SlideShare une entreprise Scribd logo
1  sur  23
Télécharger pour lire hors ligne
Binding
Corporate
Rules
	
  

	
  

-­‐Overføring	
  av	
  personopplysninger	
  2l	
  tredjestater	
  

5.	
  mars	
  2013	
  v/Inger	
  Anne	
  Folkestad	
  Tornes	
  og	
  Kjell	
  Steffner	
  
Overføring av

personopplysninger
til utlandet

Typisk	
  
– Skytjenester	
  /	
  cloud	
  compuCng	
  
– Interne	
  datasystemer	
  i	
  
internasjonale	
  konsern,	
  f.eks.	
  HR	
  
Utfordring i internasjonale konsern
Lovlig håndtering av

personopplysninger	
  
på tvers av jurisdiksjoner
BCR

•  Konsernregler	
  for	
  internasjonale	
  
organisasjoner	
  
•  Muliggjør	
  lovlig	
  transport	
  av	
  data	
  ut	
  fra	
  EU/
EØS-­‐området	
  	
  -­‐	
  innenfor	
  egen	
  organisasjon	
  
•  Gjelder	
  nå	
  både	
  for	
  databehandlere	
  og	
  
behandlingsansvarlige	
  
The eighth data protection principle and
international data transfers
”Personal data shall not be
transferred to a country or territory
outside the EEA unless that country
or territory ensures an adequate
level of protection for the rights and
freedoms of data subjects in relation
to the processing of personal data.”
Frykten for Hva som skjer når

Data krysser grensen
•  Tredjestater	
  er	
  stater	
  uten	
  for	
  EU/EØS,	
  
evt.	
  ikke	
  særskilt	
  godkjent	
  
•  ”Safe	
  Harbor”	
  gjelder	
  amerikanske	
  
selskap	
  
•  Mister	
  personopplysninger	
  sin	
  
beskySelse	
  i	
  det	
  de	
  forlater	
  EU/EØS?	
  
Art. 25 Personverndirektivet
European	
  Data	
  Protec6on	
  Direc6ve	
  (Direc6ve	
  95/46/EC,	
  the	
  “Direc6ve”)	
  	
  
	
  

Eksport er mulig når…
tredjestat	
  sørger	
  for	
  et	
  Clstrekkelig	
  vernenivå	
  
–  opplysningenes	
  art,	
  planlagte	
  behandlings	
  formål	
  
og	
  varighet,	
  opprinnelsesstat,	
  endelig	
  
bestemmelsesstat	
  etc.	
  etc.	
  etc.	
  

Andorra,	
  ArgenCna,	
  Canada,	
  Færøyene,	
  Guernsey,	
  Isle	
  of	
  
Man,	
  Israel,	
  Jersey,	
  New	
  Zealand,	
  Sveits,	
  Uruguay	
  
Art. 26 Personverndirektivet - unntak

…eller f.eks. ved bruk av

•  Binding	
  Corporate	
  Rules	
  
•  EU	
  Model	
  Contractual	
  Clauses	
  
•  Samtykke	
  fra	
  den	
  registrerte…	
  
Standard application for approval

Binding corporate rules
for the transfer of personal data

WP133
PART 1 APPLICANT INFORMATION
•  If	
  the	
  Group	
  has	
  its	
  headquarters	
  in	
  the	
  EEA	
  the	
  
form	
  should	
  be	
  filled	
  out	
  and	
  submiSed	
  by	
  that	
  
EEA	
  enCty.	
  	
  
•  If	
  the	
  Group	
  has	
  its	
  headquarters	
  outside	
  the	
  
EEA,	
  then	
  the	
  Group	
  should	
  appoint	
  a	
  Group	
  
enCty	
  located	
  inside	
  the	
  EEA	
  –	
  preferably	
  
established	
  in	
  the	
  country	
  of	
  the	
  presumpCve	
  
lead	
  DPA	
  -­‐	
  as	
  the	
  Group	
  member	
  with	
  “delegated	
  
data	
  protecCon	
  responsibiliCes”.	
  This	
  is	
  the	
  enCty	
  
which	
  should	
  then	
  submit	
  the	
  applicaCon	
  on	
  
behalf	
  of	
  the	
  Group.	
  
