Model Data Processing Agreement Version 2.0

Size: px
Start display at page:

Download "Model Data Processing Agreement Version 2.0"

Transcription

1 Mdel Data Prcessing Agreement Versin 2.0 This is the English translatin f the Dutch text f the Mdel Data Prcessing Agreement. In case the English translatin differs r deviates frm the Dutch text, the Dutch texts and interpretatins prevail. This Mdel Data Prcessing Agreement is an annex t the Privacy Cvenant Digital Educatinal Resurces(hereinafter referred t as the Cvenant) cncluded between the Primary Educatin Cuncil (PO-Raad), Secndary Educatin Cuncil (VO-Raad) and the branch rganisatins f educatinal publishing (GEU), distributrs f learning resurces (members f educatinal department f the Ryal Bk Seller Bnd) and digital service prviders in ICT educatin (VDOD). The starting pints f this Mdel Data Prcessing Agreement are in line with the prvisins f the Cvenant, the Persnal Data Prtectin Act (hereinafter: Data Prtectin Act), and the starting pints as indicated in case law and in guidelines and statements by the supervisry authrity, the Dutch Data Prtectin Authrity (Autriteit Persnsgegevens) The Mdel Data Prcessing Agreement versin 2016 is the successr f the Mdel Data Prcessing Agreement which was drawn up in 2015 in the cntext f the Privacy Cvenant Digital Educatinal Resurces, Learning resurces and Testing. In additin t using Learning Resurces and Testing, the versin 2.0 als cvers Schl and Pupil Infrmatin Resurces. In additin, sme parts f the agreement have been adjusted in line with recent develpments in legislatin, including the amendment f the Data Prtectin Act in cnnectin with the bligatin t reprt Data Leaks. The new Mdel Data Prcessing Agreement 2.0 replaces the Mdel Data Prcessing Agreement frm Data Prcessing Agreements, already cncluded based n the ld mdel frm 2015 remain in effect, in principle, until these Data Prcessing Agreement are terminated by the parties and are then fllwed by a new Data Prcessing Agreement based n the new Mdel Data Prcessing Agreement 2.0. In the Cvenant, it is agreed that Schls and Parties in the chain will use this mdel when making arrangements. If (parts f) the Mdel Data Prcessing Agreement cannt be used, nly a substantiated written dergatin is permitted. Given the number f prvisins that are either required by law, r which the Dutch Data Prtectin Authrity indicate that it must be included in the Data Prcessing Agreement, the scpe fr dergatin frm the prvisins f the Mdel is limited. This Mdel Data Prcessing Agreement cntains tw annexes: 1. The Privacy Leaflet (Annex 1) is a descriptin f the service, prduct characteristics and which categries f Persnal Data are prcessed and fr which bjectives these prcessing peratins fall under. 2. The Technical and Organisatinal Measures (Annex 2) defines what security measures are taken. Security must remain a cnstant fcus f attentin and care. Infrmatin abut the Cvenant and the Mdel Data Prcessing Agreement can be fund n the website Mre infrmatin and answers t questins abut privacy and the legal rights and bligatins fr Schls can be fund n Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

2 the websites f the industry cuncils Primary Educatin Cuncil (PO-Raad) and Secndary Educatin Cuncil (VO-raad) and Kennisnet. June 2016 Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

3 Parties: and 1. The cmpetent authrity f <name + legal frm f Schl>, registered under BRIN-number <brin> at the Dienst Uitvering Onderwijs [Dutch Educatin Service] f the Ministry f Educatin, having its registered ffice and principal place f business at <address>, in (<pstal cde>) <city>, legally represented in this matter by <functin + name>, hereinafter referred t as: 'Schl. 2. The private limited cmpany <Name> B.V., having its registered ffice and principal place f business at <address>, in (<pstal cde>) <city>, legally represented in this matter by <functin + name>, hereinafter referred t as: 'Prcessr Hereinafter cllectively referred t as: 'Parties', r separately: 'Party Whereas: a. Schl and Prcessr have cncluded an agreement whereby <specific descriptin f prducts/services t be supplied by Prcessr n behalf f Schl>, ('the Prduct and Services Agreement'). This Prduct and Services Agreement results in the Prcessr carrying ut the prcessing f Persnal Data n behalf f the Schl. b. The parties wish, als in view f the prvisins f Sectin 14 f the Persnal Data Prtectin Act, t recrd their mutual rights and bligatins fr the Prcessing f Persnal Data in this Data Prcessing Agreement. agree t the fllwing: Clause 1: Definitins In this Data Prcessing Agreement: a. Data Subject, Prcessr, Third Party, Persnal Data, Prcessing f Persnal Data and Data Cntrller are understd accrding t the definitins defined in Sectin 1 f the Data Prtectin Act; b. Data Prcessing Agreement: this Data Prcessing Agreement, including Annexes; c. Annex: an annex t this Data Prcessing Agreement, which frms an integral part theref; d. Cvenant: the Privacy Cvenant Digital Educatinal Resurces; e. Data Leak: a security breach, as referred t in Sectin 13 Data Prtectin Act, which leads t the cnsiderable risk f serius adverse effects, r serius adverse cnsequences fr the prtectin f persnal data, as referred t in Sectin 34a, subsectin 1, Data Prtectin Act; f. Digital Educatinal Resurce: Learning Resurces and Testing and Schl and Pupil Infrmatin Resurces; g. Learning Resurces and Testing: digital prduct and/r digital service cnsisting f curse material and/r tests and assciated digital services, fcussed n learning situatins fr the purpse f teaching by r n behalf f Schls; h. Schl and Pupil Infrmatin Resurces: a digital prduct and/r digital service fr the benefit f the educatin (prcess), such as a pupil administratin system, timetabling system, parent prtal, pupil and parent cmmunicatin system, an electrnic learning envirnment and a pupil tracking system. i. Privacy Leaflet: the privacy leaflet as set ut in Annex 1; Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

4 j. Prduct and Services Agreement: the agreement between the Schl and Prcessr, as defined in paragraph a; k. Mdel Data Prcessing Agreement The mdel fr a data prcessing agreement as attached in the annex t the Cvenant; l. Sub-prcessr: the party that is engaged by the Prcessr as Prcessr fr Prcessing f Persnal Data in the cntext f this Data Prcessing Agreement and the Prduct and Services Agreement; m. Data Prtectin Act: Wet bescherming persnsgegevens [Dutch Persnal Data Prtectin Act]. Clause 2: Subject and assignment f Data Prcessing Agreement 1. This Data Prcessing Agreement shall apply t the Prcessing f Persnal Data in the cntext f the implementatin f the Prduct and Services Agreement. 2. The Schl places with the Prcessr the cntract fr the Prcessing f Persnal Data fr the purpse f implementing the Prduct and Services Agreement. Clause 3: Divisin f rles 1. The Schl is the Data Cntrller in respect f the Prcessing f Persnal Data t be carried ut n its behalf. The Prcessr is a prcessr within the meaning f the Data Prtectin Act. The Schl has and maintains independent cntrl ver the purpse and methds f the Prcessing f Persnal Data. 2. The Prcessr shall ensure that the Schl, prir t the cnclusin f this Data Prcessing Agreement, is sufficiently infrmed abut the service(s) which the Prcessr prvides, and the Prcessing t be carried ut. The infrmatin given shuld enable the Schl t make a chice regarding the ffered services as such, and in additin an individual chice fr any ptinal services ffered. 3. The services referred t in subclause 2, including any ptinal services, must be described in the Privacy Leaflet accmpanying this Data Prcessing Agreement in plain language, whereby the Schl can give infrmed cnsent t the purchase f this service(s). 4. The Schl may be required t ntify the Prcessing f Persnal Data t the Dutch Data Prtectin Authrity. The Schl shall examine whether r nt it is exempt and shall ntify the Dutch Data Prtectin Authrity if it is bliged t d s. 5. The Schl and Prcessr shall prvide each ther back and frth, all the necessary infrmatin t allw prper cmpliance with the relevant privacy law and legislatin. Clause 4: Privacy Cvenant 1. The Parties agree with the prvisins in the Privacy Cvenant Digital Educatinal Resurces. Clause 5: Use f Persnal Data 1. Prcessr undertakes nt t use the Persnal Data received frm the Schl fr ther purpses r in any ther manner than fr the bjective, and the manner in which the data have been supplied r have becme knwn. The Prcessr is therefre nt allwed t carry ut prcessing peratins ther than thse assigned by the Schl (verbally, in writing r electrnically) t the Prcessr. This bligatin applies t bth during the term f this agreement and after its cmpletin. Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

