{"id":2525,"date":"2020-05-23T14:43:42","date_gmt":"2020-05-23T14:43:42","guid":{"rendered":"http:\/\/www.bizlegal.eu\/?page_id=2525"},"modified":"2020-05-23T14:43:43","modified_gmt":"2020-05-23T14:43:43","slug":"newsletter-august-2019","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2525","title":{"rendered":"Newsletter  August 2019"},"content":{"rendered":"\n<p><img loading=\"lazy\" width=\"285\" height=\"99\" src=\"\"><\/p>\n\n\n\n<p><strong>Business Legal is a regulatory compliance firm assisting businesses with general regulatory compliance. All businesses are&nbsp;<\/strong><br><strong>subject to compliance with Employment Law, Data Protection Law and Health and Safety. In addition, businesses may also&nbsp; be subject to sector specific compliance regulations, such as insurance industry regulations, food standards regulations et&nbsp;<\/strong><br><strong>cetera.&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>Business Legal provides expert support and assistance the 3 main compliance areas of Employment Law, Data Protection&nbsp;<\/strong><br><strong>Law and Health and Safety Law, and can provide specialist consultants in more specific areas.&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>SMEs often don\u2019t have an in-house legal function, and to assist in ensuring cost \u2013 effective, competent advisers are retained&nbsp; we also provide a General Counsel service to SMEs whereby we source legal services for our clients from niche specialists in&nbsp; each area.&nbsp;<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><\/td><\/tr><tr><td><\/td><td><img loading=\"lazy\" src=\"\" width=\"211\" height=\"148\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>The Public Services Card (PSC)&nbsp;<\/strong><\/p>\n\n\n\n<p>The Data Protection Commission (DPC) has determined that the PSC may not be used&nbsp; on a mandatory or compulsory basis by government departments other than the De- partment of Social Protection, which is the Department which issued the card. This&nbsp;<\/p>\n\n\n\n<p>means that it is not lawful for a PSC to be demanded in a driving licence or passport&nbsp;<br>application, or any other application to any department other than the Department of&nbsp; Social Protection.&nbsp;<\/p>\n\n\n\n<p>More problematically, the DPC has ordered the destruction of 3.2 million data subjects\u2019 records on the basis that there are no&nbsp; longer required once the primary purpose for gathering that data was achieved, namely the identification of the individual.&nbsp;<\/p>\n\n\n\n<p>The government appears to be inclined to try and retrospectively legislate to legitimise its unlawful actions, rather than to&nbsp;<br>take on board the criticism of data protection practitioners, and the DPC with regard to its actions over the last number of&nbsp;<br>years. There are very strong legal objections to this approach, as Article 5.1.b of the GDPR requires that personal data be&nbsp;<\/p>\n\n\n\n<p>\u201ccollected for specified, explicit and legitimate purposes\u201d, and the data has already been collected. Any attempt to retain the&nbsp; personal data held in respect of the PSC, or to respectively legitimise its collection would likely be resisted by recourse to liti- gation.&nbsp; The PSC has put a 21 day stay on its order for the destruction of the personal data, so we will be reporting on further&nbsp; developments in our September edition of this newsletter.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Privacy Notices\/Policies<\/strong>&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"84\" height=\"187\">With the prospect of increased GDPR regulatory activity ahead, it is important for organisations to ensure their&nbsp; Privacy Notices are compliant.&nbsp;<\/p>\n\n\n\n<p>You must provide clear, intelligible and easily accessible information to individuals about the collection and use&nbsp; of their personal data.&nbsp;<\/p>\n\n\n\n<p>This must be provided at the time personal data is obtained from individuals (or within one month when ob-<br>tained from another source).&nbsp;<\/p>\n\n\n\n<p>The categories of information to be provided include the purposes of processing, the legal basis for processing,&nbsp; the legitimate interest of the company which the company claims legitimises the processing (if applicable), any&nbsp; data sharing, any international transfers, and the data retention periods which apply to each processing.&nbsp;<\/p>\n\n\n\n<p>Working this out, with documentation to meet the requirements of accountability, can be challenging. You may need to re-<br>fresh data mapping or review justifications for legal basis. Privacy Notices should also align with your Records of Processing&nbsp;<br>Activities (as required by Article 30). You may need more than one Privacy Notice depending on the individuals involved&nbsp;<\/p>\n\n\n\n<p>(customers, staff, etc.).&nbsp; Privacy Notices are not a once-off exercise and must be kept under review to reflect processing activi- ties<strong>. <\/strong>They are part of your GDPR transparency obligations. It should be transparent to individuals that their personal data is&nbsp;<br>being processed and to what extent.