Privacy Shield. A New and Improved Safe Harbor. briefing

Size: px
Start display at page:

Download "Privacy Shield. A New and Improved Safe Harbor. briefing"

Transcription

1 Privacy Shield A New briefing The European Commission adopted its much anticipated decision on the EU- US Privacy Shield ( Privacy Shield ) on 12 July The Privacy Shield was developed jointly by the European Commission and the US Department of Commerce to replace the Safe framework, which was declared invalid by the Court of Justice of the European Union in the Schrems case. TOP 50 INNOVATIVE LAWYERS 2016 The adoption of this adequacy decision by the Commission means that any transfers of personal data from the EU to companies in the United States that are certified under the Privacy Shield will be deemed to be made in accordance with EU data protection law. As noted in our previous article here, US companies have been able since 1 August 2016 to sign up to the Privacy Shield and receive personal data originating in the EU on the basis of their Privacy Shield certification. It has been reported that over 500 organisations have been certified under the Privacy Shield to date, including such prominent stakeholders as Microsoft, Google and Salesforce, and that some 1,000 more are in the process of applying. Criticism The Privacy Shield has been the subject of much comment (both positive and critical) since its publication. Most of the criticism levied at the Privacy Shield focuses on concerns over the potential access by US public authorities to personal data transferred from the EU to the US This potential access was one of the main criticisms of Safe arising from the Schrems case, and appears to be a continued source of concern for privacy campaigners. Other criticisms of the Privacy Shield include that certain principles of European data protection law, for example in relation to data retention and purpose limitation, are not adequately reflected in the framework, and that the Privacy Shield does not give users as much control over the use of their personal data as under EU data protection law. What is new and improved in the Privacy Shield? Such criticism notwithstanding, it seems clear that the Privacy Shield improves on Safe in a number of key areas, considered below: More detailed transparency/notice requirements: The privacy principles that US companies receiving personal data originating from the EU will have to comply with (the Principles ) include more detailed and robust notice requirements than those required

2 under Safe. For example, organisations signing up to the Privacy Shield must provide a notice, in clear and conspicuous language to individuals informing them of: the types of personal data the organisation is collecting; whether (if relevant) its subsidiaries adhere to the Principles; the purposes for which the organisation will disclose personal data to third parties; the right of individuals to access their personal data; the independent resolution body designated to address complaints and provide recourse; the possibility in certain circumstances to invoke binding arbitration; and the requirement to disclose personal information in response to lawful requests by public authorities. In addition, the Principles are set out in a clear and easily understandable way for organisations in a single annex (Annex II) of the Commission s Decision. In the Safe decision these were constituted, in a rather piece-meal fashion, of Privacy Principles in one annex, and Frequently Asked Questions in another annex. More choice over uses of personal data: Privacy Shield requires certified organisations to offer individuals clear, conspicuous and readily available mechanisms to allow them to opt out of the disclosure of their personal data to third parties (save where such disclosure is to an agent pursuant to a contract) or of the use of their data for a purpose that is materially different from the purpose(s) for which it was originally collected (or subsequently authorised) by the individuals. The requirement for an opt out for a materially different use of data under the Privacy Shield is arguably more protective than the obligation under Safe, which required an opt-out for a purpose that was incompatible with the purpose(s) for which it was originally collected/subsequently authorised etc. Strengthened requirements and accountability for onward transfers: The Privacy Shield contains more detailed requirements in relation to the onward transfer of personal data from Privacy Shield organisations in the US to other third party organisations. Any onward transfers to data controllers must be made on foot of a contract with the third party controller providing that any data so transferred may only be processed for limited and specified purposes consistent with the consent provided by the individual and that the recipient will provide the same level of protection as the Principles and will notify the [Privacy Shield] organisation if it can no longer meet this obligation. By contrast, Safe only contained a broad requirement to apply the Notice and Choice Principles in respect of the disclosure of information to third parties. In addition, the Privacy Shield expands on the requirements set out in Safe in respect of the transfer of data to agents. These additional requirements include that the Privacy Shield organisation: transfers data only for limited and specified purposes; takes reasonable and appropriate steps to ensure that any processing is carried out in accordance with the Principles; takes steps to stop and remediate unauthorised processing; and provides a summary or copy of the relevant privacy provisions of the contract with the agent to the Department of Commerce if requested. A further improvement on Safe from a privacy perspective is that the Principles expressly state that Privacy Shield organisations will remain liable for any processing of personal data by their agents in a manner inconsistent with the Principles (unless the organisation proves that it is not responsible for the event giving rise to the damage). Safe, by contrast, contained a general presumption that the organisation, once it had complied 2 mccann fitzgerald ¼ october 2016