Section 2: Short description of data flows
•  Brief	
  descripCon	
  of	
  the	
  scope	
  and	
  nature	
  of	
  the	
  data	
  flows	
  
from	
  the	
  EEA	
  for	
  which	
  approval	
  is	
  sought.	
  
•  Nature	
  of	
  the	
  data	
  covered	
  by	
  BCRs,	
  and	
  in	
  parCcular,	
  if	
  
they	
  apply	
  to	
  one	
  category	
  of	
  data	
  or	
  to	
  more	
  than	
  one	
  
category	
  (for	
  instance	
  human	
  resources,	
  customers,...).	
  	
  
•  Do	
  the	
  BCRs	
  only	
  apply	
  to	
  transfers	
  from	
  the	
  EEA,	
  or	
  do	
  
they	
  apply	
  to	
  all	
  transfers	
  between	
  members	
  of	
  the	
  group?	
  	
  
•  From	
  which	
  country	
  most	
  of	
  the	
  data	
  are	
  transferred	
  
outside	
  the	
  EEA:	
  	
  
–  Extent	
  of	
  the	
  transfers	
  within	
  the	
  Group	
  that	
  are	
  covered	
  by	
  the	
  
BCRs;	
  including	
  a	
  descripCon	
  of	
  any	
  Group	
  members	
  in	
  the	
  EEA	
  
or	
  outside	
  EEA	
  to	
  which	
  personal	
  data	
  may	
  be	
  transferred.	
  
Section 3: Determination of the Lead Data
Protection Authority
•  LocaCon	
  of	
  the	
  Group’s	
  EEA	
  Headquarters.	
  	
  
•  If	
  the	
  Group	
  is	
  not	
  headquartered	
  in	
  the	
  EEA,	
  the	
  locaCon	
  
in	
  the	
  EEA	
  of	
  the	
  Group	
  enCty	
  with	
  delegated	
  data	
  
protecCon	
  responsibiliCes.	
  	
  
•  The	
  locaCon	
  of	
  the	
  company	
  which	
  is	
  best	
  placed	
  (in	
  terms	
  
of	
  management	
  funcCon,	
  administraCve	
  burden,	
  etc.)	
  to	
  
deal	
  with	
  the	
  applicaCon	
  and	
  to	
  enforce	
  the	
  binding	
  
corporate	
  rules	
  in	
  the	
  Group.	
  	
  
•  Country	
  where	
  most	
  of	
  the	
  decisions	
  in	
  terms	
  of	
  the	
  
purposes	
  and	
  the	
  means	
  of	
  the	
  data	
  processing	
  are	
  taken.	
  	
  
•  EEA	
  Member	
  States	
  from	
  which	
  most	
  of	
  the	
  transfers	
  
outside	
  the	
  EEA	
  will	
  take	
  place.	
  
BINDING NATURE OF THE BCRs
•  Measures	
  or	
  rules	
  that	
  are	
  legally	
  binding	
  on	
  all	
  members	
  of	
  
the	
  Group	
  Contracts	
  between	
  the	
  members	
  of	
  the	
  Group	
  
•  Unilateral	
  declaraCons	
  or	
  undertakings	
  made	
  or	
  given	
  by	
  the	
  
parent	
  company	
  which	
  are	
  binding	
  on	
  the	
  other	
  members	
  of	
  
the	
  Group	
  
•  IncorporaCon	
  of	
  other	
  regulatory	
  measures	
  (e.g.	
  obligaCons	
  
contained	
  in	
  statutory	
  codes	
  within	
  a	
  defined	
  legal	
  
framework)	
  	
  
•  IncorporaCon	
  of	
  the	
  BCRs	
  within	
  the	
  general	
  business	
  
principles	
  of	
  a	
  Group	
  backed	
  by	
  appropriate	
  policies,	
  audits	
  
and	
  sancCons	
  
•  members	
  of	
  the	
  corporate	
  group,	
  as	
  well	
  as	
  each	
  employee	
  
within	
  it,	
  will	
  feel	
  compelled	
  to	
  comply	
  with	
  the	
  internal	
  rules	
  
