Overview of the EU - U.S. Privacy Shield Framework

Size: px
Start display at page:

Download "Overview of the EU - U.S. Privacy Shield Framework"

Transcription

1 Overview of the EU - U.S. Privacy Shield Framework CLIENT GUIDE May 2018 By Terry Ahearn & Stuart Bartow Cyber Security & Data Protection 4300 Bohannon Drive Suite 230 Menlo Park, CA

2 The EU - U.S. Privacy Shield Framework The privacy shield lays-out 7 privacy principles combined with 16 supplemental principles. The supplemental principles explain and supplement the seven principles. This framework has cleared the first review by E.U. leadership, but significant potential hurdles remain. 1. Purpose the privacy shield framework was designed to provide both US and EU companies with a mechanism to comply with data protection requirements when transferring personal data from the EU to the United States. The privacy shield replaces the former EU-US Safe Harbor promulgated in support of the former EU Directive on data transfers. 2. Administration the privacy shield is administered by the International Trade Administration (ITA) of the Department of Commerce. 3. Self-Certifying to join the privacy shield, a US company must self-certify to the Department of Commerce and publicly commit to comply with the framework. Once a US company has self-certified, the certification is enforceable under US law. 4. Enforcement US companies are required to implement independent recourse mechanisms, distinct from the Federal Trade Commission s authority to bring enforcement under Section 5, that are empowered to provide remedies. For example, PrivacyTrust provides a dispute resolution service. 5. Principles the privacy shield lays-out 7 privacy principles combined with 16 supplemental principles. The supplemental principles explain and supplement the seven principles. Notice must provide data subjects, in clear and conspicuous language, with: (1) notice of the US organization s participation in the privacy shield; (2) the type of data collected; and (3) the purposes for which the data is collected. Data subjects must be: (1) informed of any third parties to whom their data will be transferred; (2) their right to access their data; and (3) the means for limiting the use and disclosure of their personal data. The US organization must describe available recourse mechanisms and acknowledge the FTC s (or other statutory body s) enforcement authority. Choice US organizations must provide clear, conspicuous, and readily available mechanisms by which data subjects can opt-out of any disclosure of personal data to a third party or the use of personal data for a purpose other than the one for which it was initially collected. For sensitive personal data, including data related to health, racial or ethnic origin, political and religious opinions, trade union membership, or information revealing an individual s sex life, the data subject must affirmatively opt-in to allowing the US organization to disclose the information to a third party or use the information for a separate purpose. Accountability for Onward Transfer expands regulation of and accountability for third party personal data transfers. A certified US company must specify in third party contracts that transferred personal data may only be processed for limited and specified purposes consistent with the data subject s consent. Third parties must agree to provide the same level of protection as the principles. Where the third party is acting as an agent, such as a vendor, the organization must in addition take reasonable and appropriate steps to ensure the agent upholds the principles, including to stop and remediate any unauthorized processing. This downstream data protection accountability puts significant pressure on vendor selection and monitoring practices. A certified US company organization must provide the DOC with relevant third party contractual provisions, which place some restrictions on contractual confidentiality. Regardless of contractual language, moreover, a certified US company remains liable to the data subject for its vendor s violation of the principles, unless it proves that it is not responsible for the event giving rise to the damage.

3 Security participating US companies must take reasonable and appropriate measures to protect [data] from loss, misuse and unauthorized access, disclosure, alteration and destruction. These measures must be appropriate to the risks involved and the nature of the personal data. Data Integrity and Purpose Limitation requires that the personal data must be relevant for the purposes of processing and collection must be limited to only the relevant data. US companies must take reasonable steps to ensure that personal data is reliable for its intended use, accurate, complete, and current. Even if certification has lapsed, a certified US company remains bound by the principles when processing data collected. This presents significant data management issues for long-term data processing, including risk disclosures in merger and acquisition transactions. Access certified US companies must provide data subjects with access to their personal data as well as the opportunity to correct, amend, or delete information that is inaccurate or processed in violation of the principles. Sets out detailed rules for how US companies should comply with the access principle. US companies must provide data subjects the opportunity to confirm whether their personal data is being processed, as well as whether the data is accurate and whether the certified US company is processing it lawfully. US companies may charge a fee for access as long as it is not excessive, and US companies must respond to requests for access within a reasonable time and in a reasonable manner. A certified US company may restrict access to data in exceptional circumstances where the legitimate rights of persons other than the data subject would be violated or where the burden or expense of providing access would be disproportionate to the risks to the data subject s privacy. A US company may deny access where it could reveal confidential commercial information, such as trade secrets. US companies need not retain data merely to comply with access requests. Access may be restricted in a number of situations, including where disclosure would interfere with national security, defense, public security, or research. Recourse/Enforcement/Liability the privacy shield sets out three requirements for effective enforcement: (1) recourse for individuals to whom the data relates; (2) follow up procedures for verifying that the attestations and assertions they have made about their privacy practices are true; and (3) obligations to remedy problems arising out of failure to comply with the principles and consequences for such failures. US companies are required to implement independent recourse mechanisms, distinct from the FTC s authority to bring enforcement under Section 5, that are empowered to provide remedies. Privacy shield requires the use of third party dispute resolution bodies, based either in the US or the EU, to investigate and resolve complaints. US companies must respond to complaints within 45 days and provide resolution free of charge to data subjects. Alternatively, a US company may elect to appoint a panel of Data Protection Authorities (DPAs) from the EU Member States as the independent recourse mechanism. Supplemental Principles 1. Sensitive Data in certain situations, express consent (i.e. opt-in) is not required for the processing of sensitive data. But must meet an exception (e.g. necessary to legal claims or defenses). 2. Journalistic Exceptions personal data gathered for a journalistic purpose is not subject to the privacy shield principles. 3. Secondary Liability privacy shield does not create secondary liability. If an organization is merely a conduit for data transmitted by a third party, it would not be liable (e.g. ISPs).