3 with the principles in respect of onward transfer to an agent, would not be held responsible for processing outside of the permitted purposes, unless the organisation was aware or should have been aware of such processing and did not take steps to remedy it. Data retention: The Principles state that personal data may only be retained for as long as it serves the processing purpose(s) for which it was originally collected /authorised by the individual (with an exception for archiving purposes in the public interest, journalism, literature, art etc). This is a marked improvement on Safe, which did not include specific obligations in relation to data retention. Wider range of enforcement mechanisms: The Privacy Shield also improves on Safe to the extent that it offers a wider range of avenues for individuals to seek redress where they are affected by an organisation s non-compliance with the Principles. These options include bringing a complaint: to the relevant organisation (the organisation must respond within 45 days); to the independent dispute resolution body designated in accordance with the Principles by the organisation; or, directly to the Federal Trade Commission. Individuals may also complain to a national Data Protection Authority who will deliver advice through an informal panel of DPAs established at Union level. Where the Privacy Shield organisation fails to comply with the DPAs advice within 25 days, the matter may be referred to the FTC or other competent US authority for enforcement action eg under Section 5 of the FTC Act (or similar statute) or to the Department of Commerce (who may remove the organisation from the Privacy Shield List). Finally, as a mechanism of last resort, individuals have the right to invoke binding arbitration. The Department of Commerce is to establish a fund supplied with annual contributions from Privacy Shield organisations to help cover the costs of the arbitration. Ombudsperson: The Commission decision acknowledges that whilst EU individuals do have certain avenues of redress where they have been the subject of unlawful surveillance for US national intelligence purposes, the available causes of actions are relatively limited, and EU citizens may have difficulty showing that they have the requisite standing (ie a legally protectable interest) to bring a case to court. In an effort to fill this gap, the US Secretary of State has committed to create a new Privacy Shield Ombudsperson, who is to be independent from the US Intelligence Community, and whose remit will include ensuring that individual complaints are properly investigated, that US laws have been complied with, or, where such laws have been violated, that the non-compliance has been remedied. Helpfully, individuals can address complaints to a competent national authority in their own country (and in their own language) and such authority will then assist the individual in formulating the request to the Ombudsperson. Also positive from a privacy perspective is that to bring a complaint before the Ombudsperson, an individual will not have to demonstrate that his/her personal data have in fact been accessed by the US government via surveillance activities. Assurances regarding access by US National Security agencies: The Privacy Shield includes written commitments by the US Government on enforcing the arrangement, including assurances from the Office of the Director of National 3 mccann fitzgerald ¼ october 2016

4 Intelligence and the US Department of State, on the safeguards concerning access to personal data by public authorities in the US Annual re-certification: Organisations must self re-certify their compliance with the requirements of the Privacy Shield to the Department of Commerce on (at least) an annual basis, and the Department is to monitor compliance with this requirement, and remove organisations that do not re-certify as required from the Privacy Shield List. The assessment and verification requirements were not as clear under Safe under that regime, an organisation was required to sign a statement verifying that a selfassessment had been carried out once a year. Annual Joint Review Mechanism: A major advantage of the Privacy Shield over the Safe framework is that there is an in-built Annual Joint Review mechanism, to review the functioning of the Privacy Shield on an annual basis. This annual review is to be performed by the Commission, the US Department of Commerce and the Federal Trade Commission, together with other relevant stakeholders such as Intelligence Community Representatives and the Privacy Shield Ombudsperson, as appropriate. It will also be open to EU DPAs and representatives of the Article 29 Working Party to participate in this review meeting. This means that the Privacy Shield is intended to be a living instrument, which can adapt as required to reflect future developments in privacy law. Indeed, the decision specifically states that the Commission will assess the level of protection provided by the Privacy Shield following the entry into application of the General Data Protection Regulation (in May 2018). By contrast, Safe only provided for a review to be carried out by the Commission after three years. Privacy Shield, whilst not perfect, is a viable option for transfers Whilst it is arguable that some of the criticism levied at the Privacy Shield may be justified for example, it may be difficult in reality to fully monitor the access US intelligence agencies may have to EU data transferred under the Privacy Shield - it should also be remembered that the Privacy Shield is relevant to personal data that was originally collected in accordance with EU data protection law. As such, data subjects should have been informed of any further processing of their personal data (including any processing in the US) at the time of collection, and any such processing should be compatible with the purposes for which the data were originally collected. Furthermore, any analysis of the Shield needs to take into account, from a realistic and practical standpoint, the reality that managing data transfers in today s global business environment can present significant challenges for organisations. It is also worth bearing in mind that the other currently approved exemptions to the prohibition on the transfer of personal data outside of the EEA, such as obtaining data subjects consent, entering into data transfer agreements based on the EU Commission approved Model Clauses, or putting in place binding corporate rules, can also present challenges to implementation in practice. In light of the matters considered above, it seems fair to conclude that the Privacy Shield represents a marked improvement on the Safe framework. As such, as organisations weigh up the various options around the transfer of personal data to the United States, the Privacy Shield would appear to represent a viable solution. 4 mccann fitzgerald ¼ october 2016