5 2. An verview f the categries f Persnal Data tgether with the use fr which the Persnal Data are prcessed are set ut in the Privacy Leaflet annexed t this Data Prcessing Agreement. 3. The prcessr must indicate in the Privacy Leaflet whether r nt the Privacy Leaflet relates t a Learning resurce and Testing and/r Schl and Pupil Infrmatin Resurce. The Prcessr must specify in the Privacy Leaflet fr which purpses (included in the Cvenant) Persnal Data are prcessed when using his prduct and/r service and which categries f Persnal Data are prcessed. If specified in the Explanatry Memrandum in the Privacy Leaflet, the Prcessr must als indicate under which f the bjectives as defined in the Cvenant, the Prcessing f Persnal Data takes place when using the prduct and/r service. 4. The Prcessr refrains frm transferring Persnal Data t a Third Party, unless this exchange takes place n behalf f the Schl r when this is necessary in rder t cmply with a legal bligatin impsed n the Prcessr. In the event f a legal bligatin, prir t transferring, the Prcessr must verify the basis f the request and the identity f the applicant. In additin, the Prcessr will infrm the Schl - if permitted by law - immediately, if pssible prir t transferring. 5. SPECIFIC PROVISION IN CASE OF EXCHANGING THE EDUCATIONAL REPORT: In additin t the prvisins f subclause 4, it applies that, if the Prcessr is asked t transfer Persnal Data t a Third Party designated and selected by the Schl, i.e. anther Schl, the Prcessr will nly prceed with transferring after the latter Schl has prvided its administrative educatin identity (e.g. BRIN r OiN), insfar as it is knwn. 6. [SPECIFIC PROVISION IN CASE OF DISTRIBUTION OF LEARNING RESOURCES: Every year, when drawing up the learning resurces lists fr the next schl year, whereby the learning resurces lists are drawn up fr the purpse f perfrming the Prduct and Services Agreement, the Parties will supplement and/r change the Privacy Leaflet by including the categries f Persnal Data and the use f such Persnal Data, with regard t the (digital) learning resurces that are included n the relevant learning resurces lists.] Clause 6: Cnfidentiality 1. The Prcessr ensures that everyne, including its emplyees, agents and/r Subprcessrs, wh are invlved in the Prcessing f Persnal Data, treat this data as cnfidential. The Prcessr ensures that each persn wh is invlved in the Prcessing f Persnal Data has entered int a cnfidentiality agreement r accepted a cnfidentiality clause. 2. The cnfidentiality bligatin referred t in this Clause des nt apply if the Schl has given explicit cnsent t disclse the Persnal Data t a Third Party, if disclsure f Persnal Data t a Third Party is necessary in view f the nature f services prvided by the Prcessr t the Schl, r if there is a legal bligatin t disclse the Persnal Data t a Third Party. Clause 7: Security and cntrl 1. The Prcessr will, in the same way as the Schl, ensure apprpriate technical and rganisatinal measures t prtect Persnal Data against lss r any frm f unlawful Prcessing. These measures, in accrdance with the state f technlgy and the csts invlved with the implementatin and the executin f the measures, must ensure an adequate level f prtectin, taking accunt f the risks assciated with the Prcessing f Persnal Data and the nature theref. Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

6 2. The measures specified in Clause 7.1 shall include at least: a. measures t ensure that nly authrised persnnel have access t the Persnal Data that is prcessed in the cntext f the Data Prcessing Agreement; b. measures t prtect the Persnal Data against, in particular, accidental r unlawful destructin, lss, accidental alteratin, unauthrised r unlawful strage, access r disclsure; c. measures t identify weaknesses in respect f the Prcessing f Persnal Data in the systems used fr the prvisin f services t the Schl; d. an apprpriate infrmatin security plicy fr the Prcessing f Persnal Data. 3. The Prcessr must evaluate, tighten up, supplement r imprve the infrmatin security measures it has taken t the extent warranted by the requirements r (technlgical) develpments. 4. Annex 2 establishes the arrangements between the Parties n the technical and rganisatinal security measures, as well as n the cntent and frequency f the reprts which the Prcessr prvides t the Schl abut the security measures. These measures are in line with the security measures that the Schl must take. 5. The Prcessr enables the Schl t meet its legal bligatin t mnitr cmpliance f the Prcessr f the technical and rganisatinal security measures as well as n cmpliance with the bligatins referred t in Article 8 in respect f Data Leaks. In additin t reprts by the Prcessr, this can be achieved n the basis f, but nt limited t, a valid certificatin r an equivalent verificatin r prf f evidence. 6. In additin t Clause 7 (4) the Schl has the right at all times, in cnsultatin with the Prcessr and within a reasnable perid f time, at its wn cst, t have the technical and rganisatinal security measures f the Prcessr audited by an independent Registered EDP auditr. The Parties, in mutual agreement, may agree that the audit is perfrmed by a certified and independent auditr appinted by the Prcessr wh will issue a third-party declaratin (TPM). The Schl will be infrmed f the results f the audit. Clause 8: Data Leaks 1. The Prcessr has an apprpriate plicy fr dealing with Data Leaks. 2. If the Schl r Prcessr establishes a Data Leak, they will immediately infrm the ther Party. In the event f a Data Leak, the Prcessr shall prvide all relevant infrmatin t the Data Cntrller with regard t the Data Leak, including infrmatin n any develpments arund the Data Leak, and the measures taken by the Prcessr t limit the effects f the Data Leak and t prevent recurrence. Additinally, the Parties will infrm each ther withut delay if it transpires that the security breach is likely t have a negative impact n the privacy f the Party cncerned as referred t in Sectin 34a, subsectin 2, Data Prtectin Act. 3. In the event f a Data Leak, the Prcessr will enable the Data Cntrller t take the necessary fllw-up steps with respect t the Data Leak. The Prcessr must fllw the existing prcesses that the Data Cntrller has established fr this purpse. The Parties will take as sn as pssible all reasnably required measures t prevent r limit (further) breaches r infringements cncerning the Prcessing f Persnal Data, and mre particularly (further) breaches f the Data Prtectin Act r ther legislatin cncerning the Prcessing f Persnal Data. Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

7 4. In the event f a Data Leak, the Schl must cmply with any legal reprting bligatin. The Parties may mutually determine whether and if s hw, the Prcessr can make a ntificatin t the Dutch Data Prtectin Authrity. At the request f the Schl, the Prcessr can assist and advise the Schl with this. If required, the Schl will infrm the Parties cncerned abut such an infringement. The Parties will, in gd faith and in mutual cnsultatin, make arrangements abut the reasnable distributin f any csts assciated with cmplying with the reprting bligatins. 5. The Prcessr will infrm the Schl in accrdance with the arrangements laid dwn in Annex 2 n security related incidents, ther than a Data Leak, which fall utside the scpe f Clause 1 ( e ). Clause 9: Prcedural rights f Data Subjects 1. A cmplaint r request f a Data Subject with regard t the Prcessing f Persnal Data will be frwarded immediately by the Prcessr t the Schl with respnsibility fr handling the request. 2. The Prcessr fully cperates with the Schl - t the extent reasnably pssible - t be able t meet the bligatins under the Data Prtectin Act within the statutry deadlines, in particular, the rights f the Data Subjects, such as a request fr access, crrectin, additin, remval r blcking f Persnal Data. The parties will cnsult in gd faith n the reasnable distributin f any csts invlved in this. Clause 10: Prcessing utside the Eurpean Ecnmic Area 1. The Parties shall ensure that insfar as Persnal Data are prcessed utside the Eurpean Ecnmic Area (hereinafter referred t as: EEA), this takes place nly in accrdance with legislative requirements and any bligatins resting n the Schls in this regard. If data are prcessed utside the EEA, this is specified in Annex 1, including an indicatin f the cuntries where the data will be prcessed. Clause 11: Engaging Sub-prcessrs 1. The Prcessr can engage a Sub-prcessr, whse identity and lcatin infrmatin are t be included in the Privacy Leaflet. 2. The Prcessr requires each Sub-prcessr cntractually t cmply with cnfidentiality bligatins, reprting bligatins and security measures with regard t the Prcessing f Persnal Data, which bligatins and measures must al least cmply with the prvisins f this Data Prcessing Agreement. 3. The Prcessr requires each Sub-prcessr cntractually nt t prcess Persnal Data in any ther manner than agreed in this Data Prcessing Agreement. Clause 12: Retentin perids and destructin f Persnal Data 1. The Schl will adequately infrm the Prcessr abut (legal) retentin perids that apply t the Prcessing f Persnal Data by the Prcessr. The Prcessr will nt prcess the Persnal Data fr lnger than these retentin perids. 2. The Schl requires the Prcessr t destry the Persnal Data prcessed n behalf f the Schl, r have them destryed, upn the terminatin f the Data Prcessing Agreement, unless the Persnal Data shuld be kept fr a lnger perid, such as in the cntext f legal bligatins, r at the request f the Schl. The Schl may carry ut an audit at its wn expense whether destructin has taken place. Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