Binding upon the employees
•  Work	
  employment	
  contract	
  	
  
•  CollecCve	
  agreements	
  (approved	
  by	
  workers	
  commiSee/
another	
  body)	
  	
  
•  Employees	
  must	
  sign	
  or	
  aSest	
  to	
  have	
  read	
  the	
  BCRs	
  or	
  
related	
  ethics	
  guidelines	
  in	
  which	
  the	
  BCRs	
  are	
  
incorporated	
  	
  
•  BCRs	
  have	
  been	
  incorporated	
  in	
  relevant	
  company	
  policies	
  	
  
•  Disciplinary	
  sancCons	
  for	
  failing	
  to	
  comply	
  with	
  relevant	
  
company	
  policies,	
  including	
  dismissal	
  for	
  violaCon	
  	
  
•  Summary	
  supported	
  by	
  extracts	
  from	
  policies	
  and	
  
procedures	
  or	
  confidenCality	
  agreements	
  as	
  appropriate	
  to	
  
explain	
  how	
  the	
  BCRs	
  are	
  binding	
  upon	
  employees.	
  	
  
Fordelene ved å implementere

Binding corporate rules
i organisasjonen
Hva er essensen?
•  Transportere	
  data	
  friS	
  innen	
  egen	
  
organisasjon	
  
•  Organisasjonen	
  blir	
  en	
  trygg	
  havn	
  med	
  
Clstrekkelig	
  vernenivå	
  
•  Markedsmessig	
  fortrinn	
  å	
  ha	
  sterk	
  
databeskySelse	
  og	
  personvern-­‐compliance	
  
Litt om

Personvernprinsippene	
  
personvernprinsippene
1. 
2. 
3. 
4. 
5. 
6. 
7. 
8. 

Samtykke	
  eller	
  annet	
  reSslig	
  grunnlag	
  
Proporsjonalitet	
  
Formålsbestemthet	
  
Relevans	
  og	
  minimalitet	
  
Fullstendighet	
  og	
  kvalitet	
  
Informasjon	
  og	
  innsyn	
  
Informasjonssikkerhet	
  
Særlig	
  strenge	
  regler	
  ved	
  behandling	
  av	
  
sensiCve	
  personopplysninger	
  
9.  Anonymitet	
  og	
  sporfri	
  ferdsel	
  
Grunnleggende personvernprinsipper
NOU 2009:1

ReSmessig	
  og	
  rererdig	
  behandling	
  
•  All	
  behandling	
  av	
  personopplysninger	
  krever	
  reSslig	
  grunnlag,	
  og	
  den	
  behandlingsansvarlige	
  skal	
  ta	
  
Clbørlig	
  hensyn	
  Cl	
  den	
  registrertes	
  beresgede	
  personverninteresser.	
  SensiCve	
  personopplysninger	
  er	
  
underlagt	
  strengere	
  vern	
  enn	
  alminnelige	
  personopplysninger.	
  
Brukermedvirkning	
  og	
  kontroll	
  
•  Den	
  behandlingsansvarlige	
  skal	
  gjøre	
  behandlingen	
  transparent	
  og	
  forståelig	
  for	
  den	
  registrerte,	
  slik	
  at	
  
denne	
  gjøres	
  i	
  stand	
  Cl	
  å	
  overskue	
  behandlingens	
  konsekvenser	
  og	
  er	
  i	
  stand	
  Cl	
  å	
  ivareta	
  sine	
  
personverninteresser.	
  
Formålsbestemthet	
  
•  Den	
  behandlingsansvarlige	
  skal	
  før	
  innsamling	
  og	
  behandling	
  av	
  personopplysninger	
  angi	
  et	
  klart	
  og	
  
uSrykkelig	
  formål	
  med	
  behandlingen.	
  Opplysningene	
  skal	
  ikke	
  senere	
  benySes	
  for	
  uforenlige	
  formål.	
  
Minimalitet	
  
•  Personopplysninger	
  bare	
  skal	
  innhentes,	
  lagres	
  og	
  behandles	
  i	
  den	
  grad	
  de	
  er	
  nødvendige	
  for	
  å	
  oppnå	
  
formålet	
  med	
  behandlingen	
  av	
  opplysningene.	
  