5 Further information Paul Lavery Partner, Head of Technology & Innovation Group ddi mccannfitzgerald.com Lorraine Power Senior Associate, Technology & Innovation Group ddi mccannfitzgerald.com Alternatively, your usual contact in McCann FitzGerald will be happy to help you further. This document is for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed. Principal Office Riverside One Sir John Rogerson s Quay Dublin 2 D02 X576 Tel: London Tower 42 Level 38C 25 Old Broad Street London EC2N 1HQ Tel: New York Tower West 45th Street 19th Floor New York, NY Brussels 40 Square de Meeûs 1000 Brussels Tel: Tel: inquiries@mccannfitzgerald.com McCann FitzGerald, October

The Unlimited Company

The Unlimited Company companies bill act 2014 2012 The Companies Act 2014 (the Act ) will come into effect on 1 June 2015 and will introduce significant reforms in company law in Ireland. The Act has since then been amended

More information

The Risk Manager. Additional Resources. The Latest News on Managing Your Risk. May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS

The Risk Manager. Additional Resources. The Latest News on Managing Your Risk. May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS The Risk Manager The Latest News on Managing Your Risk May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS By Beata Aldridge The new Privacy Shield and other proposed changes to European

More information

10 Things You Need to Know About the Gambling Control Bill 2013

10 Things You Need to Know About the Gambling Control Bill 2013 to Know About the Gambling Control Bill briefing TOP 50 INNOVATIVE LAWYERS 2016 Background and Introduction The general scheme of what the heads of the (the Scheme ) would look like was first published

More information

Exploiting Intellectual Property Rights: Key Attractions of Locating Operations in Ireland

Exploiting Intellectual Property Rights: Key Attractions of Locating Operations in Ireland Locating Operations in briefing Many of the leading global corporates in the technology, pharma, medical devices, biotech and other sectors involved in the commercialisation of intellectual property have

More information

Privacy Source EU-U.S. Privacy Shield Passes First Annual Review

Privacy Source EU-U.S. Privacy Shield Passes First Annual Review Privacy Source EU-U.S. Privacy Shield Passes First Annual Review Privacy Shield, the EU-U.S. data transfer agreement used by over 2,400 companies, recently passed its first annual review. This means the

More information

Privacy Shield Notice

Privacy Shield Notice PRIVACY SHIELD NOTICE Fidelity National Information Services, Inc. ( FIS ) created this ( Notice ) to help you learn about how we handle Personal Data transferred to FIS in the United States from the European

More information

Inteum EU or Switzerland Safe Harbor Policy

Inteum EU or Switzerland Safe Harbor Policy Inteum EU or Switzerland Safe Harbor Policy EU or Switzerland Safe Harbor Policy Inteum (hereinafter the "Company") respects individual privacy and values the confidence of their customers, employees,

More information

The Designated Activity Company (the DAC )

The Designated Activity Company (the DAC ) companies act 2014 The Companies Act 2014 (the Act ) will come into effect on 1 June 2015 and will introduce significant reforms in company law in Ireland. Under the Act, an existing private company limited

More information

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M.

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M. Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST Featured Speakers Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M. David Marchese Attorney, Member, Moore & Van Allen, PLLC, USA Rechtsanwältin

More information

Company Secretarial and Compliance Services Expertise

Company Secretarial and Compliance Services Expertise Company Secretarial and Compliance Services Expertise mccannfitzgerald.com expertise company secretarial and compliance services With almost 550 people, including over 350 lawyers and professional staff,

More information

Issues for Directors. companies act 2014

Issues for Directors. companies act 2014 companies act 2014 The Companies Act 2014 (the Act ) came into effect on 1 June 2015 and has introduced significant reforms in company law in Ireland. Under the terms of the Act, directors of every Irish

More information

Employee Share Incentive Schemes October 2017

Employee Share Incentive Schemes October 2017 briefing Employee Share Incentive Schemes October 2017 Employers are increasingly looking for methods to retain key talent and reward employees. Employee share incentive schemes which offer a tax saving

More information

DDB. EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy

DDB. EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy DDB EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: April 10, 2018 DDB Worldwide Communications Group Inc. and its affiliates TLP, Inc. (d/b/a Tracy Locke), Interbrand Corporation and

More information

Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: November 29, 2017 Geomni, Inc. ( Geomni ) respects your concerns about privacy. Geomni participates in the EU- U.S. Privacy Shield

More information

Ximedica, LLC Privacy Shield Policy

Ximedica, LLC Privacy Shield Policy Ximedica, LLC Privacy Shield Policy This Privacy Shield Policy (the " Policy ") sets forth the privacy principles that Ximedica ( the Company ) follows with respect to transfers of personal information

More information

TIFFANY AND COMPANY: EU-U.S. PRIVACY SHIELD PRIVACY POLICY - CONSUMER DATA

TIFFANY AND COMPANY: EU-U.S. PRIVACY SHIELD PRIVACY POLICY - CONSUMER DATA Last Updated: September 20, 2016 Tiffany and Company ( Tiffany ) respects your concerns about privacy. Tiffany participates in the EU-U.S. Privacy Shield ( Privacy Shield ) framework issued by the U.S.