8 3. The Prcessr will give the Schl written r electrnic cnfirmatin that the destructin f the Prcessed Persnal Data has taken place. 4. The Prcessr will infrm all Sub-prcessrs invlved in the Prcessing f Persnal Data f a terminatin f the Data Prcessing Agreement and will ensure that all Sub-prcessrs will r have the Persnal Data destryed. Clause 13: Cntradictin and amending the Data Prcessing Agreement 1. In case f cnflict between the prvisins f this Data Prcessing Agreement and the prvisins f the Prduct and Services Agreement, the prvisins f this Data Prcessing Agreement will prevail. 2. If the Parties have t deviate frm the articles in the Mdel Data Prcessing Agreement due t circumstances, r want t make additins, these changes and/r additins will be defined and substantiated by the Parties in an verview that is attached as Annex 3 t this Data Prcessing Agreement. The prvisins f this paragraph shall nt apply t additins and/r amendments f the Annexes 1 and In the event f significant changes t the prduct and/r the (additinal) services that impact the Prcessing f Persnal Data, the Schl will be infrmed in plain language abut the implicatins f these changes befre the Schl chses t accept this. Imprtant changes will mean in any case: adding r amending a functinality that leads t an increase in respect f the Persnal Data t be prcessed, the bjectives fr which the Persnal Data are prcessed and the engagement f a Sub-prcessr r different Sub-prcessr. The amendments will be incrprated in Annex Amendments t the Clauses f the Data Prcessing Agreement can nly be effected by jint agreement. 5. In the event that any prvisin f this Data Prcessing Agreement is r becmes invalid, vidable r therwise unenfrceable, the remaining prvisins f this Data Prcessing Agreement remain in full frce and effect. In that case, the Parties will enter int cnsultatin t replace the invalid, vidable r therwise unenfrceable prvisin by an enfrceable alternative prvisin. The parties will take the utmst accunt f the purpse and intent f the invalid, vid r therwise unenfrceable prvisin. Clause 14: Duratin and terminatin 1. The duratin f this Data Prcessing Agreement is equal t the duratin f the Prduct and Services Agreement cncluded between the Parties, including any extensins theref. 2. This Data Prcessing Agreement will end autmatically upn terminatin f the Prduct and Services Agreement. The terminatin f this Data Prcessing Agreement will nt exempt the Parties frm their bligatins arising frm this Data Prcessing Agreement which by their nature are expected t cntinue after terminatin. Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

9 ANNEX 1: PRIVACY LEAFLET [name f prduct/service] Schls are increasingly using digital applicatins within educatin. The use and prvisin f these prducts and services requires data that can be traced back t individuals (such as pupils). Schls must make arrangements with Prcessrs n the use f such Persnal Data. This leaflet gives schls infrmatin abut the service the prcessr prvides and what persnal data the prcessr will prcess. In shrt, abut the questin "wh, what, where, why and hw" deals with the privacy f the persns cncerned whse data are exchanged. Using this Privacy Leaflet helps Schls t better understand the functin f the prduct and/r service and what types f data are t be exchanged. In the cntext f the recgnisability, it is desirable that Prcessrs use this Privacy Leaflet as much as pssible in a unifrm manner. Deviatins frm this mdel are indeed pssible but shuld preferably be limited. If the space in this Annex is insufficient t describe the required infrmatin, is it pssible t include the infrmatin in a separate annex r annexes, which shall be numbered as fllws: "Annex 1A", "Annex 1B", etc. These Annexes will be attached t the Data Prcessing Agreement. A. General infrmatin Name f prduct and/r service : Name f Prcessr and lcatin infrmatin : Brief explanatin and functining f prduct and service : Link t supplier and/r prduct page : Target grup (such as PE/SE lwer/upper) : User : pupils/parents/guardians/teachers B. The specific services Descriptin f the specific services prvided and assciated Prcessing 1. Prcessing which frm an integral part f the service ffered. a. [.] b. [.] [.] 2. Descriptin f the ptinal Prcessing ffered by the prcessr Explanatin: This relates t additinal services and assciated Prcessing which d nt frm an integral part f the service ffered. These include, fr example, ptinal services fr the Schl that may be helpful t the Schl fr the purpses f the primary (learning) prcess and administrative wrk The Schl must chse (rder) the purchase f these services. This can be achieved by indicating this chice in writing in this Annex (fr example, by ticking a tick bx) ). Agreement can als take place by means f the Schl activating the service in practice, fr example, by switching a prduct r service n r ff. The Schl that makes the chice in this way, must be able t d s n the basis f previusly prvided infrmatin (such as, fr instance, listed in this leaflet). a. [.] b. [.] Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

10 [.] C. Objectives fr the prcessing f data The Prcessr must explicitly indicate in this Leaflet whether it is: I. a supplier f a digital prduct and/r digital service cnsisting f curse material and/r tests, r II. (als) a supplier f a Schl and Pupil Infrmatin Resurces. Re I. If the Prcessr is a supplier f a digital prduct and/r digital service cnsisting f Learning Resurces and Testing, then the pssible bjectives f these prducts and services are defined in the relevant part f Clause 5 (1) f the Privacy Cvenant Digital Educatinal Resurces 2.0. These d nt need t be further named in this Leaflet. Re II. Only if the prcessr is (als) a supplier f a digital prduct and/r digital service cnsisting f a Schl and Pupil Infrmatin Resurce, this Privacy Leaflet shuld explicitly mentin the purpses fr which Persnal Data are prcessed when using the prduct and/r the service. The Prcessr must fllw as clsely as pssible the list f bjectives laid dwn in Clause 5 (2) f the Privacy Cvenant Digital Educatinal Resurces. D. Categries and types f persnal data Descriptin and summary f categries f Persnal Data which are used: Any ptinal Persnal Data (which are nt requested and stred as standard): Types f data (such as special data r financial infrmatin): E. General infrmatin n security measures taken: Fr the sake f brevity, please refer t Annex 2 t the Data Prcessing Agreement fr the security measures taken.. Specific security measures fr this service/prduct [if applicable]: Any certificatins: Audits/Third Party declaratins: City/Cuntry f strage and Prcessing f Persnal Data: F. Sub-prcessrs The Prcessr engages the fllwing Sub-prcessrs fr the service/prduct: [party name, brief descriptin f task/service shwing what data are prcessed by this Sub-prcessr] City/Cuntry f strage and Prcessing f Persnal Data (if the Persnal Data are prcessed utside the EEA, a separate reprt must be made f the cuntries where the Persnal Data are prcessed). G. Cntact details Fr questins r cmments abut this leaflet r the peratin f the prduct r service, please cntact: [cntact infrmatin]. H. Versin [versin number and date f last mdificatin] Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

11 This privacy leaflet is part f the arrangements made in the Privacy Cvenant Digital Educatinal Resurces 2.0, an initiative f the Primary Educatin Cuncil, Secndary Educatin Cuncil, the varius interested parties (GEU, KBB-e and VDOD) and the Ministry f Educatin, Culture and Science. Yu can find mre infrmatin n: Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