<strong>&nbsp;<\/strong><\/p>\n\n\n\n<p>We can help you with your Privacy Notice which is the shop window for your organisation&nbsp;<br><\/p>\n\n\n\n<p><strong>How do you verify the identity of an individual requesting access to their data or that data be deleted?&nbsp;&nbsp; The Dutch Data Protection Authority, Autoriteitpersoonsgegevens, has provided guidance <\/strong>&nbsp;&nbsp;<\/p>\n\n\n\n<p>If at all possible, refrain from asking for a copy of a formal ID&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" width=\"168\" height=\"189\">Some alternatives may be:&nbsp;<\/p>\n\n\n\n<p>1. Via an existing login system.&nbsp;&nbsp;<\/p>\n\n\n\n<p>2. A form of two-factor authentication. For example:&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u2022 after receiving a request via e-mail request a confirmation by SMS. This mobile number&nbsp;<\/p>\n\n\n\n<p>must then match the customer data from your administration.&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u2022 &nbsp;&nbsp; &nbsp;request confirmation of the telephone request by e-mail. This e-mail address must match&nbsp;<\/p>\n\n\n\n<p>the customer data from your administration.&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u2022 ask for the last 3 digits of the account number, the date of birth and \/ or the customer&nbsp;<\/p>\n\n\n\n<p>number for verification.&nbsp;<\/p>\n\n\n\n<p>\u2022 ask someone to come by and show you his\/her ID proof without making a copy. Note,&nbsp;<\/p>\n\n\n\n<p>however, that this cannot be used to set up a threshold to allow access and should only&nbsp;<br>offered as an alternative&nbsp;<\/p>\n\n\n\n<p><strong>GDPR fine in Romania.&nbsp;<\/strong><\/p>\n\n\n\n<p>UniCredit Bank was fined \u20ac130,000 for not applying adequate technical and organizational measures to protect personal data.&nbsp; Customers&#8217; ID number and address were exposed in bank statements for payments made to other persons. If a customer was&nbsp; transferring funds or making a payment to an account the beneficiary would see this data.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>EU Standard Contractual Clauses (SCCs) and EU-US Privacy Shield&nbsp;<\/strong><\/p>\n\n\n\n<p>The major case of C-311\/18 &#8211; <em>Data Protection Commissioner (Ireland) v Facebook Ireland Limited &amp; Schrems<\/em> has now been&nbsp;<\/p>\n\n\n\n<p>heard&nbsp; by the CJEU. At issue is the validity of two key international data transfer mechanisms: the EU Standard Contractual&nbsp;<br>Clauses (<strong>SCCs<\/strong>) and EU-US Privacy Shield, both widely-used mechanisms by EEA businesses to legitimise the transfer of personal&nbsp; data to countries outside the EEA (e.g. the US).&nbsp;&nbsp; A decision is expected on December 19<sup>th<\/sup> 2019.&nbsp;<\/p>\n\n\n\n<p>While we can\u2019t pre-empt the decision of the CJEU, if the SCCs and\/or Privacy Shield were invalidated that would mean that&nbsp;<br>businesses that have heretofore been relying on these mechanisms would need to consider alternative mechanisms for trans- ferring their personal data to third countries. &nbsp;&nbsp;<\/p>\n\n\n\n<p>These include:&nbsp;<\/p>\n\n\n\n<p>\u2022 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Binding Corporate Rules (<strong>BCRs<\/strong>)&nbsp;<br>\u2022 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Derogations&nbsp;<\/p>\n\n\n\n<p>\u2022 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Consent&nbsp;<\/p>\n\n\n\n<p>Given the lack of any practical alternatives, should the SCCs and\/or Privacy shield be struck down, the European Data Protec-<br>tion Board will come under significant pressure to allow for some kind of moratorium during which no enforcement action will&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" alt=\"Reserved: Businesses would need to:  \" width=\"26423683\" height=\"4211348\">be taken by a national regulator, as happened previously when the precursor to Privacy&nbsp;<br>Shield (Safe Harbour) was deemed invalid.&nbsp;&nbsp;<\/p>\n\n\n\n<p><img loading=\"lazy\" src=\"\" alt=\"Reserved: \u2022 consider the extent to which business operations may  \ncontinue without the need to transfer personal data  \noutside the EEA;  \n\u2022 consider alternate mechanisms such as BCRs or one of  \nthe derogations, or demonstrate data subject consent to  \nthe transfers; and  \n\u2022 engage with third party service providers to determine  \nwhat contingency plans they are putting in place to ena- \nble them to continue to receive data.  \n\" width=\"57314275\" height=\"29290507\">\u2022 educate senior management on the implications of a&nbsp;<br>declaration of invalidity;&nbsp;<\/p>\n\n\n\n<p>\u2022 analyse data flows outside the EEA, what mechanism(s)&nbsp;<br>underpin these transfers and how important these&nbsp;<br>transfers are;&nbsp;<\/p>\n\n\n\n<p>\u2022 assess the potential impact of having to stop transferring&nbsp;<br>data abroad and how any fall out may be mitigated. E.g&nbsp;<br>cease certain data processing activities or cross-border&nbsp;<br>transfers, bring the personal data back into the EEA or&nbsp;<br>continue processing outside of the EEA;&nbsp;<br><\/p>\n\n\n\n<p><strong>How should companies plan for BREXIT?