More information

The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: November 17, 2016 The Marketing Arm Inc. ( TMA ) respect your concerns about privacy. TMA participates in the EU-U.S.

More information

An Overview. the obligation on every "large company" 1 to establish an audit committee; provides for new types of company;

An Overview. the obligation on every large company 1 to establish an audit committee; provides for new types of company; 2014 An Overview companies act 2014 The 2014 (the Act ) came into effect on 1 June 2015 and has introduced significant reforms in company law in Ireland. Some provisions of the Act will not apply to a

More information

Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data

Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data Last Updated: September 28, 2016 Fitbit, Inc. ( Fitbit ) respects your concerns about privacy. Fitbit participates in the EU-U.S. Privacy

More information

Working Party on the Protection of Individuals with regard to the Processing of Personal Data

Working Party on the Protection of Individuals with regard to the Processing of Personal Data EUROPEAN COMMISSION DIRECTORATE GENERAL XV Internal Market and Financial Services Free movement of information, company law and financial information Free movement of information and data protection, including

More information

Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR)

Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR) Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty Overview of the EU General Data Protection Regulation (GDPR) WHAT YOU NEED TO KNOW ABOUT THE EU GENERAL DATA PROTECTION REGULATION (GDPR) What is the GDPR?

More information

DRAFT MOTION FOR A RESOLUTION

DRAFT MOTION FOR A RESOLUTION European Parliament 2014-2019 Committee on Civil Liberties, Justice and Home Affairs 2018/2645(RSP) 10.4.2018 DRAFT MOTION FOR A RESOLUTION to wind up the debate on the statement by the Commission pursuant

More information

Practising Law Institute: Privacy Shield Boot Camp

Practising Law Institute: Privacy Shield Boot Camp Practising Law Institute: Privacy Shield Boot Camp Substantive Differences Between Safe Harbor and Privacy Shield Panel 2 September 12, 2016 Baker & McKenzie LLP is a member firm of Baker & McKenzie International,

More information

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES ... 1 A. Ecolab s Commitment to Data Privacy... 3 B. Definitions... 3 C. Scope... 4 D. Data Privacy Principles... 4 E. Application of Local Law... 5 F. Human Resources Data Collected... 6 G. Purposes of

More information

COMMISSION OF THE EUROPEAN COMMUNITIES

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, COMMISSION DECISION of pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the Safe

More information

ROSETTA STONE LTD. PROCESSING ADDENDUM

ROSETTA STONE LTD. PROCESSING ADDENDUM ROSETTA STONE LTD. PROCESSING ADDENDUM This Data Processing Addendum (this DPA ) forms part of the order document(s) (each a Service Order ) and Services Agreement (collectively, the Agreement ), entered

More information

Customer means any EEA entity that registers for or purchases products or services from SDL or SDL EEA Entities.

Customer means any EEA entity that registers for or purchases products or services from SDL or SDL EEA Entities. SDL Inc. : EU-US Privacy Shield Notice Policy version: 1.01 Effective Date: 26 September 2016 The SDL Group of companies is an international commercial organization which due to the nature of modern business

More information

BREXIT AND DATA PROTECTION Q & A

BREXIT AND DATA PROTECTION Q & A BREXIT AND DATA PROTECTION Q & A What happens now? The UK decision to leave the EU will not affect existing data protection and privacy laws in the UK. These laws (the UK Data Protection Act 1998 (DPA)

More information

Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018)

Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018) Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018) Once fully executed, this DPA forms a part of the agreement

More information

The Allied Group Privacy Shield Policy

The Allied Group Privacy Shield Policy The Allied Group Privacy Shield Policy The Allied Group, Inc. ("Allied") has adopted this Privacy Shield Policy ("Policy") to establish and maintain an adequate level of Personal Data privacy protection.

More information

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING PAPER

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING PAPER COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 13.02.2002 SEC(2002) 196 COMMISSION STAFF WORKING PAPER The application of Commission Decision 520/2000/EC of 26 July 2000 pursuant to Directive 95/46 of

More information

Data protection and transfer

Data protection and transfer Brexit Quick Brief #5 Data protection and transfer Key points The movement of personal data between locations is an integral part of modern banking operations. Financial services firms store and process

More information

The European Court of Justice Invalidated EU/US Safe Harbor: What Does the Future Hold?