12 ANNEX 2: Technical and rganisatinal security measures The Prcessr, in accrdance with the Data Prtectin Act and Clause 7 f the Data Prcessing Agreement, is bliged t take technical and rganisatinal measures t ensure the security f the Prcessing f Persnal Data. If the space in this Annex is insufficient t describe the required infrmatin, is it pssible t include the infrmatin in a separate annex r annexes, which shall be numbered as fllws: "Annex 2A", "Annex 2B", etc. These Annexes will be attached t the Data Prcessing Agreement. Descriptin f the measures as referred t in Clause 7.2 f the Data Prcessing Agreement. I. Descriptin f the measures taken t ensure that nly authrised persnnel have access t the Prcessing f Persnal Data. Mre specifically, an verview f which (grups f) emplyees f the Prcessr have access t which Persnal Data, including a descriptin f the peratins these emplyees may carry ut with the Persnal Data. a. (grups f) emplyees wh have access t which Persnal Data: b. peratins that these emplyees perfrm using the Persnal Data: II. Descriptin f the measures t prtect Persnal Data against accidental r unlawful destructin, accidental lss r alteratin, unauthrised r unlawful strage, Prcessing, access r disclsure. Mre specifically, an verview f the technical and rganisatinal (security) measures taken by the Prcessr and the security standard used. [descriptin f security f the applicatin/platfrm] [descriptin f methd f identificatin/authenticatin/authrisatin and security theref] [descriptin f security f methd f exchange/transprt f data] III. Descriptin f the measures t identify weaknesses in respect f the Prcessing f Persnal Data in the systems used fr the prvisin f services t the Schl; [such as a peridic analysis f (security) incidents, peridically cnducting an external/ internal vulnerabilities investigatin (ethical hack) r peridically cnducting checks n the security f systems] Reprting (Clause 7.4 f the Data Prcessing Agreement The Prcessr reprts peridically with a frequency f [ ] times a year, by [ ] t the Data Cntrller n the measures taken by the Prcessr n the technical and rganisatinal security measures and any cncerns therein.] [cntact details helpdesk/service desk fr security incidents] Infrming abut Data Leaks and/r security related incidents Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

13 Arrangements n the prvisin f infrmatin in the event f Data Leaks and/r security related incidents, in particular n The way in which mnitring and identificatin f incidents takes place, The way in which infrmatin is shared: In what way (via , telephne); T whm it shuld be addressed (cntact persn and cntact details); Whm shuld be cntacted (fr fllw-up actins). Infrmatin that must be shared in any case abut an incident The characteristics f the incident such as: date and time f discvery, summary f the incident, attribute and type f incident (what part f security des it relate t, hw has it ccurred, des it relate t reading, cpying, mdifying, deleting/destructing and/r theft f persnal data); The cause f the security incident; The measures taken t prevent any damage r further damage; Naming Data Subjects wh may be affected by the incident and the extent; The size f the grup f Data Subjects; The type f data affected by the incident (in particular special data, r data f a sensitive nature, including access r identificatin data, financial data r learning perfrmance). Any arrangements if, and if s hw, the Prcessr can make a ntificatin t the Dutch Data Prtectin Authrity. Versin [versin number and date f the mst recent amendment] This privacy leaflet is part f the arrangements made in the Privacy Cvenant Digital Educatinal Resurces 2.0, an initiative f the Primary Educatin Cuncil, Secndary Educatin Cuncil, the varius interested parties (GEU, KBB-e and VDOD) and the Ministry f Educatin, Culture and Science. Yu can find mre infrmatin n: Mdel Data Prcessing Agreement Privacy Cvenant Digital Educatinal Resurces versin June

Privacy & Data Protection Policy

Privacy & Data Protection Policy Privacy & Data Prtectin Plicy Whitby & District Fishing Industry Training Schl Limited and 54 Nrth Maritime Training ("Whitby Fishing Schl", WDFITS, 54 Nrth Maritime "we" r "us") are cmmitted t prmting

More information

Summit Asset Managers Limited

Summit Asset Managers Limited Irish Infrastructure Trust Privacy Ntice Intrductin This ntice sets ut details f hw and why Summit Asset Managers Limited, f Beresfrd Curt,, Dublin 1, Ireland, acting n behalf the Irish Infrastructure

More information

Purpose... 1 Definitions... 1 Policy... 2

Purpose... 1 Definitions... 1 Policy... 2 Cntents Purpse... 1 Definitins... 1 Plicy... 2 1. Privacy Principles... 2 2. Cllectin f infrmatin... 2 3. Unique Student Identifiers (USI)... 3 4. Strage and use f infrmatin... 4 5. Disclsure f infrmatin...

More information

HIPAA Privacy Rule LINKS AND RESOURCES AFFECTED ENTITIES IMPACT ON EMPLOYERS. Provided by Brown & Brown of Louisiana, LLC

HIPAA Privacy Rule LINKS AND RESOURCES AFFECTED ENTITIES IMPACT ON EMPLOYERS. Provided by Brown & Brown of Louisiana, LLC Prvided by Brwn & Brwn f Luisiana, LLC HIPAA Privacy Rule The HIPAA Privacy Rule establishes natinal standards t prtect individuals medical recrds and ther persnal health infrmatin. The Privacy Rule applies

More information

RISK MANAGEMENT AND BUSINESS CONTINUANCE A FAIS Standard. An AC Guidance Note. July 2010

RISK MANAGEMENT AND BUSINESS CONTINUANCE A FAIS Standard. An AC Guidance Note. July 2010 RISK MANAGEMENT AND BUSINESS CONTINUANCE A FAIS Standard An AC Guidance Nte July 2010 Risk Management and Business Cntinuance - A FAIS standard The General Cde f cnduct deals in a number f ways with the

More information

Data Protection Policy

Data Protection Policy Data Prtectin Plicy PLEASE NOTE: A new Data Prtectin Plicy, cmpliant with the requirements f the Data Prtectin Act 2018 and the Eurpean General Data Prtectin Regulatin (GDPR), is currently underging the

More information

MiFID Supervisory Briefing Appropriateness and execution-only

MiFID Supervisory Briefing Appropriateness and execution-only MiFID Supervisry Briefing Apprpriateness and executin-nly 19 December 2012 ESMA/2012/851 Date: 19 December 2012 ESMA/2012/851 I. Backgrund 1. ESMA is required t play an active rle in building a cmmn supervisry

More information

DATA PROTECTION POLICY FOR PUPILS AND PARENTS

DATA PROTECTION POLICY FOR PUPILS AND PARENTS DATA PROTECTION POLICY FOR PUPILS AND PARENTS This Plicy is relevant t the whle schl including EYFS Cntents 1.0 Intrductin 2.0 Respnsibility fr data prtectin 3.0 Types f persnal data prcessed by the schl

More information

TERMS OF REFERENCE FOR THE PROVISION OF OUTSOURCED INTERNAL AUDIT SERVICE

TERMS OF REFERENCE FOR THE PROVISION OF OUTSOURCED INTERNAL AUDIT SERVICE W&RSETA Standard Bidding Dcuments Terms f Reference TERMS OF REFERENCE FOR THE PROVISION OF OUTSOURCED INTERNAL AUDIT SERVICE 1 W&RSETA Standard Bidding Dcuments Terms f Reference 1. BACKGROUND TO W&RSETA

More information

Terms and Conditions 19 December 2018

Terms and Conditions 19 December 2018 Stck and Shares Lifetime ISA (Prperty Saver) Terms and Cnditins 19 December 2018 These Terms, tgether with the Applicatin Frm, frm a legal agreement between yu and us which sets ut hw the Lifetime ISA

More information

Audit and Risk Management Committee Charter

Audit and Risk Management Committee Charter Audit and Risk Management Cmmittee Charter Pivtal Systems Crpratin ("Cmpany") 1. Objectives The Audit and Risk Management Cmmittee (Cmmittee) has been established by the bard f directrs (Bard) f the Cmpany.

