookies At Knowledge Skills & Attitude Limited, we take your privacy seriously and this privacy statement explains what personal data or information we collect from you and from people who

More information

VISTRA ZURICH AG - PRIVACY NOTICE

VISTRA ZURICH AG - PRIVACY NOTICE Effective Date: from 25 May 2018 VISTRA ZURICH AG - PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal data, and your rights

More information

PRIVACY NOTICE VOLUNTEER INFORMATION. Liverpool Women s NHS Foundation Trust

PRIVACY NOTICE VOLUNTEER INFORMATION. Liverpool Women s NHS Foundation Trust PRIVACY NOTICE VOLUNTEER INFORMATION Liverpool Women s NHS Foundation Trust Introduction This document summarises who we are, what information we hold about you, what we will do with the information we

More information

Privacy Policy November 30th, 2017

Privacy Policy November 30th, 2017 Privacy Policy November 30th, 2017 THIS PAGE INTENTIONALLY LEFT BLANK Table of Contents 1 PREFACE 4 2 DEFINITIONS 4 3 NAME AND ADDRESS OF THE CONTROLLER 6 4 COOKIES 6 5 COLLECTION OF GENERAL DATA AND INFORMATION

More information

TIA. Privacy Policy and Cookie Policy 5/25/18

TIA. Privacy Policy and Cookie Policy 5/25/18 TIA Privacy Policy and Cookie Policy 5/25/18 Background: TIA understands that your privacy is important to you and that you care about how your information is used and shared online. We respect and value

More information

You can find a brief summary of this Privacy Policy in the chart below.

You can find a brief summary of this Privacy Policy in the chart below. In this policy Shine TV Limited with registered office at Shepherds Building Central, Charecroft Way, Shepherds Bush, London, W14 0EE, UK (Company or we) informs you about how we collect, use and disclose

More information

Privacy Policy Hafliger Films SpA

Privacy Policy Hafliger Films SpA Hafliger Films SpA, with registered office at Via B. Buozzi no. 14-20089 Rozzano (MI), has for many years considered it of fundamental importance to protect the personal details of customers and suppliers,

More information