The UK government is currently considering proposals to reform the data protection regulations in the UK. Generally, there appears to be a move to a more practical and pragmatic privacy compliance sys...
Fines for non-compliant use of website cookies are on the rise. Don’t be caught out.
There have been numerous instances recently of data privacy regulators issuing organisations with fines for non-compliantly utilising cookies on their websites, without the user’s prior consent. It ...
New UK International Data Transfer Mechanism to be used from March 2022
The UK has finalised a new International Data Transfer Agreement to be used for transfers of personal data abroad. Simultaneously, an addendum to the EU Standard Contractual Clauses, currently used fo...
New Standard Contractual Clauses Required for EU Personal Data Transfers
Personal data cannot legally be transferred outside the EU/EEA (European Economic Area), or indeed the UK, without specific legal safeguards in place, unless the country in question has been deemed to...
UK Data Protection Changes to Affect Doing Business Abroad
The UK government has unveiled plans for a new global data transfer regime, suggesting deviations will occur from the current EU-aligned practices. UK Digital Secretary, Oliver Dowden, has stated that...
Rules for employers wanting to check employees’ vaccination status
With many employees starting to return to the office, employers must consider how to manage this effectively and in accordance with the law. The Information Commissioner’s Office (ICO) has published...
Obtain valid consent for direct marketing to avoid fines
American Express has been fined £90,000 by UK data protection regulator, the ICO, for unlawfully sending more than 4 million unsolicited direct marketing emails, without having first obtained valid c...
EU grants data adequacy decision in favour of UK (for now)…
With the temporary bridging period ending, the EU has finally ruled that UK data protection laws are ‘adequate’ for the purposes of transfers of personal data across borders. This will come as a h...
Key Documents your Company Needs to Demonstrate GDPR Compliance
Under the UK General Data Protection Regulation (GDPR) there are hefty fines for non-compliance, of up to 4% of global annual turnover or £17.5 million, whichever is the higher. Data protection is th...
What to do in the event of a personal data breach (hint: you have 72 hours to act, but don’t panic)
A breach of security which leads to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, constitutes a data breach, whether accidental or deliberate. The breach ...