4 4. Due Diligence and Audits activities of auditors and bankers may involve processing of data without the knowledge of the data subject. This is allowed under specific circumstances, specifically, when a public company is being audited or any company is engaged in a due diligence related to a merger and disclosure would threaten the purpose or possibly violate legal requirements. 5. Data Protection Authorities (DPAs) US companies must employ effective mechanisms for assuring compliance with the privacy shield. A US company can satisfy this requirement by adhering to the requirements set-forth in the privacy shield for cooperating with DPAs. This is done in the self-certification and a US$500 fee is required. 6. Self-Certification see above under principles. To join the privacy shield, a US company must self-certify to the Department of Commerce and publicly commit to comply with the framework. There is specific information to be provided under the self-certification. Once a US company has self-certified, the certification is enforceable under US law. 7. Verification US companies must have procedures in place to verify that the attestations and assertions they make about their privacy shield practices are true and those privacy practices have been implemented as represented and in accordance with the privacy shield. 8. Access see above under principles. Certified US companies must provide data subjects with access to their personal data as well as the opportunity to correct, amend, or delete information that is inaccurate or processed in violation of the principles. 9. Human Resources Data privacy shield creates separate rules for transferring human resources data in order to ensure compliance with labor laws in the Member States. Employers generally must comply with the privacy shield s notice and choice requirements, but they may be exempt from the access requirement in the case of employee security investigations, grievance proceedings, corporate reorganizations, or where it may prejudice sound management. The employer may transfer human resources data only where a U.S. agency has jurisdiction to hear claims against the organization arising out of the processing of employee data. Finally, the employer must provide the Department of Commerce with a copy of its human resources privacy policy. 10. Obligatory Contracts for Onward Transfers see above principles. A certified US company must specify in third party contracts that transferred personal data may only be processed for limited and specified purposes consistent with the data subject s consent. Third parties must agree to provide the same level of protection as the principles. 11. Dispute Resolution Enforcement privacy shield requires the use of third party dispute resolution bodies, based either in the US or the EU, to investigate and resolve complaints. US companies must respond to complaints within 45 days and provide resolution free of charge to data subjects. Alternatively, a US company may elect to appoint a panel of Data Protection Authorities (DPAs) from the EU Member States as the independent recourse mechanism. 12. Choice/Timing of Opt-Out see above under principles. A data subject should be able to exercise an opt out choice of having personal data used for direct marketing at any time subject to reasonable limits established by the US company, such as giving the US company time to make the opt out effective. In the United States, individuals may be able to exercise this option through the use of a central opt out program (e.g. Direct Marketing Association s Mail Preference Service). Data subjects should be given a readily available and affordable mechanism to exercise this option. A US company may use information for certain direct marketing purposes when it is impracticable to provide the data subject with an opportunity to opt out before using the information, if the US company promptly gives the data subject such opportunity at the same time (and upon request at any time) to decline (at no cost to the individual) to receive any further direct marketing communications and the US company complies with the data subject s wishes.

5 13. Travel Information travel information, such as frequent flyer or hotel reservation information and special handling needs, such as meals to meet religious requirements or physical assistance, may be transferred to US companies located outside the EU in several different circumstances. US companies subscribing to the privacy shield provide adequate protection for personal data and may therefore receive data transfers from the EU without meeting the circumstances laid-out in the GDPR. 14. Pharmaceutical and Medical Products data used for pharmaceutical research and other purposes should be anonymized where appropriate. Specific requirements and exceptions apply to personal data used: (1) in future scientific research; (2) after withdrawal from a clinical trial; (3) in transfers for regulatory or supervision purposes; (4) in blinded studies; and (5) in product safety and efficacy. Key-Coded Data is not personal data subject to the privacy shield. 15. Public Record and Publicly Available Information the privacy principles do not apply to public record information as long as it is not combined with non-public information. 16. Access Requests by Public Authorities US companies may voluntarily issue periodic transparency reports on the number of requests for personal data they receive from public authorities for law enforcement or national security reasons, to the extent such disclosures are permissible under applicable law. Absence of notice in accordance with the privacy shield shall not prevent or impair US company s ability to respond to any lawful request. Sources and Resources U.K. Information Commissioner s Office ( Int l Assoc. Privacy Professionals ( TeachPrivacy.com Department of Commerce U.S. Privacy Shield Framework (

6 Firm Overview Lewis Roca is a premier U.S.-based law firm, serving clients from around the world in complex litigation, intellectual property, business transactions, labor and employment, regulatory counseling, and government relations. More than 275 lawyers strong, we are large enough to handle virtually any matter, no matter how sophisticated, but small enough to preserve our culture of legal excellence and exceptional client service. Our firm is built on a rich history of difficult cases won by distinguished lawyers. For decades, we have been at the forefront of legal change in intellectual property, business regulations, land use, technology, and civil rights. Our prominent alumni include presidential advisors, federal appellate judges, and renowned legal scholars. Why Lewis Roca? Distinguished History of Legal Excellence Dedicated to Outstanding Client Service Exceptional Practice & Industry Expertise Depth and Continuity of Client Relationships Commitment to Diversity & Inclusiveness Although we embrace and celebrate our history, we continue to redefine ourselves each day by the strength of our client relationships and service. We pride ourselves on our ability to deliver for our clients while serving their highest goals and needs. Silicon Valley Albuquerque Irvine Los Angeles Phoenix Tucson Denver Colorado Reno Springs Las Vegas