Datakvalitet	
  
•  Personopplysninger	
  skal	
  ha	
  Clstrekkelig	
  kvalitet	
  i	
  forhold	
  Cl	
  det	
  formålet	
  de	
  skal	
  anvendes	
  Cl.	
  DeSe	
  
innebærer	
  blant	
  annet	
  at	
  opplysningene	
  skal	
  være	
  Clstrekkelig	
  oppdaterte,	
  presise	
  og	
  relevante	
  seS	
  opp	
  
mot	
  formålet	
  med	
  behandlingen.	
  
Informasjonssikkerhet	
  
•  Den	
  behandlingsansvarlige	
  (og	
  databehandleren)	
  skal	
  sørge	
  for	
  ClfredssCllende	
  informasjonssikkerhet	
  
med	
  hensyn	
  Cl	
  konfidensialitet,	
  integritet	
  og	
  Clgjengelighet	
  ved	
  behandling	
  av	
  personopplysninger.	
  
EU directive / OECD principles
1.  No2ce—data	
  subjects	
  should	
  be	
  given	
  noCce	
  when	
  their	
  data	
  is	
  being	
  
collected;	
  
2.  Purpose—data	
  should	
  only	
  be	
  used	
  for	
  the	
  purpose	
  stated	
  and	
  not	
  for	
  
any	
  other	
  purposes;	
  
3.  Consent—data	
  should	
  not	
  be	
  disclosed	
  without	
  the	
  data	
  subject’s	
  
consent;	
  
4.  Security—collected	
  data	
  should	
  be	
  kept	
  secure	
  from	
  any	
  potenCal	
  
abuses;	
  
5.  Disclosure—data	
  subjects	
  should	
  be	
  informed	
  as	
  to	
  who	
  is	
  collecCng	
  
their	
  data;	
  
6.  Access—data	
  subjects	
  should	
  be	
  allowed	
  to	
  access	
  their	
  data	
  and	
  make	
  
correcCons	
  to	
  any	
  inaccurate	
  data;	
  and	
  
7.  Accountability—data	
  subjects	
  should	
  have	
  a	
  method	
  available	
  to	
  them	
  
to	
  hold	
  data	
  collectors	
  accountable	
  for	
  following	
  the	
  above	
  principles.	
  
International Safe Harbor Privacy Principles
1.  No2ce	
  -­‐	
  Individuals	
  must	
  be	
  informed	
  that	
  their	
  data	
  is	
  being	
  
collected	
  and	
  about	
  how	
  it	
  will	
  be	
  used.	
  
2.  Choice	
  -­‐	
  Individuals	
  must	
  have	
  the	
  ability	
  to	
  opt	
  out	
  of	
  the	
  
collecCon	
  and	
  forward	
  transfer	
  of	
  the	
  data	
  to	
  third	
  parCes.	
  
3.  Onward	
  Transfer	
  -­‐	
  Transfers	
  of	
  data	
  to	
  third	
  parCes	
  may	
  only	
  
occur	
  to	
  other	
  organizaCons	
  that	
  follow	
  adequate	
  data	
  protecCon	
  
principles.	
  
4.  Security	
  -­‐	
  Reasonable	
  efforts	
  must	
  be	
  made	
  to	
  prevent	
  loss	
  of	
  
collected	
  informaCon.	
  
5.  Data	
  Integrity	
  -­‐	
  Data	
  must	
  be	
  relevant	
  and	
  reliable	
  for	
  the	
  purpose	
  
it	
  was	
  collected	
  for.	
  
6.  Access	
  -­‐	
  Individuals	
  must	
  be	
  able	
  to	
  access	
  informaCon	
  held	
  about	
  
them,	
  and	
  correct	
  or	
  delete	
  it	
  if	
  it	
  is	
  inaccurate.	
  