More information

A-1110 Wien. Privacy Notice

A-1110 Wien. Privacy Notice Eurfins Lebensmittelanalytik Tel. +43 (1) 944 33 44-0 ffice@eurfins.at www.eurfins.at Privacy Ntice Table f cntents 1 Cntrller infrmatin... 2 2 What infrmatin shuld yu give Eurfins?... 2 3 Why d we use

More information

PSNC Briefing on the NHS Complaints procedure (from 1 April 2009)

PSNC Briefing on the NHS Complaints procedure (from 1 April 2009) PSNC Briefing n the NHS Cmplaints prcedure (frm 1 April 2009) Under the prvisins f the Natinal Health Service (Pharmaceutical Services) Regulatins 2005 1 pharmacy cntractrs are required t make arrangements

More information

Huntington Bancshares Incorporated

Huntington Bancshares Incorporated Audit Cmmittee Apprved By: Bard f Directrs Huntingtn Bancshares Incrprated Apprval Date 1 f 6 Purpse f Cmmittee The Audit Cmmittee (Cmmittee) is established by the Bard f Directrs (Bard) t assist the Bard

More information

FINANCIAL SERVICES GUIDE

FINANCIAL SERVICES GUIDE PART N: iinvest Securities Financial Services Guide (FSG) FINANCIAL SERVICES GUIDE DATED: Octber 2017 Cntents f this FSG This Financial Services Guide ( FSG ) is an imprtant dcument that iinvest Securities

More information

Information concerning the constitution, goals and functions of the agency, including 1 :

Information concerning the constitution, goals and functions of the agency, including 1 : Annual Reprt cmpliance checklist This checklist utlines the gvernance, perfrmance, reprting cmpliance and prcedural requirements f the Financial Administratin and Audit Act 1977 and the Financial Management

More information

Renewing an Insurance Policy

Renewing an Insurance Policy AGENTS, BROKERS Renewing an Insurance Plicy This renewal prcedure is designed t help representatives respect their bligatins when renewing an insurance plicy. Essentially, these bligatins are spelled ut

More information

PAYMENT BY CARD TERMS & CONDITIONS

PAYMENT BY CARD TERMS & CONDITIONS PAYMENT BY CARD TERMS & CONDITIONS Versin 2.0 - June 2013 Effective frm 1 st June 2013 Issued n 1 st June 2013 Terms & Cnditins fr use f Credit/Debit card fr Payments (POS) Intrductin This Service is ffered

More information

Guidelines and Recommendations Guidelines on periodic information to be submitted to ESMA by Credit Rating Agencies

Guidelines and Recommendations Guidelines on periodic information to be submitted to ESMA by Credit Rating Agencies Guidelines and Recmmendatins Guidelines n peridic infrmatin t be submitted t ESMA by Credit Rating Agencies 23 June 2015 ESMA/2015/609 Table f Cntents 1 Scpe... 3 2 Definitins... 3 3 Purpse f Guidelines...

More information

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Audit Cmmittee Charter St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Versin 3.0, 19 February 2018 Apprver Bard f Directrs St Andrew

More information

Manual of Administrative Policies and Procedures

Manual of Administrative Policies and Procedures Manual f Administrative Plicies and Prcedures POLICY 1.49 Cntract Management and Signing Authrity Plicy Categry: General Related Prcedures: Prcedures fr Negtiating, Apprving and Signing University Cntracts

More information

Guidelines for submission to the NSW Population and Health Services Research Ethics Committee. Version June 2015

Guidelines for submission to the NSW Population and Health Services Research Ethics Committee. Version June 2015 Guidelines fr submissin t the NSW Ppulatin and Health Services Research Versin 3.0 18 June 2015 Cntents Sectin 1: Intrductin... 3 Sectin 2: Research Gvernance... 4 Sectin 3: Submissins t the NSW PHSREC...

More information

Pershing Financial Services Guide (FSG) including its Privacy Policy

Pershing Financial Services Guide (FSG) including its Privacy Policy Pershing Financial Services Guide (FSG) including its Privacy Plicy Issued by Pershing Securities Australia Pty Ltd ABN 60 136 184 962 Australian Financial Services License N. 338 264 Date FSG was prepared:

More information

Approval Process and Arrangements for University Consultancy Work

Approval Process and Arrangements for University Consultancy Work Apprval Prcess and Arrangements fr University Cnsultancy Wrk 1 Intrductin Cnsultancy activities can be separated int tw types: thse undertaken in City s name (University cnsultancy) and thse undertaken

More information

AUDIT & RISK COMMITTEE CHARTER

AUDIT & RISK COMMITTEE CHARTER AUDIT & RISK COMMITTEE CHARTER Rle and Respnsibilities The Bard f The Institute f Internal Auditrs Australia (IIA-Australia) has established a Bard Audit & Risk Cmmittee as part f its respnsibilities in

More information

Record Keeping and Notes in Records for Claims Adjusters

Record Keeping and Notes in Records for Claims Adjusters CLAIMS ADJUSTERS Recrd Keeping and Ntes in Recrds fr Claims Adjusters A claims adjuster s bligatin t keep prper recrds is related t the bligatin t act with cmpetence and prfessinal integrity, as required

More information

Terms of Reference - Board of Directors (approved by the Board on 12 April 2018)

Terms of Reference - Board of Directors (approved by the Board on 12 April 2018) Terms f Reference - Bard f Directrs (apprved by the Bard n 12 April 2018) 1. Respnsibility and Principal Duties The Bard f Directrs has the verall respnsibility fr the gvernance f the Cmpany and fr supervising

More information

Are you ready for the FUTURE of your Quality Management system?

Are you ready for the FUTURE of your Quality Management system? 1 Are yu ready fr the FUTURE f yur Quality Management system? BACKGROUND Quality Management System standard, ISO 9001 has made sme majr changes released in September 2015. Organizatins are studying and

More information

ENQUIRIES : SENIOR MANAGER: LEGAL AND COMPLIANCE MANUAL IN ACCORDANCE WITH THE PROMOTION OF ACCESS TO INFORMATION ACT, 2000 (ACT NO.

ENQUIRIES : SENIOR MANAGER: LEGAL AND COMPLIANCE MANUAL IN ACCORDANCE WITH THE PROMOTION OF ACCESS TO INFORMATION ACT, 2000 (ACT NO. CS DIRECTIVE 1/2016 PROMULGATED BY : COMPANY SECRETARY EFFECTIVE FROM : 22 APRIL 2016 ENQUIRIES : SENIOR MANAGER: LEGAL AND COMPLIANCE APPLICABLE TO : ALL ATNS EMPLOYEES MANUAL IN ACCORDANCE WITH THE PROMOTION

More information

Europa Group Privacy Policy

Europa Group Privacy Policy Eurpa Grup Privacy Plicy The privacy and security f yur persnal infrmatin is very imprtant t us (Eurpa Grup). This plicy explains hw we cllect and use yur persnal infrmatin. Please read it carefully. This

More information

Privacy Notice for Applicants and Tenants

Privacy Notice for Applicants and Tenants Privacy Ntice fr Applicants and Tenants What we need Scttish Brders Husing Assciatin (SBHA) will be a "cntrller" f the persnal infrmatin that yu prvide t us thrugh yur cmpleted Husing Applicatin Frm, and

More information

This financial planning agreement (the Agreement ) is made on this date: between the undersigned party, whose mailing address is

This financial planning agreement (the Agreement ) is made on this date: between the undersigned party, whose mailing address is F I N A N C I A L P L A N N I N G A G R E E M E N T This financial planning agreement (the Agreement ) is made n this date: between the undersigned party, CLIENT(s): whse mailing address is (hereinafter

More information

STATE OF NEW YORK MUNICIPAL BOND BANK AGENCY

STATE OF NEW YORK MUNICIPAL BOND BANK AGENCY STATE OF NEW YORK MUNICIPAL BOND BANK AGENCY Recvery Act Bnd Prgram Written Prcedures fr Tax Cmpliance and Internal Mnitring, adpted September 12, 2013 PROGRAM OVERVIEW The State f New Yrk Municipal Bnd

More information

Data Protection Code of Practice

Data Protection Code of Practice Data Prtectin Cde f Practice Data Prtectin Cde f Practice 1 1 Intrductin 1.1 This Cde f Practice has been apprved by the Bard f Gvernrs f Sussex Cast Cllege Hastings as part f its cmmitment t its legal

More information

TERMS OF REFERENCE. Audit and Risk Committee (the "Committee") of Wilmcote Holdings Plc (the "Company")

TERMS OF REFERENCE. Audit and Risk Committee (the Committee) of Wilmcote Holdings Plc (the Company) References t the "Bard" shall mean the full Bard f Directrs. MEMBERSHIP - The Bard has reslved t establish a cmmittee f the Bard t be knwn as the Audit and Risk Cmmittee. - The Cmmittee shall cmprise at

More information

MiFID Supervisory Briefing Suitability

MiFID Supervisory Briefing Suitability MiFID Supervisry Briefing Suitability 19 December 2012 ESMA/2012/850 Date: 19 December 2012 ESMA/2012/850 I. Backgrund 1. ESMA is required t play an active rle in building a cmmn supervisry culture by

More information

The Company is a public company incorporated in Bermuda and its securities are listed on AIM.