7 About Us Stuart Bartow Partner Silicon Valley Stuart Bartow is a partner in Lewis Roca Rothgerber Christie s Intellectual Property practice group, and is comanaging partner of the Silicon Valley office. Stuart is a trial lawyer and experienced litigator with months worth of trial days in federal courts and other tribunals, both in the United States and internationally. As a dual-qualified U.S. patent attorney and English solicitor, he represents clients from around the globe in intellectual property and privacy matters, with an emphasis on complex disputes concerning high technology. Education J.D., Georgetown University Law Center M.S., Columbia University B.S., B.S.E.E., University of Maryland, College Park Bar Admissions California Terry Ahearn Partner Silicon Valley TAhearn@lrrc.com Terry is a partner in Lewis Roca Rothgerber Christie s Intellectual Property practice group and is comanaging partner of the Silicon Valley office. Terry is a trial lawyer and represents clients in intellectual property and other complex commercial litigation related to high technology. Terry has significant experience managing major complex patent litigation, including management of electronic data in large, cross-border litigations. Terry is also certified CIPP/ US by the International Association of Privacy Professionals. Terry regularly counsels clients in the area of data privacy and cybersecurity Education J.D., Santa Clara University School of Law B.A., cum laude, Fordham University Bar Admissions California Richard K. Clark Partner Denver RClark@lrrc.com Dick Clark has more than 40 years of experience as a business lawyer emphasizing international trade, investment and finance. He offers legal advice to public companies and small and large private companies, both domestic and foreign. Mr. Clark has successfully handled international transactions and resolved international disputes involving complex issues such as export controls, import duties and tariffs, distribution agreements and networks, foreign manufacturing and fabrication, theft of trade secrets, antidumping issues, product liability claims, international financing arrangements, mergers and acquisitions, entity selection, contract rights and remedies, transfer pricing, internet and website issues, infringement of trademarks and patents, foreign trade zones, and treaty application disputes. Education J.D., University of South Dakota School of Law, 1969 B.A., University of South Dakota, 1966 Bar Admissions Colorado

8 Copyright 2018 Lewis Roca Rothgerber Christie LLP, All rights reserved. These materials have been prepared by Lewis Roca Rothgerber Christie LLP for general informational purposes only. These materials do not, and are not intended to, constitute legal advice. The information provided in this document is not privileged and does not create an attorney-client relationship with Lewis Roca Rothgerber Christie or any of the firm s lawyers.

Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Geomni, Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: November 29, 2017 Geomni, Inc. ( Geomni ) respects your concerns about privacy. Geomni participates in the EU- U.S. Privacy Shield

More information

The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy

The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy The Marketing Arm Inc. EU-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: November 17, 2016 The Marketing Arm Inc. ( TMA ) respect your concerns about privacy. TMA participates in the EU-U.S.

More information

Customer means any EEA entity that registers for or purchases products or services from SDL or SDL EEA Entities.

Customer means any EEA entity that registers for or purchases products or services from SDL or SDL EEA Entities. SDL Inc. : EU-US Privacy Shield Notice Policy version: 1.01 Effective Date: 26 September 2016 The SDL Group of companies is an international commercial organization which due to the nature of modern business

More information

Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data

Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data Fitbit, Inc.: EU-U.S. Privacy Shield Privacy Policy - Consumer Data Last Updated: September 28, 2016 Fitbit, Inc. ( Fitbit ) respects your concerns about privacy. Fitbit participates in the EU-U.S. Privacy

More information

Inteum EU or Switzerland Safe Harbor Policy

Inteum EU or Switzerland Safe Harbor Policy Inteum EU or Switzerland Safe Harbor Policy EU or Switzerland Safe Harbor Policy Inteum (hereinafter the "Company") respects individual privacy and values the confidence of their customers, employees,

More information

Ximedica, LLC Privacy Shield Policy

Ximedica, LLC Privacy Shield Policy Ximedica, LLC Privacy Shield Policy This Privacy Shield Policy (the " Policy ") sets forth the privacy principles that Ximedica ( the Company ) follows with respect to transfers of personal information

More information

DDB. EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy

DDB. EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy DDB EU/Swiss-U.S. Privacy Shield: Consumer Privacy Policy Last Updated: April 10, 2018 DDB Worldwide Communications Group Inc. and its affiliates TLP, Inc. (d/b/a Tracy Locke), Interbrand Corporation and

More information

TIFFANY AND COMPANY: EU-U.S. PRIVACY SHIELD PRIVACY POLICY - CONSUMER DATA

TIFFANY AND COMPANY: EU-U.S. PRIVACY SHIELD PRIVACY POLICY - CONSUMER DATA Last Updated: September 20, 2016 Tiffany and Company ( Tiffany ) respects your concerns about privacy. Tiffany participates in the EU-U.S. Privacy Shield ( Privacy Shield ) framework issued by the U.S.