&nbsp;<\/strong><\/p>\n\n\n\n<p>If Brexit proceeds on the 31st October next the UK will be-<br>come a third \u2013 country, and it (and by extension its companies&nbsp; processing data in the UK) will no longer be considered a safe&nbsp; destination for EU personal data.&nbsp;<\/p>\n\n\n\n<p>Although the UK has passed a Data Protection Act 2018, with&nbsp; roughly equivalent provisions to the GDPR, in the absence of a&nbsp; Withdrawal Agreement being concluded between the EU and&nbsp; the UK the transition from being a member of the EU, to being&nbsp; an unsafe third \u2013 country destination for EU personal data will&nbsp; be immediate.&nbsp;<\/p>\n\n\n\n<p><strong>Existing contractual provisions between controllers based in&nbsp; the EU, and processors based in the UK.&nbsp;<\/strong><\/p>\n\n\n\n<p>Currently, when a controller based in the EU (including in the&nbsp; UK) proposes to retain a processor based in the UK, they are&nbsp;<br>required to put in place an agreement complying with Article&nbsp; 28.3 of the GDPR (often called a controller \u2013 processor agree- ment). This requirement will remain, but it will become more&nbsp; important, as the UK will now be considered an unsafe third \u2013&nbsp; country destination for EU personal data.&nbsp;<\/p>\n\n\n\n<p>In addition however, the EU-based controller will have 2 legiti- mise the transfer of personal data from the EU to the UK.&nbsp;<br>There are a number of ways of doing this, but the most com-<br>mon, and most practically useful method is the execution of&nbsp;<br>Standard Contractual Clauses (SCCs), often also called Model&nbsp; Clauses.&nbsp;&nbsp;<\/p>\n\n\n\n<p>In simple terms, every EU-based controller who has a UK&nbsp;<\/p>\n\n\n\n<p>based processor, will have to ensure that in addition to a con- troller \u2013 processor contract, they also have in place a Model&nbsp;<br>Clause contract between themselves and that UK based pro-<br>cessor.&nbsp;<\/p>\n\n\n\n<p>This is not as simple as it sounds, as processors often refuse to&nbsp; sign controller \u2013 processor contract, or Model Clause con-<br>tracts. In the absence of both these agreements being signed,&nbsp; the controller has no legal option but to sever the relationship&nbsp; with the processor. This can create contractual difficulties in&nbsp;<br>itself, as there can be contractual or statutory consequences&nbsp; from terminating the contract with the processor.&nbsp;<\/p>\n\n\n\n<p><strong>Article 27 Representatives&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>in circumstances where a UK based company is targeting EU residents for the offering of goods or services, or is monitoring the&nbsp; behaviour of EU-based residents, such as behavioural advertising, then it will be subject to the EU GDPR, and will have to ap-<br>point an EU-based representative in accordance with Article 27 of the GDPR. Business Legal can assist with the provision of a&nbsp;<br>specialist Article 27 Representative service, with specific Article 27 Representative liability insurance.&nbsp;<\/p>\n\n\n\n<p><strong>UK arrangements are similar&nbsp;<\/strong><\/p>\n\n\n\n<p>The UK has put in place similar provisions with regard to the transfer of UK data to third \u2013 countries, and there are require- ments for third \u2013 country based controllers and processors to have a UK Representative appointed.&nbsp;<\/p>\n\n\n\n<p><strong>Miscellaneous&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>in circumstances where a UK company is the lead controller for a group of companies, then it will be necessary for an alterna- tive group company in an EU jurisdiction to take over this role.&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Business Legal is a regulatory compliance firm assisting businesses with general regulatory compliance. All businesses are&nbsp;subject to compliance with Employment Law, Data Protection Law and Health and Safety. In addition, businesses may also&nbsp; be subject to sector specific compliance regulations, such as insurance industry regulations, food standards regulations et&nbsp;cetera.&nbsp; Business Legal provides expert support and &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2525\"> <span class=\"screen-reader-text\">Newsletter  August 2019<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 6 years ago"},"absolute_dates":{"created":"Posted on 23\/05\/2020","modified":"Updated on 23\/05\/2020"},"absolute_dates_time":{"created":"Posted on 23\/05\/2020 2:43 pm","modified":"Updated on 23\/05\/2020 2:43 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2525"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2525"}],"version-history":[{"count":1,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2525\/revisions"}],"predecessor-version":[{"id":2526,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2525\/revisions\/2526"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}