7.  Enforcement	
  -­‐	
  There	
  must	
  be	
  effecCve	
  means	
  of	
  enforcing	
  these	
  
rules.x	
  
Inger Anne Folkestad Tornes

•  Advokatfullmektig
•  Rådgivning for IKT-sektoren
•  Jobber med kontraktsrett,
personvern og e-handel,
samt offentlige anskaffelser
•  Tlf. 970 99 524
ift@lynxlaw.no

Kjell Steffner

•  Advokat, partner
•  Særskilt bransjekompetanse
innen IKT
•  God forståelse for teknologi,
prosjektmetodikk og strategi
•  Jobber med kontraktsrett,
forhandlinger, offentlige
anskaffelser og personvern
•  Tlf. 905 11 901
ks@lynxlaw.no
LYNX	
  advokaQirma	
  DA	
  
Hieronymus	
  Heyerdahls	
  gate	
  1	
  
N-­‐0160	
  Oslo	
  
	
  
hSp://lynxlaw.no/	
  
	
  

Contenu connexe

Tendances

Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protectionMRS
 
Operations network meeting 22 January 2019
Operations network meeting 22 January 2019Operations network meeting 22 January 2019
Operations network meeting 22 January 2019MRS
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018MRS
 
MRS Code of Conduct 2019 - Changes to Fair Data
MRS Code of Conduct 2019 - Changes to Fair DataMRS Code of Conduct 2019 - Changes to Fair Data
MRS Code of Conduct 2019 - Changes to Fair DataMRS
 
MRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowHackerOne
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliantSiddharth Ram Dinesh
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
EU Data Protection Regulation: Role of the Data Protection Officer
EU Data Protection Regulation: Role of the Data Protection OfficerEU Data Protection Regulation: Role of the Data Protection Officer
EU Data Protection Regulation: Role of the Data Protection OfficerMRS
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...m-hance
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPRJessvin Thomas
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsElliot Reeman
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
GAMABrief: When Education Meets Big Data
GAMABrief: When Education Meets Big DataGAMABrief: When Education Meets Big Data
GAMABrief: When Education Meets Big DataChristina Gagnier
 

Tendances (20)

Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
Operations network meeting 22 January 2019
Operations network meeting 22 January 2019Operations network meeting 22 January 2019
Operations network meeting 22 January 2019
 
Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018Operations network - consent under gdpr 24.01.2018
Operations network - consent under gdpr 24.01.2018
 
MRS Code of Conduct 2019 - Changes to Fair Data
MRS Code of Conduct 2019 - Changes to Fair DataMRS Code of Conduct 2019 - Changes to Fair Data
MRS Code of Conduct 2019 - Changes to Fair Data
 
MRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational MeasuresMRS Operations Network: GDPR - Organisational Measures
MRS Operations Network: GDPR - Organisational Measures
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
EU Data Protection Regulation: Role of the Data Protection Officer
EU Data Protection Regulation: Role of the Data Protection OfficerEU Data Protection Regulation: Role of the Data Protection Officer
EU Data Protection Regulation: Role of the Data Protection Officer
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...GDPR – what does it mean for charities and what you need to consider - Iain P...
GDPR – what does it mean for charities and what you need to consider - Iain P...
 
Getting Ready for GDPR
Getting Ready for GDPRGetting Ready for GDPR
Getting Ready for GDPR
 
Privacy Access Letter I Feb 5 07
Privacy Access Letter I   Feb 5 07Privacy Access Letter I   Feb 5 07
Privacy Access Letter I Feb 5 07
 
The Countdown to the GDPR Regulations
The Countdown to the GDPR RegulationsThe Countdown to the GDPR Regulations
The Countdown to the GDPR Regulations
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
GAMABrief: When Education Meets Big Data
GAMABrief: When Education Meets Big DataGAMABrief: When Education Meets Big Data
GAMABrief: When Education Meets Big Data
 

En vedette

Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...
Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...
Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...Brian Heidelberger
 
How brands can use hashtags without getting sued
How brands can use hashtags without getting suedHow brands can use hashtags without getting sued
How brands can use hashtags without getting suedBrian Heidelberger
 
New FTC Action re Testimonials and Endorsements
New FTC Action re Testimonials and EndorsementsNew FTC Action re Testimonials and Endorsements
New FTC Action re Testimonials and EndorsementsBrian Heidelberger
 