More information

Privacy Shield Notice

Privacy Shield Notice PRIVACY SHIELD NOTICE Fidelity National Information Services, Inc. ( FIS ) created this ( Notice ) to help you learn about how we handle Personal Data transferred to FIS in the United States from the European

More information

The Risk Manager. Additional Resources. The Latest News on Managing Your Risk. May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS

The Risk Manager. Additional Resources. The Latest News on Managing Your Risk. May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS The Risk Manager The Latest News on Managing Your Risk May 2016 INCREASED LIABILITY IN THE FACE OF UNCERTAIN DATA REGULATIONS By Beata Aldridge The new Privacy Shield and other proposed changes to European

More information

Safe Harbor and Data Privacy Statement

Safe Harbor and Data Privacy Statement Safe Harbor and Data Privacy Statement Introduction Paragon is a professional services firm providing process design, early case assessment, electronic discovery, consulting and archive services to law

More information

Enforcing a Mechanics Lien in Nevada

Enforcing a Mechanics Lien in Nevada Prepared by John E. Bragonje Lewis Roca Rothgerber Christie LLP 3993 Howard Hughes Parkway, Suite 600 Las Vegas, Nevada 89169 jbragonje@lrrc.com (702) 474-2625 Enforcing a Mechanics Lien in Nevada This

More information

Practising Law Institute: Privacy Shield Boot Camp

Practising Law Institute: Privacy Shield Boot Camp Practising Law Institute: Privacy Shield Boot Camp Substantive Differences Between Safe Harbor and Privacy Shield Panel 2 September 12, 2016 Baker & McKenzie LLP is a member firm of Baker & McKenzie International,

More information

ROSETTA STONE LTD. PROCESSING ADDENDUM

ROSETTA STONE LTD. PROCESSING ADDENDUM ROSETTA STONE LTD. PROCESSING ADDENDUM This Data Processing Addendum (this DPA ) forms part of the order document(s) (each a Service Order ) and Services Agreement (collectively, the Agreement ), entered

More information

The Allied Group Privacy Shield Policy

The Allied Group Privacy Shield Policy The Allied Group Privacy Shield Policy The Allied Group, Inc. ("Allied") has adopted this Privacy Shield Policy ("Policy") to establish and maintain an adequate level of Personal Data privacy protection.

More information

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M.

Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST. Featured Speakers. Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M. Globalaw-MCI Webinar Tuesday, 12 July at 4 pm CEST Featured Speakers Karin McGinnis Susanne Klein LL.M. Dr. Benno Barnitzke LL.M. David Marchese Attorney, Member, Moore & Van Allen, PLLC, USA Rechtsanwältin

More information

HSBC Privacy code. Everything you need to know about the security and privacy of your personal information at HSBC

HSBC Privacy code. Everything you need to know about the security and privacy of your personal information at HSBC HSBC Privacy code Everything you need to know about the security and privacy of your personal information at HSBC HSBC Privacy Code Table of Contents Protecting Personal Information 1 Scope 1 Ten Privacy

More information

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES ... 1 A. Ecolab s Commitment to Data Privacy... 3 B. Definitions... 3 C. Scope... 4 D. Data Privacy Principles... 4 E. Application of Local Law... 5 F. Human Resources Data Collected... 6 G. Purposes of

More information

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software The Controller and Processor Data Protection Binding Corporate Rules of BMC Software 4 August 2015 Table of Contents Introduction 2 PART I: BACKGROUND AND ACTIONS 3 PART II: BMC AS A CONTROLLER 5 PART

More information

What U.S.- Based Investment Advisers Should Know

What U.S.- Based Investment Advisers Should Know BulletPoint June 2018 What U.S.- Based Investment Advisers Should Know The European Union s ( EU ) General Data Protection Regulation (the GDPR ) became effective on May 25, 2018, and provides individuals

More information

Bobbie J. Collins. Associate. P / F

Bobbie J. Collins. Associate. P / F Bobbie J. Collins Associate P 719.386.3016 / F 719.386.3070 bcollins@lrrc.com Colorado Springs / 90 South Cascade Avenue, Suite 1100, Colorado Springs, CO 80903 Bobbie Collins assists clients with a variety

More information

BINDING CORPORATE RULES

BINDING CORPORATE RULES BINDING CORPORATE RULES CONTROLLER PRINCIPLES INTRODUCTION At Marsh & McLennan Companies (MMC), we respect and are committed to protecting the privacy, security and integrity of Personal Information 1

More information

CLOUDINARY DATA PROCESSING ADDENDUM

CLOUDINARY DATA PROCESSING ADDENDUM CLOUDINARY DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the agreement for the subscription by the Customer to the Cloudinary Service ("Subscription Agreement") between Cloudinary

More information

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING PAPER

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING PAPER COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 13.02.2002 SEC(2002) 196 COMMISSION STAFF WORKING PAPER The application of Commission Decision 520/2000/EC of 26 July 2000 pursuant to Directive 95/46 of

More information

INTERNATIONAL SOS. Data Protection Policy. Version 1.8

INTERNATIONAL SOS. Data Protection Policy. Version 1.8 INTERNATIONAL SOS Data Protection Policy Document Owner: LCIS Division Document Manager: Group General Counsel Effective: December 2008 2017 All copyright in these materials are reserved to AEA International

More information

It is the policy of Citizens Deposit Bank & Trust to adhere to the following Privacy Policy.

It is the policy of Citizens Deposit Bank & Trust to adhere to the following Privacy Policy. It is the policy of Citizens Deposit Bank & Trust to adhere to the following Privacy Policy. Purpose and Objectives This policy reaffirms and formalizes our bank's realization of and respect for the privacy

More information

Prairie Centre Credit Union

Prairie Centre Credit Union Code for the Protection of Personal Information Prairie Centre Credit Union Adopted by: Prairie Centre Credit Union Board of Directors July 15, 2003 Updated November 2014 Introduction P rairie Centre Credit

More information

Recent privacy legislation in the European Union has posed specific

Recent privacy legislation in the European Union has posed specific Recent Developments in EU Employee Data Privacy Law SEBASTIEN DUCAMP, CHERYL TAMA OBLANDER, AND HEATHER BENNO The authors explain how U.S. businesses with operations in Europe can reduce the risk of liability

