The EU and US have announced an “agreement in principle” of a new Privacy Shield that will allow the simpler movement of personal data between entities based in the respective jurisdictions. Since...
New UK International Data Transfer Mechanism to be used from March 2022
The UK has finalised a new International Data Transfer Agreement to be used for transfers of personal data abroad. Simultaneously, an addendum to the EU Standard Contractual Clauses, currently used fo...
Supreme Court’s decision in £3billion data privacy case may come as a relief for data controllers
The Supreme Court has handed down their eagerly awaited decision in the £3billion case of Lloyd v Google. The court blocked the claim by Richard Lloyd, representing 4 million iPhone users, from proce...
New Standard Contractual Clauses Required for EU Personal Data Transfers
Personal data cannot legally be transferred outside the EU/EEA (European Economic Area), or indeed the UK, without specific legal safeguards in place, unless the country in question has been deemed to...
Children’s Privacy – New Requirements for Business providing Online Services
A statutory Code of Practice, the Age Appropriate Design Code, (known as ‘The Children’s Code’) has come into effect in the UK and, post 2 September 2021, businesses must ensure they comply with...
UK Data Protection Changes to Affect Doing Business Abroad
The UK government has unveiled plans for a new global data transfer regime, suggesting deviations will occur from the current EU-aligned practices. UK Digital Secretary, Oliver Dowden, has stated that...
Rules for employers wanting to check employees’ vaccination status
With many employees starting to return to the office, employers must consider how to manage this effectively and in accordance with the law. The Information Commissioner’s Office (ICO) has published...
Obtain valid consent for direct marketing to avoid fines
American Express has been fined £90,000 by UK data protection regulator, the ICO, for unlawfully sending more than 4 million unsolicited direct marketing emails, without having first obtained valid c...
EU grants data adequacy decision in favour of UK (for now)…
With the temporary bridging period ending, the EU has finally ruled that UK data protection laws are ‘adequate’ for the purposes of transfers of personal data across borders. This will come as a h...
Key Documents your Company Needs to Demonstrate GDPR Compliance
Under the UK General Data Protection Regulation (GDPR) there are hefty fines for non-compliance, of up to 4% of global annual turnover or £17.5 million, whichever is the higher. Data protection is th...