Author Archive

« Older Entries | Newer Entries »

Checklist: Trial/POC

Before committing to a purchase and full deployment, a prospective customer may require a trial or ‘proof of concept’ (POC) of the supplier’s technology.  Although a trial will be limited in both duration and scope, many of the implementation, licensing, data processing and liability issues that apply to full deployment will also apply to a trial.

Issues to consider when negotiating a trial/POC agreement include:

  1. How long will the trial continue?  Does the customer have an option to extend the trial?
  2. What is the scope of the trial?  Is the trial limited to a testing or staging environment, or is the customer entitled to deploy the technology in a live, production environment?
  3. Will the customer provide the supplier with formal feedback during or following the trial? Will the supplier be entitled to use data from the trial and/or customer feedback for marketing purposes?
  4. Is the customer paying for the trial? Can the customer deduct the trial payment against the charges for a purchase of a full deployment?
  5. If the trial involves the use of any supplier hardware or other equipment, who is responsible for any loss or damage during the trial?
  6. Does the trial involve the processing of the customer’s personal data, and require data processing terms to be agreed?

Tags: , ,
Posted in Uncategorised | Comments Off on Checklist: Trial/POC

EU-UK data transfers from 1st January 2021 – where are we?

29/12/20 – Prior to the announcement of the EU-UK Trade and Cooperation Agreement [1], I was having to explain to a client that it was looking increasing likely that, from 1st January 2021, transfers of personal data from organisations located in EEA countries to the UK would no longer be lawful. (more…)

Tags: , , , , ,
Posted in Privacy, Updates | Comments Off on EU-UK data transfers from 1st January 2021 – where are we?

European Commission publishes new draft SCCs for consultation

19/11/20 – By way of background, transfers of EU citizens’ personal data to locations outside the European Economic Area (EEA) require a GDPR-permitted transfer mechanism. (more…)

Tags: , , , , , ,
Posted in Privacy, Updates | Comments Off on European Commission publishes new draft SCCs for consultation

Special category data – what do I need to know?

Ok, let’s start with the basics.  What is ‘special category data’?

Article 9 of the GDPR (as incorporated into UK law, and amended) (“UK GDPR”) defines special category data as:

In short, special category data is personal data that needs more protection because it is sensitive.

And what does ‘more protection’ mean?

It means that, in addition to ensuring that the processing is generally lawful, fair and transparent, and that it complies with all the other principles and requirements of the UK GDPR, you must comply with the following requirements:

  1. Prior to processing any special category data, you must not only identify and document a lawful basis under Article 6 (as required for all processing of personal data), but you must also satisfy at least one of the conditions for processing special category data listed in Article 9.
  2. Of the 10 conditions for processing special category data in Article 9, five require you to meet additional conditions and safeguards set out in Schedule 1 of the Data Protection Act 2018 (“Schedule 1 conditions”).   For some Schedule 1 conditions you also need to put in place an ‘appropriate policy document’.  The ICO has provided an appropriate policy document template.
  3. In practice, you may need to use the explicit consent condition for the special category data processing (Article 9(2)(a)).  If so, then bear in mind that the individual’s consent must be:
    • freely given
    • specific, i.e. it must specify the nature of the special category data, and be separate from any other consents
    • affirmative, i.e. opt-in
    • unambiguous
    • capable of being withdrawn at any time.
  4. Article 35 requires you to do a Data Protection Impact Assessment (DPIA) for any type of processing that “is likely to result in a high risk to the rights and freedoms of natural persons”.  This is more likely to be the case when processing special category data.
  5. Article 30 requires controllers to maintain a record of processing activities.  The exemption from this obligation for organisations employing fewer than 250 persons (Article 30(5)) does not apply where the processing includes special categories of data.
  6. Update your privacy notice with specific information about your processing of special category data.

 

 

Tags: , , , , , , ,
Posted in Privacy, Updates | Comments Off on Special category data – what do I need to know?

EDPB Guidelines on controllers and processors

21/09/20 – On 2 September 2020, the European Data Protection Board (EDPB) adopted ‘Guidelines 07/2020 on the concepts of controller and processor in the GDPR’.  The Guidelines deal with the principles underpinning the differences between controllers and processors, and also delve into the more esoteric world of joint controllers. (more…)

Posted in Updates | Comments Off on EDPB Guidelines on controllers and processors

Demise of the EU-U.S. Privacy Shield

23/07/20 – If you, as a ‘data exporter’, want to transfer personal data to a country outside the EEA (and which is not one of the 12 countries that have been granted an adequacy decision by the European Commission), then you need to use one of the GDPR-approved ‘transfer mechanisms’. (more…)

Tags: , , , , , , ,
Posted in Privacy, Updates | Comments Off on Demise of the EU-U.S. Privacy Shield

The P2B Regulation – regulating the e-commerce gatekeepers

13/07/20 – The EU Platform to Business Regulation (the ‘P2B Regulation’) came into effect on 12 July 2020.  The P2B Regulation applies to all online platforms and search engines which provide services to business users in the EU, where those business users offer goods or services to consumers in the EU. (more…)

Posted in Updates | Comments Off on The P2B Regulation – regulating the e-commerce gatekeepers

Checklist: Service levels

Issues to consider when drafting, reviewing or negotiating service levels include:

Service levels

Service credits

Tags: , , , , ,
Posted in Commercial, Technology | Comments Off on Checklist: Service levels

Checklist: SaaS

Issues to consider when negotiating a SaaS (Software as a Service) agreement include:

Tags: , ,
Posted in Uncategorised | Comments Off on Checklist: SaaS

Government’s response to the Law Commission’s report on Electronic execution of documents

12/03/20 – The UK government has issued a Statement in response to the Law Commission’s report on Electronic execution of documents.  My article on the Law Commission’s report can be accessed here.

Key takeaways from the government’s Statement:

  1. The government agrees with the report’s conclusion that businesses and individuals can feel confident in using e-signatures in without the need for primary legislation.
  2. The government accepts the report’s recommendation that an Industry Working Group should be established to consider, in particular, the security and technology of electronic signatures.
  3. The Industry Working Group will also be asked to consider the question of video witnessing of electronic signatures.
  4. In accordance with the report’s recommendation, the government will ask the Law Commission to undertake a broader review of the law of deeds. The timing for the review will however be subject to government and Law Commission priorities given the existing volume of law reform work.

Tags: , , , ,
Posted in Commercial, Updates | Comments Off on Government’s response to the Law Commission’s report on Electronic execution of documents

Next Page »« Previous Page

Get in touch

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Your email address will only be used to respond to your message