More information

Practical Guide to Nevada Gaming Law for Institutional Investors

Practical Guide to Nevada Gaming Law for Institutional Investors Practical Guide to Nevada Gaming Law for Institutional Investors Albuquerque Casper Colorado Springs Denver Las Vegas Phoenix Reno Silicon Valley Tucson Table of Contents A Practical Guide to Nevada Gaming

More information

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES EMPLOYEE NOTICE OF DATA PRIVACY POLICIES TABLE OF CONTENTS A. Ecolab s Commitment to Data Privacy... 2 B. Definitions... 2 C. Scope... 3 D. Application of Local Law... 3 E. Employee Data Collected... 3

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM (European Union GDPR) (May 2018) This Data Processing Addendum ( DPA ) forms part of the Pancake Laboratories Inc, DBA ShortStack.com ( ShortStack) Terms and Conditions (https://www.shortstack.com/terms-andconditions/),

More information

EU Data Processing Addendum

EU Data Processing Addendum EU Data Processing Addendum This EU Data Processing Addendum ( Addendum ) is made and entered into by and between AlienVault, Inc., a Delaware corporation ( AlienVault ) and the customer specified in the

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM Page 1 of 20 DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Customer Terms of Service found at https://slack.com/terms-of-service, unless Customer has entered into a

More information

Moxtra, Inc. DATA PROCESSING ADDENDUM

Moxtra, Inc. DATA PROCESSING ADDENDUM Moxtra, Inc. DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Terms of Service found at http://moxtra.com/terms-of-service/, unless Company has entered into a superseding

More information

CBSA PRIVACY POLICY. Canadian Business Strategy Association Page 1

CBSA PRIVACY POLICY. Canadian Business Strategy Association Page 1 CBSA PRIVACY POLICY The CBSA Privacy Policy is a statement of principles and policies regarding the protection of personal information provided by the Canadian Business Strategy Association. The objective

More information

EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY

EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY 1. INTRODUCTION EQUAL ACCESS FUNDING PTY LTD PRIVACY POLICY This Policy applies to Equal Access Funding Pty Ltd ABN 23 156 554 255 (referred to as EAF, we, our, us ) and covers all of its operations and

More information

ClientBrief. International Litigation & Arbitration Practice

ClientBrief. International Litigation & Arbitration Practice Fall Winter 2005 Investment Treaty Arbitration/Protection and Vindication of International Investment Rights Introduction Opportunities for investments and business are truly global and ever-increasing.

More information

CANADIAN AMATEUR SYNCHRONIZED SWIMMING ASSOCIATION, INC. SASKATCHEWAN SECTION PRIVACY POLICY

CANADIAN AMATEUR SYNCHRONIZED SWIMMING ASSOCIATION, INC. SASKATCHEWAN SECTION PRIVACY POLICY CANADIAN AMATEUR SYNCHRONIZED SWIMMING ASSOCIATION, INC. SASKATCHEWAN SECTION PRIVACY POLICY PURPOSE OF THIS POLICY 1. To set rules for the collection and disclosure of personal information in a manner

More information

* Unless otherwise indicated, this policy will still apply beyond the review date.

* Unless otherwise indicated, this policy will still apply beyond the review date. Name of Policy Description of Policy Privacy Policy This policy sets out how ACU manages privacy obligations and reflects the 13 Australian Privacy Principles (APPs) from Schedule 1 of the Privacy Amendment

More information

DATA PROTECTION NOTICE

DATA PROTECTION NOTICE DATA PROTECTION NOTICE Who are we? We are the Trustees of the Pension Scheme for the Nursing and Midwifery Council and Associated Employers (the Scheme). We collect, hold and use personal information to

More information

Privacy Source EU-U.S. Privacy Shield Passes First Annual Review

Privacy Source EU-U.S. Privacy Shield Passes First Annual Review Privacy Source EU-U.S. Privacy Shield Passes First Annual Review Privacy Shield, the EU-U.S. data transfer agreement used by over 2,400 companies, recently passed its first annual review. This means the

More information

SCCCI Personal Data Protection Policy

SCCCI Personal Data Protection Policy SCCCI Personal Data Protection Policy At SCCCI, we are committed to protecting and safeguarding the personal data we collected from you. This Personal Data Protection Policy describes the types of personal

More information

Amgen Binding Corporate Rules (BCRs) Public Document

Amgen Binding Corporate Rules (BCRs) Public Document Amgen Binding Corporate Rules (BCRs) Public Document Introduction: Amgen is a biotechnology leader committed to serving patients with grievous illness. Binding Corporate Rules (BCRs) express Amgen s commitment

More information

Jericho Tennis Club's Privacy Policy

Jericho Tennis Club's Privacy Policy Jericho Tennis Club's Privacy Policy 1. Introduction At Jericho Tennis Club (the "Club"), respecting privacy is an important part of our commitment to our Members, Prospective Members, and Employees. That

More information

DATA PROTECTION ADDENDUM

DATA PROTECTION ADDENDUM DATA PROTECTION ADDENDUM In the event an agreement ( Underlying Agreement ) entered into by and between (i) either Sunovion Pharmaceuticals Inc. or its subsidiary, Sunovion Pharmaceuticals Europe Ltd.

More information

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THIS PROTOCOL is dated 2018 BETWEEN (1) The Chancellor, Masters, and Scholars of the University of Cambridge of The Old Schools,

More information

Affiliate Agreement. Affiliate Agreement. [Affiliate Name] Plain English Summary

Affiliate Agreement. Affiliate Agreement. [Affiliate Name] Plain English Summary Plain English Summary The purpose of this is to ensure that Creative Commons and its affiliates fully understand their duties respective to each other. Among other things: Affiliate is responsible for

More information

The Brazilian Data Protection Law LGPD

The Brazilian Data Protection Law LGPD Debevoise Update D&P The Brazilian Data Protection Law LGPD August 20, 2018 Last week, Brazil enacted its long-awaited Data Protection Law (Law 13,709/2018), known as Lei Geral de Proteção de Dados or

More information

Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy. May 2018

Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy. May 2018 Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy May 2018 Vanguard Group (Ireland) Limited (the Manager ), Vanguard Funds plc ( VF ), and Vanguard Investment

More information

Are You Prepared for the California Consumer Privacy Act?