The Company is a public company incorporated in Bermuda and its securities are listed on AIM. (Incrprated in Bermuda Registratin N. 44512) POLICY FOR TRADING IN COMPANY SECURITIES The Cmpany is a public cmpany incrprated in Bermuda and its securities are listed n AIM. Schedule 1 t this Plicy cntains

More information

UK Employment Law Changes in 2010: New Statutory Rates, Limits and Entitlements

UK Employment Law Changes in 2010: New Statutory Rates, Limits and Entitlements February 2010 UK Emplyment Law Changes in 2010: New Statutry Rates, Limits and Entitlements BY CHRIS BRACEBRIDGE AND ANNA SANFORD At a Glance Varius changes t emplyment related cmpensatin, benefit and

More information

NESA School Governance Compliance Requirements supporting the NSW Education Act 1990

NESA School Governance Compliance Requirements supporting the NSW Education Act 1990 NESA Schl Gvernance Cmpliance Requirements supprting the NSW Educatin Act 1990 NSW Educatin Standards Authrity (NESA) Registratin Systems and Member Nn-gvernment Schls (NSW) Manual (Refer t Schl Gvernance

More information

Handling Complaints at Lloyd s: Guidance for managing agents and their representatives

Handling Complaints at Lloyd s: Guidance for managing agents and their representatives Cmplaints May 2017 Llyd s cmplaints Handling Cmplaints at Llyd s: Guidance fr managing agents and their representatives This guidance nte prvides a practical prcess fr handling UK cmplaints received frm

More information

AusNet Electricity Services Pty Ltd. Information Sharing Protocol and Register

AusNet Electricity Services Pty Ltd. Information Sharing Protocol and Register AusNet Electricity Services Pty Ltd Infrmatin Sharing Prtcl and Register 1 BACKGROUND This is AusNet Electricity Distributin Pty Ltd s ( DNSP s) infrmatin sharing prtcl, and infrmatin sharing register,

More information

Audit & Risk Committee Charter

Audit & Risk Committee Charter Audit & Risk Cmmittee Charter AUDIT & RISK COMMITTEE CHARTER The Audit & Risk Cmmittee has been established by reslutin f the Bard f Macmahn Hldings Limited ( Macmahn r the Cmpany ). Membership The Audit

More information

Producer Statements will be accepted only in accordance with this policy.

Producer Statements will be accepted only in accordance with this policy. Prducer Statements Plicy This plicy has been prepared t ensure that Cuncil has clearly dcumented plicies and prcedures fr the request fr and acceptance f Prducer Statements in cnnectin with applicatins

More information

Summary Plan Descriptions (SPD)

Summary Plan Descriptions (SPD) Descriptins (SPD) SPDs What Are They and Wh Needs Them? What is an SPD? The DOL defines the SPD as the Primary vehicle fr infrming participants and beneficiaries abut their plan and hw it perates. Must

More information

Triodos Bank. UK Recruitment Privacy Statement

Triodos Bank. UK Recruitment Privacy Statement Trids Bank. UK Recruitment Privacy Statement The Trids Bank UK (TBUK) recruitment Privacy Statement prvides transparency n hw yur persnal data will be cllected and used during the recruitment and selectin

More information

DATA PROTECTION POLICY: PUPILS AND PARENTS

DATA PROTECTION POLICY: PUPILS AND PARENTS DATA PROTECTION POLICY: PUPILS AND PARENTS 1 Abut this Plicy The privacy f ur pupils and parents is very imprtant t the schl and we have taken steps t prtect it. This plicy explains hw we use (r "prcess")

More information

NUMBER: BUSF 3.30 Business and Finance. Other Educational and General Program Accounts ("E" Funds) Date: October 18, 2006 I. PURPOSE OF THE POLICY

NUMBER: BUSF 3.30 Business and Finance. Other Educational and General Program Accounts (E Funds) Date: October 18, 2006 I. PURPOSE OF THE POLICY NUMBER: BUSF 3.30 SECTION: Business and Finance SUBJECT: Other Educatinal and General Prgram Accunts ("E" Funds) Date: Octber 18, 2006 Plicy fr: Prcedure fr: Authrized by: Issued by: All Campuses All Campuses

More information

What credit related information do we collect and hold and how do we collect it?

What credit related information do we collect and hold and how do we collect it? In this Credit Reprting Plicy, ORIX, we, us and ur mean ORIX Australia Crpratin Limited and ur related cmpanies. Thse related cmpanies may als have their wn privacy r credit reprting plicies which set

More information

2.6 When introducing new systems, care must be taken to ensure:

2.6 When introducing new systems, care must be taken to ensure: Appendix 3 SRA Guidelines Accunting Prcedures and Systems 1. Intrductin 1.1 These guidelines, published under rule 26 f the SRA Accunts Rules 2011, are intended t be a benchmark r brad statement f gd practice

More information

LMA GUIDANCE: GDPR CORE USES INFORMATION NOTICE

LMA GUIDANCE: GDPR CORE USES INFORMATION NOTICE LMA GUIDANCE: GDPR CORE USES INFORMATION NOTICE FEBRUARY 2018 NOTE: This guidance and the Lndn Market Cre Uses Infrmatin Ntice will be updated when the UK Data Prtectin Bill is enacted the Bill currently

More information

JAUPT Appraisal Criteria Centre Application. November 2016

JAUPT Appraisal Criteria Centre Application. November 2016 JAUPT Appraisal Criteria Centre Applicatin Nvember 2016 1. Intrductin T be able t assess centre applicatins fr the suitability f Peridic Training many factrs have t be taken int accunt and cnsidered befre

More information

Audit Committee Charter

Audit Committee Charter Audit Cmmittee Charter I. Purpse f Audit Cmmittee The purpse f the Audit Cmmittee, which is part f the Bard, shall be (a) t assist the Bard s versight f (i) the integrity f the Cmpany s financial statements,

More information

AUDIT COMMITTEE CHARTER

AUDIT COMMITTEE CHARTER AUDIT COMMITTEE CHARTER WBHO Audit Cmmittee Charter Page 1 f 9 Intrductin The Audit Cmmittee is cnstituted as a statutry cmmittee f the Cmpany in respect f its statutry duties in terms f Sectin 94(1) f

More information

Article 5.2 of the Grant Agreement (GA) defines forms of costs and how they can be applied to the different budget categories.

Article 5.2 of the Grant Agreement (GA) defines forms of costs and how they can be applied to the different budget categories. Fact Sheet 1.1 Overview f eligible csts per budget categry This Fact Sheet shall serve the EUROfusin beneficiaries and linked third parties as a guideline. It shall neither cnstitute a legally binding

More information

Work Instruction. for Change Management. Work Instruction Administrator John Doe Chief Corporeal Officer ACME

Work Instruction. for Change Management. Work Instruction Administrator John Doe Chief Corporeal Officer ACME Wrk Instructin fr Change Management Wrk Instructin Administratr Jhn De Chief Crpreal Officer Wrk Instructin Authr Benjamin M.A. Rbsn Directr f Operatins IPSec Pty Ltd Date f Last Update 3/05/2011 12 Mrtuary

More information

MIFID Policy Client classification

MIFID Policy Client classification MIFID Plicy Client classificatin Page 1 f 8 Cntents 1. Intrductin... 3 2. Purpse... 3 3. Client Classificatin... 5 a) Eligible cunterparties... 5 b) Prfessinal clients... 6 c) Retail clients... 8 d) Classificatin

More information

Risk and Audit Committee charter

Risk and Audit Committee charter Risk and Audit Cmmittee charter 1. Intrductin The Bard f Cffey Internatinal Limited ( Cffey r the Cmpany ) has established a Risk and Audit Cmmittee ( Cmmittee ). It is nted that the Cmmittee is a sub-cmmittee

More information

Details of Rate, Fee and Other Cost Information

Details of Rate, Fee and Other Cost Information Details f Rate, Fee and Other Cst Infrmatin Accunt terms are nt guaranteed fr any perid f time. All terms, including fees and APRs fr new transactins, may change in accrdance with the Credit Card Agreement