The European Court of Justice Invalidated EU/US Safe Harbor: What Does the Future Hold? Association of Corporate Counsel NJ and Lowenstein Sandler LLP The European Court of Justice Invalidated EU/US Safe Harbor: What Does the Future Hold? Presented by: November 20, 2015 Mary J. Hildebrand,

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM This Data Processing Addendum (the DPA ) forms part of Telia Bedriftsavtale or other written or electronic agreement between the Parties for the purchase of telecommunication services, and regulates any

More information

Standard contractual clauses for the transfer of personal data to third countries - Frequently asked questions

Standard contractual clauses for the transfer of personal data to third countries - Frequently asked questions MEMO/05/3 Brussels, 7 January 2005 Standard contractual clauses for the transfer of personal data to third countries - Frequently asked questions Directive 95/46/EC, on the protection of individuals with

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) is made between Cognito, LLC., a South Carolina corporation ( Cognito Forms ) and {OrganizationLegalName} ( Customer or Controller or {Organization}

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum This Data Processing Addendum ( DPA ) forms part of the Agreement(s) and is entered by and between the Customer and the Service Provider on the Effective Date. For the avoidance

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the Master Purchase Agreement, Customer Agreement, Channel Partner Agreement, End User License Agreement or other written agreement

More information

Amgen Binding Corporate Rules (BCRs) Public Document

Amgen Binding Corporate Rules (BCRs) Public Document Amgen Binding Corporate Rules (BCRs) Public Document Introduction: Amgen is a biotechnology leader committed to serving patients with grievous illness. Binding Corporate Rules (BCRs) express Amgen s commitment

More information

Effective flow of personal data post-brexit

Effective flow of personal data post-brexit Effective flow of personal data post-brexit Implications for capital markets April 2018 Association for Financial Markets in Europe www.afme.eu GDPR Background Contents Executive Summary... 3 1 GDPR Background...

More information

Data Processing Appendix

Data Processing Appendix Company Name* Execution Date *Company name indicated must conform to the name on customer s Master Subscription Agreement executed with SugarCRM. This Data Processing Appendix on the processing of personal

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM Page 1 of 20 DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Customer Terms of Service found at https://slack.com/terms-of-service, unless Customer has entered into a

More information

EU U.S. Privacy Shield First annual Joint Review

EU U.S. Privacy Shield First annual Joint Review ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 255 EU U.S. Privacy Shield First annual Joint Review Adopted on 28 November 2017 This Working Party was set up under Article 29 of Directive 95/46/EC.

More information

GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers

GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers Area 1 Security, Inc. 142 Stambaugh Street Redwood City, CA 94063 EU GDPR DPA GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers Who should execute this DPA: If you qualify

More information

Data protection clauses in commercial contracts. Amy Chandler & Paul Jonson

Data protection clauses in commercial contracts. Amy Chandler & Paul Jonson Data protection clauses in commercial contracts Amy Chandler & Paul Jonson Data controller/data processor 1. A company engages a payroll company to process payslips and make payments to its employees.

More information

Moxtra, Inc. DATA PROCESSING ADDENDUM

Moxtra, Inc. DATA PROCESSING ADDENDUM Moxtra, Inc. DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Terms of Service found at http://moxtra.com/terms-of-service/, unless Company has entered into a superseding

More information

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES EMPLOYEE NOTICE OF DATA PRIVACY POLICIES TABLE OF CONTENTS A. Ecolab s Commitment to Data Privacy... 2 B. Definitions... 2 C. Scope... 3 D. Application of Local Law... 3 E. Employee Data Collected... 3

More information

Data Privacy Group Client Alert: The UK Votes for Brexit Data Protection Implications

Data Privacy Group Client Alert: The UK Votes for Brexit Data Protection Implications 24 JUNE, 2016 CONTACT Joel Harrison Partner +44-20-7615-3051 jharrison@milbank.com Data Privacy Group Client Alert: The UK Votes for Brexit Data Protection Implications The outcome of yesterday s referendum

More information

Note: Changes from Commission Decision 2002/16/EC are marked in redline

Note: Changes from Commission Decision 2002/16/EC are marked in redline Note: Changes from Commission Decision 2002/16/EC are marked in redline Commission Decision of 27 December 20015 February 2010 on standard contractual clauses for the transfer of personal data to processors

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement ( DPA or Agreement ), entered into by the CPI customer identified on the applicable CPI services agreement for CPI services ( Customer ) and the

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Databricks Terms of Service found at https://www.databricks.com/termsofservice, unless Subscriber has entered into a superseding

More information

Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy. May 2018

Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy. May 2018 Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy May 2018 Vanguard Group (Ireland) Limited (the Manager ), Vanguard Funds plc ( VF ), and Vanguard Investment

More information

Pension Trustees. Final Countdown to the GDPR

Pension Trustees. Final Countdown to the GDPR Pension Trustees Final Countdown to the GDPR Introduction The General Data Protection Regulation (GDPR) will come into force in all EU Member States in May 2018. It is not a radical departure from the

More information

A New Regulatory Framework for Credit Servicing Firms in Ireland

A New Regulatory Framework for Credit Servicing Firms in Ireland September 2015 A New Regulatory Framework for Credit Servicing Firms in Ireland Background For further information on any of the issues discussed in this article please contact: The Consumer Protection

More information

Account Opening Application CHILD BOND SAVINGS

Account Opening Application CHILD BOND SAVINGS Account Opening Application CHILD BOND SAVINGS 2 P a g e TERMS AND CONDITIONS FOR ACCOUNTS Updated May 2016 1 Application These Terms & Conditions apply to all Accounts, except where explicitly defined

More information

URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses. (Revised September 2017)

URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses. (Revised September 2017) URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses (Revised September 2017) This Data Processing Addendum ( Addendum ) forms part of the Master Subscription Agreement or the online

More information

TPAS AND THE FREEDOM OF INFORMATION ACT 2000

TPAS AND THE FREEDOM OF INFORMATION ACT 2000 TPAS AND THE FREEDOM OF INFORMATION ACT 2000 THE PENSIONS ADVISORY SERVICE TPAS has been providing information and guidance to members of the public on all aspects of pension provision since 1983. We provide

More information

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT EN EN EN COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 20.10.2004 SEC (2004) 1323 COMMISSION STAFF WORKING DOCUMENT The implementation of Commission Decision 520/2000/EC on the adequate protection of

More information

The Old Post Office, 4 Bryanston, Blandford, DT11 0PR t: e:

The Old Post Office, 4 Bryanston, Blandford, DT11 0PR t: e: . The Old Post Office, 4 Bryanston, Blandford, DT11 0PR t: 0800 368 8163 e: info@gfp-uk.com www.gfp-uk.com GFP UK is a trading style of Goodale Financial Partners Limited which is an appointed representative

More information

Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team

Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team The University of Nottingham ( the University ) Tri-Campus Data Transfer Policy Background and Statement of

More information

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software The Controller and Processor Data Protection Binding Corporate Rules of BMC Software 4 August 2015 Table of Contents Introduction 2 PART I: BACKGROUND AND ACTIONS 3 PART II: BMC AS A CONTROLLER 5 PART

More information

Government Legislation Programme: Overview

Government Legislation Programme: Overview briefing in detail, inside: Company Law 2 Financial Services 2 Planning & Environment 3 On 8 June 2016 the Government published its Programme for the new parliamentary term. This briefing highlights the

More information

Interoperability effort between APEC CBPR and EU BCR. Malcolm Crompton Managing Director, IIS Google Japan Tokyo, 17 April 2014

Interoperability effort between APEC CBPR and EU BCR. Malcolm Crompton Managing Director, IIS Google Japan Tokyo, 17 April 2014 Interoperability effort between APEC CBPR and EU BCR Malcolm Crompton Managing Director, IIS Google Japan Tokyo, 17 April 2014 Privacy laws are proliferating 40 35 30 25 20 15 10 5 0 Cross-border data

More information

Safe Harbor and Data Privacy Statement

Safe Harbor and Data Privacy Statement Safe Harbor and Data Privacy Statement Introduction Paragon is a professional services firm providing process design, early case assessment, electronic discovery, consulting and archive services to law

More information

AWS GDPR DATA PROCESSING ADDENDUM

AWS GDPR DATA PROCESSING ADDENDUM AWS GDPR DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) is an agreement between Amazon Web Services, Inc. ( AWS, we, us, or our ) and you or the entity you represent ( Customer, you or

More information

Financial Planning Limited. Terms Of Business

Financial Planning Limited. Terms Of Business Financial Planning Limited Terms Of Business Andrew Adviser. ABC Financial Planning Limited 1 Street. Town, County SN1 1SD. ABC Financial Planning Limited is an Appointed Representative of Intrinsic Financial

More information

DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses)

DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses) DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses) This Data Processing Agreement ("DPA") forms part of the Master Services and Subscription Agreement between Customer and

More information

Brexit Essentials: an update on data protection and privacy

Brexit Essentials: an update on data protection and privacy Brexit Essentials: an update on data protection and privacy November 2017 With the United Kingdom set to withdraw from the European Union on 29 March 2019, the Ministry for Brexit faces a critical juncture

More information

Increased Corporate Governance Requirements for Insurers

Increased Corporate Governance Requirements for Insurers Increased Corporate Governance Requirements for Insurers 0 INCREASED CORPORATE GOVERNANCE REQUIREMENTS FOR INSURERS Introduction On 17 December 2009, the definitive text of the Solvency II Directive (2009/138/EC)

More information

Even If You Are a U.S. Company, Don t Ignore the GDPR: Complying with the EU s New Data Privacy Law

Even If You Are a U.S. Company, Don t Ignore the GDPR: Complying with the EU s New Data Privacy Law Even If You Are a U.S. Company, Don t Ignore the GDPR: Complying with the EU s New Data Privacy Law On May 25, 2018, the European Union (EU)'s General Data Protection Regulation (GDPR) comes into force,

More information

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THIS PROTOCOL is dated 2018 BETWEEN (1) The Chancellor, Masters, and Scholars of the University of Cambridge of The Old Schools,

More information

Proposed amendments to Telecommunications Consumer Protections Code (DR C628:2015)

Proposed amendments to Telecommunications Consumer Protections Code (DR C628:2015) 28 July 2015 Mr John Stanton Chief Executive Officer Communications Alliance Limited PO Box 444 MILSONS POINT NSW 1565 Dear Mr Stanton Proposed amendments to Telecommunications Consumer Protections Code