Are You Prepared for the California Consumer Privacy Act? Are You Prepared for the California Consumer Privacy Act? Jeffrey M. Goldman Pepper Hamilton LLP Sharon R. Klein Pepper Hamilton LLP Alex Nisenbaum Pepper Hamilton LLP September 7, 2018 Jeffrey M. Goldman

More information

BASWARE PERSONAL DATA PROCESSING APPENDIX

BASWARE PERSONAL DATA PROCESSING APPENDIX This Basware personal data processing appendix and its annexes ( DPA ) is an appendix to, and legally binding only in connection with, the sales agreement between Basware and Customer with regard to Basware

More information

SBI Canada Bank Privacy Policy

SBI Canada Bank Privacy Policy Owner: Privacy Officer Version: 2.2 Approving Body: Board Date Approved: August 30, 2016 List of Recipients: All Staff Introduction 1. All banks in Canada are subject to Personal Information Protection

More information

Fees and Expiration. Replacement Card at Expiration : There is no additional cost to obtain a replacement Card due to expiration.

Fees and Expiration. Replacement Card at Expiration : There is no additional cost to obtain a replacement Card due to expiration. Visa or Mastercard Prepaid Gift Card Cardholder Agreement CUSTOMER SERVICE CONTACT INFORMATION: Address: 5501 S. Broadband Ln, Sioux Falls, SD 57108 Website: MyPrepaidBalance.com and My Prepaid App Phone

More information

DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES)

DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES) DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES) This Data Processing Addendum ( DPA ) shall become effective without any further action by the parties: (a) if Customer signing this

More information

DATA PROTECTION POLICY. AtonLine Limited

DATA PROTECTION POLICY. AtonLine Limited 20 Kyriakou Matsi Avenue, 4 th Floor CY-1082 Nicosia Cyprus Tel: +357 22 68 00 15 Fax: +357 22 68 00 16 Web: www.atonint.com DATA PROTECTION POLICY AtonLine Limited 2018 This Data Protection Policy is

More information

PRIVACY AND CYBERSECURITY ISSUES IN M&A TRANSACTIONS

PRIVACY AND CYBERSECURITY ISSUES IN M&A TRANSACTIONS PRIVACY AND CYBERSECURITY ISSUES IN M&A TRANSACTIONS Don Shelkey and Ezra Church May 22, 2018 2018 Morgan, Lewis & Bockius LLP Overview Introduction Why should I care? Five Key Legal Requirements Sector-Specific

More information

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ). GROUP PRIVACY POLICY Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ). 1 PURPOSE AND SCOPE 1.1 The aim of this policy is to establish uniform,

More information

SUPERIOR COURT OF THE STATE OF CALIFORNIA FOR THE COUNTY OF LOS ANGELES

SUPERIOR COURT OF THE STATE OF CALIFORNIA FOR THE COUNTY OF LOS ANGELES SUPERIOR COURT OF THE STATE OF CALIFORNIA FOR THE COUNTY OF LOS ANGELES EDUARD SHAMIS, ) Case No.: BC662341 ) Plaintiffs, ) Assigned for All Purposes to ) The Hon. Maren E. Nelson, Dept. 17 v. ) ) NOTICE

More information

Implementing the Obligations of the Gramm-Leach-Bliley Act The NAIC Model for State Privacy Regulation

Implementing the Obligations of the Gramm-Leach-Bliley Act The NAIC Model for State Privacy Regulation Implementing the Obligations of the Gramm-Leach-Bliley Act The NAIC Model for State Privacy Regulation This memorandum provides an analysis of the provisions of the National Association of Insurance Commissioners

More information

Modification of Services

Modification of Services These Terms and Conditions of Use ( Terms and Conditions of Use") apply to your access to, and use of, any Dickey s Barbecue Pit ("Dickey s") website, mobile application, and online service or program

More information

R E S U M E E N D E R P L L C. C O M

R E S U M E E N D E R P L L C. C O M R A Y M O N D G. BENDER A R B I T R A T O R M E D I A T O R S U I T E 5 7 0 1 2 0 0 N E W H A M P S H I R E A V E N U E, N. W. W A S H I N G T O N, D. C. 2 0 0 3 6-6 8 0 2 T ( 2 0 2 ) 7 7 6-2 7 5 8 F (

More information

Privacy Shield. A New and Improved Safe Harbor. briefing

Privacy Shield. A New and Improved Safe Harbor. briefing Privacy Shield A New briefing The European Commission adopted its much anticipated decision on the EU- US Privacy Shield ( Privacy Shield ) on 12 July 2016. The Privacy Shield was developed jointly by

More information

Privacy Policy. NESS Super is committed to respecting your right to privacy and protecting your personal information.