More information

COMPLAINTS POLICY ARUNSIDE PRIMARY SCHOOL. POLICY ADOPTED: 20 th JUNE 2016 THE POLICY IS TO BE REVIEWED: November 2017

COMPLAINTS POLICY ARUNSIDE PRIMARY SCHOOL. POLICY ADOPTED: 20 th JUNE 2016 THE POLICY IS TO BE REVIEWED: November 2017 COMPLAINTS POLICY ARUNSIDE PRIMARY SCHOOL POLICY ADOPTED: 20 th JUNE 2016 THE POLICY IS TO BE REVIEWED: Nvember 2017 Arunside Primary Schl Blackbridge Lane West Sussex RH12 1RR Cmplaints Plicy (Parents

More information

WHOLESALE AND RETAIL SETA. Skills Development for Economic Growth. ETQA Assessor and Moderator Registration Policy

WHOLESALE AND RETAIL SETA. Skills Development for Economic Growth. ETQA Assessor and Moderator Registration Policy WHOLESALE AND RETAIL SETA Skills Develpment fr Ecnmic Grwth ETQA Assessr and Mderatr Registratin Plicy WHOLESALE AND RETAIL SETA ETQA ASSESSOR AND MODERATOR POLICY Effective Date: 00/00/2007 Dc ID: Rev:

More information

Best Execution Policy. Version: July 2018

Best Execution Policy. Version: July 2018 Best Executin Plicy Versin: 3.0 18 July 2018 Next Review Date: 1 Octber 2018 Cntents 1 Intrductin... 4 2 Review f plicy... 4 3 Best Executin... 4 3.1 Summary f Best Executin... 4 3.2 Delivery f Best Executin...

More information

Environmental Health & Safety Requirements for Master Agreement of Services

Environmental Health & Safety Requirements for Master Agreement of Services Envirnmental Health & Safety Requirements fr Master Agreement f Services If Cntractr emplyees will perfrm Services n any Michelin premises, Cntractr must cmply with the fllwing requirements: Cmply with

More information

Subject Access Requests

Subject Access Requests Subject Access Requests The Data Prtectin Act 1998 gives rights t individuals in respect f the persnal data that rganisatins hld abut them. One f thse rights is the right t get a cpy f the infrmatin that

More information

RECRUITMENT & SELECTION PRIVACY NOTICE May 2018

RECRUITMENT & SELECTION PRIVACY NOTICE May 2018 This ntice explains hw Biffa cllects and uses persnal data during the recruitment and selectin prcess. The Table at the end f this ntice prvides an verview f the persnal data that we cllect, the purpses

More information

NCTJ Conflicts of Interest Policy and Procedures

NCTJ Conflicts of Interest Policy and Procedures NCTJ Cnflicts f Interest Plicy and Prcedures Purpse This plicy aims t draw attentin t the pssibility f cnflicts, minimise r prevent a cnflict ccurring and manage cnflicts that have arisen. Definitin f

More information

International Standard on Auditing (Ireland) 265. Communicating Deficiencies in Internal Control to Those Charged with Governance and Management

International Standard on Auditing (Ireland) 265. Communicating Deficiencies in Internal Control to Those Charged with Governance and Management Internatinal Standard n Auditing (Ireland) 265 Cmmunicating Deficiencies in Internal Cntrl t Thse Charged with Gvernance and Management MISSION T cntribute t Ireland having a strng regulatry envirnment

More information

Best Execution & Client Order Execution Policy. October P age 1 6. BE31/10/17 v1

Best Execution & Client Order Execution Policy. October P age 1 6. BE31/10/17 v1 Best Executin & Client Order Executin Plicy Octber 2017 BE31/10/17 v1 P age 1 6 Cntents 1. Backgrund... 3 2. Order placement... 3 3. Order executin factrs... 3 4. Order executin plicy... 3 5. Order executin

More information

Accord Group Privacy Policy

Accord Group Privacy Policy Accrd Grup (WA) Pty Ltd CERTIFIED PRACTISING ACCOUNTANTS ABN: 96 210 970 944 William Murray Huse 92 Wray Avenue FREMANTLE WA 6160 PO Bx 236 FREMANTLE WA 695 Email: accrdwa@accrdwa.cm.au Telephne: (08)

More information

BECCLES INDOOR BOWLS CLUB

BECCLES INDOOR BOWLS CLUB . BECCLES INDOOR BOWLS CLUB PRIVACY NOTICE FOR OUR MEMBERS We are cmmitted t respecting yur privacy. This ntice is t explain hw we may use persnal infrmatin we cllect befre, during and after yur membership

More information

TRID Rule Purchase For Applications dated on or after 10/3/2015

TRID Rule Purchase For Applications dated on or after 10/3/2015 Fr Applicatins dated n r after 10/3/2015 This dcument prvides a brief verview f the TRID Rule s requirements and specifies the purchase requirements fr CMG Mrtgage, Inc., dba CMG Financial, (CMG). CMG

More information

[AGENCY NAME] Mandate and Roles Document. (Pure Advisory Committees)

[AGENCY NAME] Mandate and Roles Document. (Pure Advisory Committees) [This sample dcument has been develped by the Agency Gvernance Secretariat. It is intended t be used fr infrmatinal purpses nly. Agencies are encuraged t adapt the dcument t meet their specific needs.

More information

School Business Manager

School Business Manager Plicy Title: Risk Assessment Plicy Authr: Schl Business Manager Audience: Staff Reviewed by: Gvernrs Review frequency: Annual Reviewed when: Octber 2016 Risk Assessment Plicy Intrductin Nrthease Manr Schl

More information

Using the Work of an Auditor s Expert

Using the Work of an Auditor s Expert SINGAPORE STANDARD ON AUDITING SSA 620 Using the Wrk f an Auditr s Expert This SSA 620 supersedes SSA 620 Using the Wrk f an Expert in September 2009. Auditrs are required t cmply with the auditing standards

More information

Overview of Statements of Investment Policies and Procedures (SIPP) Requirements

Overview of Statements of Investment Policies and Procedures (SIPP) Requirements Financial Services Cmmissin f Ontari Cmmissin des services financiers de l Ontari SECTION: INDEX NO.: TITLE: APPROVED BY: PUBLISHED: Investment Guidance Ntes IGN-005 Overview f Statements f Investment

More information

ANNEX III FINANCIAL AND CONTRACTUAL RULES I. RULES APPLICABLE TO BUDGET CATEGORIES BASED ON UNIT CONTRIBUTIONS

ANNEX III FINANCIAL AND CONTRACTUAL RULES I. RULES APPLICABLE TO BUDGET CATEGORIES BASED ON UNIT CONTRIBUTIONS 2016_KA2_ Annex 3_EB.dcx ANNEX III FINANCIAL AND CONTRACTUAL RULES I. RULES APPLICABLE TO BUDGET CATEGORIES BASED ON UNIT CONTRIBUTIONS I.1 Cnditins fr eligibility f unit cntributins Where the grant takes

More information

CORPORATE GOVERNANCE POLICY

CORPORATE GOVERNANCE POLICY CORPORATE GOVERNANCE POLICY Bard Missin Sagicr Real Estate X Fund Limited ( X Fund r the Cmpany ) was incrprated in 2011 under the laws f St. Lucia as an Internatinal Business Cmpany (IBC). X Fund is cmmitted

More information

How to Become a Delaware Public Benefit Corporation

How to Become a Delaware Public Benefit Corporation Hw t Becme a Delaware Public Benefit Crpratin This utline describes the majr steps required fr an existing Delaware crpratin t becme a Delaware public benefit crpratin. 1. Summary. In rder t becme a public

More information

TERMS AND CONDITIONS FOR APPOINTMENT OF INDEPENDENT DIRECTOR

TERMS AND CONDITIONS FOR APPOINTMENT OF INDEPENDENT DIRECTOR TERMS AND CONDITIONS FOR APPOINTMENT OF INDEPENDENT DIRECTOR 1 PRIVATE & CONFIDENTIAL Date: T, Independent Directrs, Subject: Appintment as an Independent Directr InfBeans Technlgies Limited Dear Sir/Madam,