More information

ON24 DATA PROCESSING ADDENDUM

ON24 DATA PROCESSING ADDENDUM ON24 DATA PROCESSING ADDENDUM This Data Processing Addendum ( Addendum ) is entered into by and between ON24 Inc., on behalf of itself and its Affiliates ( ON24 ), and Client, on behalf of itself and its

More information

ESMA s Brexit Reminder

ESMA s Brexit Reminder June 1, 2017 ESMA s Brexit Reminder Although most Brexit related media coverage of the financial services sector has focused to date on banking, on insurance and on market infrastructure issues post-divorce,

More information

Data Protection Cayman Islands

Data Protection Cayman Islands Data Protection Cayman Islands Author: Martin S. Lane, Partner In June 2017, The Data Protection Law (the DP Law ) was published in the Cayman Islands Official Gazette. The DP Law will be brought into

More information

THE IRON MOUNTAIN GDPR JARGON BUSTER

THE IRON MOUNTAIN GDPR JARGON BUSTER THE IRON MOUNTAIN GDPR JARGON BUSTER DON T KNOW YOUR BCRS FROM YOUR DPOS? IF SO, YOU RE NOT ALONE. The new EU General Data Protection Regulation (GDPR for short, and yet another set of initials you ll

More information

DATA PROCESSING ADENDUM

DATA PROCESSING ADENDUM W www.exponea.com C +421 948 127 332 sales@exponea.com A Exponea, Twin City B, Mlynské Nivy 12 821 09 Bratislava, SK DATA PROCESSING ADENDUM Exponea s.r.o. registered in the Commercial Register maintained

More information

UNFAIR CONTRACT TERMS REGULATORY GUIDE INSTRUMENT 2007

UNFAIR CONTRACT TERMS REGULATORY GUIDE INSTRUMENT 2007 FSA 2007/50 UNFAIR CONTRACT TERMS REGULATORY GUIDE INSTRUMENT 2007 Powers exercised A. The Financial Services Authority makes this instrument in the exercise of the power in section 157(1) (Guidance) of

More information

ARTICLE 29 Data Protection Working Party

ARTICLE 29 Data Protection Working Party ARTICLE 29 Data Protection Working Party Brussels, 11th April 2018 Mr Clemens-Martin Auer e-health Network Member State co-chair Director General Federal Ministry of Health, Austria Subject: Agreement

More information

Guide to compliance with the Australian Privacy Principles. APP 1 Open and transparent management of personal information

Guide to compliance with the Australian Privacy Principles. APP 1 Open and transparent management of personal information Guide to compliance with the Australian Privacy Principles This guide provides a summary of each of the Australian Privacy Principles (APPs) prescribed under the Privacy Act 1988 (Cth), together with some

More information

STONE ROWE BREWER LLP TERMS OF BUSINESS

STONE ROWE BREWER LLP TERMS OF BUSINESS STONE ROWE BREWER LLP TERMS OF BUSINESS 1. Stone Rowe Brewer LLP Our services are provided to you by Stone Rowe Brewer LLP ( the LLP ) which is a limited liability partnership. The LLP has sole legal liability

More information

ADMIRAL MARKETS UK LTD PRIVACY POLICY

ADMIRAL MARKETS UK LTD PRIVACY POLICY ADMIRAL MARKETS UK LTD PRIVACY POLICY Valid as of 2nd of December 2016 1. GENERAL PROVISIONS 1.1 Definitions used in the procedure: Client means any natural or legal person who has entered into client

More information

Data Processing Agreement and Privacy Policy (EU) Classification: PUBLIC March 2018

Data Processing Agreement and Privacy Policy (EU) Classification: PUBLIC March 2018 1. PURPOSE AND SCOPE 1.1 This document sets out Fourth s Data Processing Agreement and Privacy Policy for its Customers with operations in the EU and/or who process Personal Data of data subjects located

More information

CONTENTS. KLRCA ARBITRATION RULES (As revised in 2017) UNCITRAL ARBITRATION RULES (As revised in 2013) SCHEDULES. Part I. Part II.

CONTENTS. KLRCA ARBITRATION RULES (As revised in 2017) UNCITRAL ARBITRATION RULES (As revised in 2013) SCHEDULES. Part I. Part II. CONTENTS Part I KLRCA ARBITRATION RULES (As revised in 2017) Part II UNCITRAL ARBITRATION RULES (As revised in 2013) Part III SCHEDULES Copyright of the KLRCA First edition MODEL ARBITRATION CLAUSE Any

More information

CONTENTS TOB.MP.INT.RES.6.0 2

CONTENTS TOB.MP.INT.RES.6.0 2 Terms Of Business {Name of adviser}. {Name of firm XXXX Ltd}. Address they will conduct business from. {Name of firm} is an Appointed Representative of {Intrinsic Mortgage Planning / Intrinsic Financial

More information

August Proposal for EMIR Reform targeted changes with important consequences for AIFs, AIFMs and UCITS Management Companies