Privacy Policy. NESS Super is committed to respecting your right to privacy and protecting your personal information. February 2018 Privacy Policy Our privacy commitment to you NESS Super is committed to respecting your right to privacy and protecting your personal information. We are bound by the provisions of the Privacy

More information

DATA SHARING AGREEMENT. Between LEO Pharma A/S and [insert name of Researcher]

DATA SHARING AGREEMENT. Between LEO Pharma A/S and [insert name of Researcher] DATA SHARING AGREEMENT Between LEO Pharma A/S and [insert name of Researcher] This Data Sharing Agreement ( Agreement ) effective as of the date of the last signature (the Effective Date ) is entered into

More information

Business Transition Checklist

Business Transition Checklist Business Transition Checklist Key legal (and some business) considerations for a smooth and profitable business transition by James J. Scheinkman, Brian L. Blaylock and Brian D. Manning If you remember

More information

Association of Service Providers for Employability and Career Training ( ASPECT ) PRIVACY CODE

Association of Service Providers for Employability and Career Training ( ASPECT ) PRIVACY CODE Association of Service Providers for Employability and Career Training ( ASPECT ) PRIVACY CODE INTRODUCTION ASPECT is an association of community-based trainers that represents and promotes the interests

More information

Tax Identity Shield What to Expect. Tax Identity Shield Terms & Conditions

Tax Identity Shield What to Expect. Tax Identity Shield Terms & Conditions Tax Identity Shield What to Expect Congratulations! Enrolling in Tax Identity Shield (by signing below) is an important first step in helping to better protect your taxpayer identity. What happens next?

More information

AMIST Super. Privacy Policy

AMIST Super. Privacy Policy AMIST Super Privacy Policy Our privacy commitment to you AMIST Super is committed to respecting your right to privacy and protecting your personal information. We are bound by the provisions of the Privacy

More information

Principles. Bison Transport will implement policies and procedures to give effect to this policy, including:

Principles. Bison Transport will implement policies and procedures to give effect to this policy, including: Principles The ten principles that form this policy are interrelated, and Bison Transport will adhere to the ten principles as a whole. This policy, then, applies to personal information about Bison Transport

More information

Company Accreditation

Company Accreditation Company Accreditation HANDBOOK VERSION 2.0 Table of Contents 1. INTRODUCTION 1 2. NABCEP COMPANY ACCREDITATION POLICY 2 I. POLICY PURPOSE 2 II. POLICY SCOPE 2 III. COMPANY ACCREDITATION REQUIREMENTS 2

More information

The Invest Georgia Exemption

The Invest Georgia Exemption ADVISORY LITIGATION PRIVATE EQUITY CONVERGENT The Invest Georgia Exemption Michael Stegawski michael@convergentcapitalgroup.com 800.750.9861 x101 This memorandum is provided for educational and informational

More information

Code of Conduct & Practice

Code of Conduct & Practice Code of Conduct & Practice Terms of Usage 2015. Credit Collection Association of Singapore (CCAS). All Rights Reserved. No part of this publication may be resold, reproduced or transmitted in any form

More information

WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?

WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA? OVERVIEW of this Policy and Commitments to Privacy within Dual At Dual ("we", "us", "our"), we regularly collect and use information which may identify individuals ("personal data"), including insured

More information

Code Of Banking Practice

Code Of Banking Practice Code Of Banking Practice PREAMBLE The Code of Banking Practice (the Code) seeks to foster good relations between Banks and their Customers (as defined below) and to promote good banking practice by formalising

More information

Commercial Arbitration

Commercial Arbitration International Institute for Conflict Prevention & Resolution CPR PROCEDURES & CLAUSES Global Rules for Accelerated Commercial Arbitration Effective August 20, 2009 30 East 33rd Street 6th Floor New York,

More information

When Trouble Knocks, Will Directors and Officers Policies Answer?

When Trouble Knocks, Will Directors and Officers Policies Answer? When Trouble Knocks, Will Directors and Officers Policies Answer? Michael John Miguel Morgan Lewis & Bockius LLP Los Angeles, California The limit of liability theory lies within the imagination of the

More information

TOKEN PURCHASE AGREEMENT

TOKEN PURCHASE AGREEMENT TOKEN PURCHASE AGREEMENT PLEASE READ THIS TOKEN PURCHASE AGREEMENT DATED 17 JULY 2018 (THE AGREEMENT ) VERY CAREFULLY. THIS AGREEMENT ALSO SETS FORTH THE TERMS AND CONDITIONS. This Agreement contains the

More information

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT EN EN EN COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 20.10.2004 SEC (2004) 1323 COMMISSION STAFF WORKING DOCUMENT The implementation of Commission Decision 520/2000/EC on the adequate protection of

More information

Privacy Policy. Amendment History. Trustee Name

Privacy Policy. Amendment History. Trustee Name Trustee Name Policy Name Number of Pages (ABN: 74 065 680 195, RSE: L0003155), trustee of the Manildra Flour Mills Retirement Fund (ABN: 32 448 411 930, RSE R1067415) 6 (plus this covering page and a contents

More information

E-Sign Disclosure we, our you your Account Communication 1. Scope of Communications to Be Provided in Electronic Form.

E-Sign Disclosure we, our you your Account Communication 1. Scope of Communications to Be Provided in Electronic Form. E-Sign Disclosure This E-Sign Disclosure and Consent ( Disclosure ), applies to all Communications for any Account offered through www.myprepaidcenter.com that is not otherwise governed by the terms and

More information

Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR)

Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty. Overview of the EU General Data Protection Regulation (GDPR) Michael R. Cohen CIPP/US, CIPP/E Gray Plant Mooty Overview of the EU General Data Protection Regulation (GDPR) WHAT YOU NEED TO KNOW ABOUT THE EU GENERAL DATA PROTECTION REGULATION (GDPR) What is the GDPR?

More information

CODE OF BANKING PRACTICE

CODE OF BANKING PRACTICE Publication History First published by the Australian Bankers Association in August 2003. Subsequent amendments published in May 2004. For details of these amendments see www.bankers.asn.au under Code

More information

INSURANCE COVERAGE COUNSEL

INSURANCE COVERAGE COUNSEL INSURANCE COVERAGE COUNSEL 2601 AIRPORT DR., SUITE 360 TORRANCE, CA 90505 tel: 310.784.2443 fax: 310.784.2444 www.bolender-firm.com 1. What does it mean to say someone is Cumis counsel or independent counsel?

