The UK has finalised a new International Data Transfer Agreement to be used for transfers of personal data abroad. Simultaneously, an addendum to the EU Standard Contractual Clauses, currently used fo...
New Standard Contractual Clauses Required for EU Personal Data Transfers
Personal data cannot legally be transferred outside the EU/EEA (European Economic Area), or indeed the UK, without specific legal safeguards in place, unless the country in question has been deemed to...
UK Data Protection Changes to Affect Doing Business Abroad
The UK government has unveiled plans for a new global data transfer regime, suggesting deviations will occur from the current EU-aligned practices. UK Digital Secretary, Oliver Dowden, has stated that...
Rules for employers wanting to check employees’ vaccination status
With many employees starting to return to the office, employers must consider how to manage this effectively and in accordance with the law. The Information Commissioner’s Office (ICO) has published...
Obtain valid consent for direct marketing to avoid fines
American Express has been fined £90,000 by UK data protection regulator, the ICO, for unlawfully sending more than 4 million unsolicited direct marketing emails, without having first obtained valid c...
EU grants data adequacy decision in favour of UK (for now)…
With the temporary bridging period ending, the EU has finally ruled that UK data protection laws are ‘adequate’ for the purposes of transfers of personal data across borders. This will come as a h...
Key Documents your Company Needs to Demonstrate GDPR Compliance
Under the UK General Data Protection Regulation (GDPR) there are hefty fines for non-compliance, of up to 4% of global annual turnover or £17.5 million, whichever is the higher. Data protection is th...
What to do in the event of a personal data breach (hint: you have 72 hours to act, but don’t panic)
A breach of security which leads to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, constitutes a data breach, whether accidental or deliberate. The breach ...
Replacement Standard Contractual Clauses Adopted for Personal Data Transfers
The European Commission (‘EC’) has announced its adoption of a new version of Standard Contractual Clauses (‘SCCs’) for use between entities transferring personal data to countries outside of ...
Check whether you need to appoint a Data Protection Representative post-Brexit and avoid fines
Earlier this month, a company based outside of the EU, Locatefamily.com, was fined €525,000 for failing to appoint a Data Protection Representative (DPR). This highlights the importance of not overl...