August Proposal for EMIR Reform targeted changes with important consequences for AIFs, AIFMs and UCITS Management Companies August 2017 Proposal for EMIR Reform targeted changes with important consequences for AIFs, AIFMs and UCITS Management Companies Background to EMIR Reform On 4 May 2017, the European Commission (the Commission

More information

An Agreement dated XX/XX/XXXX governing the conduct of Insurance Business between:

An Agreement dated XX/XX/XXXX governing the conduct of Insurance Business between: Terms of Business Agreement (Non Risk Transfer) An Agreement dated XX/XX/XXXX governing the conduct of Insurance Business between: and Seacurus Ltd (SEAC) (UK Regulator registration number 435893) a Lloyd

More information

Visa Debit Conditions of Use

Visa Debit Conditions of Use Visa Debit Conditions of Use BEFORE YOU USE YOUR VISA CARD Please read these Conditions of Use. They apply to: all transactions initiated by you through an Electronic Banking Terminal (which in these Conditions

More information

Fees and Expiration. Replacement Card at Expiration : There is no additional cost to obtain a replacement Card due to expiration.

Fees and Expiration. Replacement Card at Expiration : There is no additional cost to obtain a replacement Card due to expiration. Visa or Mastercard Prepaid Gift Card Cardholder Agreement CUSTOMER SERVICE CONTACT INFORMATION: Address: 5501 S. Broadband Ln, Sioux Falls, SD 57108 Website: MyPrepaidBalance.com and My Prepaid App Phone

More information

British Bankers Association submission to the consultation on the legal framework for the fundamental right to protection of personal data

British Bankers Association submission to the consultation on the legal framework for the fundamental right to protection of personal data British Bankers Association submission to the consultation on the legal framework for the fundamental right to protection of personal data The BBA 1 is pleased to respond to the European Commission s consultation

More information

INTERNATIONAL SOS. Data Protection Policy. Version 1.8

INTERNATIONAL SOS. Data Protection Policy. Version 1.8 INTERNATIONAL SOS Data Protection Policy Document Owner: LCIS Division Document Manager: Group General Counsel Effective: December 2008 2017 All copyright in these materials are reserved to AEA International

More information

CUSTOMER DATA PROCESSING ADDENDUM

CUSTOMER DATA PROCESSING ADDENDUM CUSTOMER DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) and applicable Attachments apply when HP acts as a Data Processor and processes Customer Personal Data on behalf of Customer in order

More information

IRIS Group of Companies Customer Data Processing Terms

IRIS Group of Companies Customer Data Processing Terms IRIS Group of Companies Customer Data Processing Terms Definitions (any other capitalised terms not contained in this section will be as defined in the IRIS Software Group General Terms & Conditions (

More information

TFI Markets. Currency Specialists. Agreement between TFI Markets Ltd and Holders of Payment Accounts for the provision of Payment Services

TFI Markets. Currency Specialists. Agreement between TFI Markets Ltd and Holders of Payment Accounts for the provision of Payment Services TFI Markets Currency Specialists Agreement between TFI Markets Ltd and Holders of Payment Accounts for the provision of Payment Services These terms and conditions concern the execution of payment transactions

More information

Terms of Business- Direct Customers

Terms of Business- Direct Customers Terms of Business- Direct Customers Effective from 17th October 2018, these Terms of Business set out the basis on which Ecclesiastical Insurance Office Plc will provide insurance services to you They

More information

European Communities Takeover Bids Directive 2004 Regulations 2006

European Communities Takeover Bids Directive 2004 Regulations 2006 European Communities Takeover Bids Directive 2004 Regulations 2006 0 EUROPEAN COMMUNITIES (TAKEOVER BIDS (DIRECTIVE 2004/25/EC)) REGULATIONS 2006 Introduction The EU Takeovers Directive (2004/25/EC) (the

More information

Pension Trustees Final Countdown To GDPR

Pension Trustees Final Countdown To GDPR Pension Trustees Final Countdown To GDPR " ROBERT HANIVER SENIOR ASSOCIATE/TECHNOLOGY MASON HAYES & CURRAN " STEPHEN GILLICK PARTNER/PENSIONS MASON HAYES & CURRAN The General Data Protection Regulation

More information

Group Flexible Retirement Plan

Group Flexible Retirement Plan Group Flexible Retirement Plan Key features This is an important document. Please read it and keep it for future reference. Key features document: Pages 1 20 Terms and conditions for joining: Pages 21

More information

Customer GDPR Data Processing Agreement

Customer GDPR Data Processing Agreement Customer GDPR Data Processing Agreement This Customer Data Processing Agreement reflects the requirements of the European Data Protection Regulation ( GDPR ) as it comes into effect on May 25, 2018. Bench

More information

Central Bank consults on CFDs for Retail Investors

Central Bank consults on CFDs for Retail Investors March 2017 Central Bank consults on CFDs for Retail Investors The Central Bank has, on March 6, 2017, isssued Consultation Paper 107 (the CP ) on the protection of retail investors in relation to the distribution

More information