More information

SRI LANKA AUDITING STANDARD 580 WRITTEN REPRESENTATIONS CONTENTS

SRI LANKA AUDITING STANDARD 580 WRITTEN REPRESENTATIONS CONTENTS SRI LANKA AUDITING STANDARD 580 WRITTEN REPRESENTATIONS (Effective fr audits f financial statements fr perids beginning n r after 01 January 2014) CONTENTS Paragraph Intrductin Scpe f this SLAuS... 1-2

More information

TASSAL GROUP LIMITED ABN Procedures for the Oversight and Management of Material Business Risks. (Approved by the Board 28 May 2015)

TASSAL GROUP LIMITED ABN Procedures for the Oversight and Management of Material Business Risks. (Approved by the Board 28 May 2015) Prcedures fr the Oversight and Management f Material Business Risks TASSAL GROUP LIMITED ABN 15 106 067 270 Prcedures fr the Oversight and Management f Material Business Risks (Apprved by the Bard 28 May

More information

CODE OF CONDUCT AND ETHICS POLICY ON CONFLICTS OF INTEREST

CODE OF CONDUCT AND ETHICS POLICY ON CONFLICTS OF INTEREST CODE OF CONDUCT AND ETHICS POLICY ON CONFLICTS OF INTEREST Magna Internatinal Inc. Plicy n Gifts & Entertainment 1 POLICY ON CONFLICTS OF INTEREST Magna emplyees have a duty t act in Magna s best interest.

More information

ARIZONA FIRE DISTRICT ASSOCIATION FINANCIAL PROCEDURES POLICY

ARIZONA FIRE DISTRICT ASSOCIATION FINANCIAL PROCEDURES POLICY FINANCIAL PROCEDURES POLICY 1. PURPOSE The purpse f these Financial Prcedures is t prvide cnsistent applicatin f cnduct and prper internal cntrls t safeguard the assets f the Arizna Fire District Assciatin

More information

JOHN L. LITTLE, D.D.S, P.A ACKNOWLEDGEMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES. May Refuse to Sign This Acknowledgement-

JOHN L. LITTLE, D.D.S, P.A ACKNOWLEDGEMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES. May Refuse to Sign This Acknowledgement- JOHN L. LITTLE, D.D.S, P.A ACKNOWLEDGEMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES -Yu I, Privacy Practices. May Refuse t Sign This Acknwledgement- ---, have received a cpy f this ffice's Ntice f {Please

More information

This Privacy Notice applies to La Prairie employees, applicants and, where applicable, to contractors who provide services to La Prairie.

This Privacy Notice applies to La Prairie employees, applicants and, where applicable, to contractors who provide services to La Prairie. EMPLOYEE PRIVACY NOTICE Last updated 24 May, 2018. What des this ntice cver? References in this Privacy Ntice t La Prairie, we r us shall mean the La Prairie grup cmpany t which yu are applying r by which

More information

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF PLURALSIGHT, INC. Adopted May 3, 2018

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF PLURALSIGHT, INC. Adopted May 3, 2018 CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF PLURALSIGHT, INC. Adpted May 3, 2018 PURPOSE The purpse f the Cmpensatin Cmmittee (the Cmpensatin Cmmittee ) f the Bard f Directrs (the

More information

Welcome. 1.Identification. 2.Accuracy of content

Welcome. 1.Identification. 2.Accuracy of content Welcme We are delighted t welcme yu t Samsnite s Service Prtal (hereinafter referred t as the "Site"), the fficial nline stre fr spare parts. We ask yu t take the time t read these terms and cnditins carefully.

More information

Alabama Department of Revenue Driver Or Vehicle Data Information Request

Alabama Department of Revenue Driver Or Vehicle Data Information Request Alabama Interactive, Inc 104 Nrth Jacksn Street Mntgmery, AL 36104 (866) 353-EGOV www.alabamainteractive.rg subscriptins@alabamainteractive.rg Alabama Department f Revenue Driver Or Vehicle Data Infrmatin

More information

Trustee Benefits. 1. Expense payments

Trustee Benefits. 1. Expense payments Trustee Benefits 1. Expense payments Expenses shuld be reasnable in the cntext f a charity s assets and resurces, and prperly incurred in the furtherance f a charity s activities. They are generally always

More information

Risk Management Policy

Risk Management Policy Risk Management Plicy 1. Purpse The purpse f this plicy is t prvide clear guidelines fr the management f risk. Risk is defined as the effect f uncertainty n bjectives. 1 Risk Management is the discipline

More information

International Complaints Handling: New Procedures in Italy. To advise of new complaints handling arrangements for Italy

International Complaints Handling: New Procedures in Italy. To advise of new complaints handling arrangements for Italy market bulletin Ref: Y5041 Title Purpse Type Frm Internatinal Cmplaints Handling: New Prcedures in Italy T advise f new cmplaints handling arrangements fr Italy Event Paul Brady Head f Market Cnduct Date

More information

May Audit and Compliance Program Charter

May Audit and Compliance Program Charter May 2015 Audit and Cmpliance Prgram Charter TABLE OF CONTENTS PAGE 1.0 BACKGROUND 2 2.0 AUDIT AND COMPLIANCE ASSESSMENT 2 3.0 KEY LEGISLATIVE AUTHORITY AND POWERS 4 4.0 VALUES 5 5.0 STEPS IN THE ASSESSMENT

More information

Summary Plan Descriptions

Summary Plan Descriptions Summary Plan Descriptins All grup health plans subject t the Emplyee Retirement Incme Security Act (ERISA) are required t prvide participants with a Summary Plan Descriptin (SPD). An SPD must be written

More information

Documentation / Other important Standards with SME perspective

Documentation / Other important Standards with SME perspective Dcumentatin / Other imprtant Standards with SME perspective SME - Definitin f MSMEs in India (As Per Micr, Small & Medium Enterprises Develpment (MSMED) Act, 2006) Manufacturing Enterprises Investment

More information

Trust Research & Innovation Standard Operating Procedure

Trust Research & Innovation Standard Operating Procedure Title f Standard Operating Prcedure: Dcument Summary: Dcument Authr: Target Audience: Cnsultatin: Apprval Cmmittee: Crss Reference Dcument(s): Assciated Trust Dcuments Cntact details fr further infrmatin:

More information

Summary Plan Descriptions (SPDs)

Summary Plan Descriptions (SPDs) Prvided by McGriff Insurance Services, Inc., McGriff, Seibels & Williams, Inc., BB&T Insurance Services f Califrnia, Inc., and Precept Insurance Slutins, LLC Summary Plan Descriptins (SPDs) Delivery Requirements:

More information

THE CLOROX COMPANY AUDIT COMMITTEE CHARTER. [Effective May 8, 2017]

THE CLOROX COMPANY AUDIT COMMITTEE CHARTER. [Effective May 8, 2017] THE CLOROX COMPANY AUDIT COMMITTEE CHARTER [Effective May 8, 2017] PURPOSE AND AUTHORITY The Audit Cmmittee ( Cmmittee ) is established by the Bard f Directrs ( Bard ) fr the purpses f: 1. Representing

More information

AUDIT, RISK MANAGEMENT AND COMPLIANCE COMMITTEE CHARTER

AUDIT, RISK MANAGEMENT AND COMPLIANCE COMMITTEE CHARTER AUDIT, RISK MANAGEMENT AND COMPLIANCE COMMITTEE CHARTER August 2012 OPUS Grup Limited Audit, Risk Management and Cmpliance Cmmittee 1. GENERAL PURPOSE The primary bjective f the Audit, Risk Management

More information

Policy Coversheet. Link Tutors: appointment and responsibilities

Policy Coversheet. Link Tutors: appointment and responsibilities Plicy Cversheet Name f Plicy: Link Tutrs: appintment and respnsibilities Purpse f Plicy: Intended audience(s): Apprval fr this plicy given by: T utline the arrangements fr the appintment f University Link

More information

Clearing arrangements

Clearing arrangements Rules Ntice Guidance Nte Dealer Member Rules Please distribute internally t: Internal Audit Legal and Cmpliance Operatins Regulatry Accunting Senir Management Cntact: Richard J. Crner Vice President, Member

More information

Independent Director and Audit Committee

Independent Director and Audit Committee Independent Directr and Audit Cmmittee Rules summary The listed cmpany s bard f directrs is representing the sharehlders. They are respnsible fr making decisins n the cmpany s imprtant plicies and strategies.

More information