More information

Gregory Keating. Practice Group Leader PRACTICE FOCUS. EDUCATION Boston College Law School JD, 1993, cum laude. Trinity College BA, 1987

Gregory Keating. Practice Group Leader PRACTICE FOCUS. EDUCATION Boston College Law School JD, 1993, cum laude. Trinity College BA, 1987 Gregory Keating Practice Group Leader T +1 (617) 248-5065 gkeating@choate.com a respected expert in the defense of whistle-blower claims and for his phenomenal expertise representing clients in the education

More information

2017 Copyright The Sequoia Project. All rights reserved.

2017 Copyright The Sequoia Project. All rights reserved. Exhibit 1 Carequality Connection Terms As used herein, Organization refers to the Carequality Connection upon which these Carequality Connection Terms are binding and Sponsoring Implementer refers to the

More information

Agreement for Advisors Providing Services to Interactive Brokers Customers

Agreement for Advisors Providing Services to Interactive Brokers Customers 6101 03/10/2015 Agreement for Advisors Providing Services to Interactive Brokers Customers This Agreement is entered into between Interactive Brokers ("IB") and the undersigned Advisor. WHEREAS, IB provides

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement ( DPA or Agreement ), entered into by the CPI customer identified on the applicable CPI services agreement for CPI services ( Customer ) and the

More information

SYNCHRO SWIM MANITOBA PRIVACY POLICY

SYNCHRO SWIM MANITOBA PRIVACY POLICY SYNCHRO SWIM MANITOBA PRIVACY POLICY Approved: Feb 15, 2006 By the Board of Directors Number of pages: 8 Purpose of this Policy 1. The purpose of this policy is to govern the collection, use and disclosure

More information

Privacy Policy. Pursuant to U.S. State & Federal Laws the following is a statement of your legal rights.

Privacy Policy. Pursuant to U.S. State & Federal Laws the following is a statement of your legal rights. General Disclaimer Privacy Policy Pursuant to U.S. State & Federal Laws the following is a statement of your legal rights. Disclaimer & Legal Rights No Warranties ALL WEB SITES, PRODUCTS AND SERVICES ARE

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the End User License and Services Agreement (the Agreement ) between Customer and Ivanti, to reflect the parties agreement about

More information

TOKEN PURCHASE AGREEMENT

TOKEN PURCHASE AGREEMENT TOKEN PURCHASE AGREEMENT PLEASE READ THIS TOKEN PURCHASE AGREEMENT DATED 17 JULY 2018 (THE AGREEMENT ) VERY CAREFULLY. THIS AGREEMENT ALSO SETS FORTH THE TERMS AND CONDITIONS. This Agreement contains the

More information

Professional liability

Professional liability Professional liability 360 www.mpplaw.com about our Practice Established in 1969, Morris Polich & Purdy llp has a rich, prestigious history of representing all types of professionals. Our many services

More information

Georgia Power Valdosta Federal credit union Privacy Policy

Georgia Power Valdosta Federal credit union Privacy Policy Georgia Power Valdosta Federal credit union Privacy Policy Review/Revision Date: October 20,2016 Approval Date: February 26, 2001 Approved by: Board of Directors General Policy Statement: The Georgia Power

More information

LEGAL PRIVACY NOTICE (EFFECTIVE MAY/2018) 12 Demostheni Severi Avenue 5th Floor 1080 Nicosia Cyprus

LEGAL PRIVACY NOTICE (EFFECTIVE MAY/2018) 12 Demostheni Severi Avenue 5th Floor 1080 Nicosia Cyprus LEGAL PRIVACY NOTICE (EFFECTIVE MAY/2018) 12 Demostheni Severi Avenue 5th Floor 1080 Nicosia Cyprus BACKGROUND Emergo Wealth Ltd. understands that your privacy is important to you and that you care about

More information

ON24 DATA PROCESSING ADDENDUM

ON24 DATA PROCESSING ADDENDUM ON24 DATA PROCESSING ADDENDUM This Data Processing Addendum ( Addendum ) is entered into by and between ON24 Inc., on behalf of itself and its Affiliates ( ON24 ), and Client, on behalf of itself and its

More information

Privacy in Canada Federal Legislation: Personal Information Protection and Electronic Documents Act

Privacy in Canada Federal Legislation: Personal Information Protection and Electronic Documents Act Table of Contents Introduction Privacy in Canada Definition of Personal Information : the ten principles Accountability Identifying Purposes Consent Limiting Collection Limiting Use, Disclosure, and Retention

More information

Litigation & Dispute Resolution

Litigation & Dispute Resolution Disputes arise from sources ranging from internal matters, such as employee or whistleblower claims, to external matters, such as contract disputes, government investigations or protecting intellectual

More information

THE ETHICS OF OUTSOURCING LEGAL SERVICES

THE ETHICS OF OUTSOURCING LEGAL SERVICES THE ETHICS OF OUTSOURCING LEGAL SERVICES FRAMEWORK FOR THINKING ABOUT LEGAL OUTSOURCING Value Capacity Efficiency Cost Savings Predictability Innovation Peace of Mind Quality People Process Technology

More information

Taking care of what s important to you

Taking care of what s important to you A v i v a C a n a d a I n c. P r i v a c y P o l i c y Taking care of what s important to you Table of Contents Introduction Privacy in Canada Definition of Personal Information Privacy Policy: the ten

More information