FTC Answers Your Questions on Endorsements and Testimonials
FTC Answers Your Questions on Endorsements and TestimonialsFTC Answers Your Questions on Endorsements and Testimonials
FTC Answers Your Questions on Endorsements and TestimonialsBrian Heidelberger
 
How to Create Binding Terms/Rules
How to Create Binding Terms/RulesHow to Create Binding Terms/Rules
How to Create Binding Terms/RulesBrian Heidelberger
 
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...Brian Heidelberger
 
Nmdl fianl project
Nmdl fianl projectNmdl fianl project
Nmdl fianl projectElundmark29
 
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...Brian Heidelberger
 

En vedette (9)

Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...
Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...
Everything (Current) You Wanted To Know About Advertising, Promotions and Pri...
 
How brands can use hashtags without getting sued
How brands can use hashtags without getting suedHow brands can use hashtags without getting sued
How brands can use hashtags without getting sued
 
New FTC Action re Testimonials and Endorsements
New FTC Action re Testimonials and EndorsementsNew FTC Action re Testimonials and Endorsements
New FTC Action re Testimonials and Endorsements
 
FTC Answers Your Questions on Endorsements and Testimonials
FTC Answers Your Questions on Endorsements and TestimonialsFTC Answers Your Questions on Endorsements and Testimonials
FTC Answers Your Questions on Endorsements and Testimonials
 
How to Create Binding Terms/Rules
How to Create Binding Terms/RulesHow to Create Binding Terms/Rules
How to Create Binding Terms/Rules
 
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...
How Brand Marketers Can (& Can't) Stay Legal Using Twitter's Live Streaming A...
 
Recent Court Decision re TCPA
Recent Court Decision re TCPARecent Court Decision re TCPA
Recent Court Decision re TCPA
 
Nmdl fianl project
Nmdl fianl projectNmdl fianl project
Nmdl fianl project
 
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...
Can Brands Use a Celebrities in Social Media Without Permission - Ad Age Mini...
 

Similaire à Binding Corporate Rules for International Data Transfers

ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]Kwanzoo Inc
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterBrowne Jacobson LLP
 
GDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowGDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowRachel Roach
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudGurbir Singh
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRBartLieben
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance Dovetail Software
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentationPriyanka Aash
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firmsaccenture
 
The GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farThe GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farPECB
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityEQS Group
 

Similaire à Binding Corporate Rules for International Data Transfers (20)

Binding corporate rules
Binding corporate rulesBinding corporate rules
Binding corporate rules
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]ABM Display Advertising Success in the World of GDPR [PPT]
ABM Display Advertising Success in the World of GDPR [PPT]
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
What does GDPR mean for your business?
What does GDPR mean for your business?What does GDPR mean for your business?
What does GDPR mean for your business?
 
Public sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, ExeterPublic sector breakfast club, October 2016, Exeter
Public sector breakfast club, October 2016, Exeter
 
GDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to KnowGDPR & Your Cloud Provider - What You Need to Know
GDPR & Your Cloud Provider - What You Need to Know
 
Kawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the CloudKawser Hamid : ICO and Data Protection in the Cloud
Kawser Hamid : ICO and Data Protection in the Cloud
 
Domain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPRDomain management and brand protection in the era of the EU's GDPR
Domain management and brand protection in the era of the EU's GDPR
 
#HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance #HR and #GDPR: Preparing for 2018 Compliance
#HR and #GDPR: Preparing for 2018 Compliance
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
GDPR for your Payroll Bureau
GDPR for your Payroll BureauGDPR for your Payroll Bureau
GDPR for your Payroll Bureau
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
General Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian FirmsGeneral Data Protection Regulation (GDPR) Implications for Canadian Firms
General Data Protection Regulation (GDPR) Implications for Canadian Firms
 
GDPR: What does it mean for your business?
GDPR: What does it mean for your business?GDPR: What does it mean for your business?
GDPR: What does it mean for your business?
 
The GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farThe GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so far
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Impact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A SecurityImpact of GDPR on Third Party and M&A Security
Impact of GDPR on Third Party and M&A Security
 

Plus de Kjell Steffner

Investorer engler eller togrøvere
Investorer engler eller togrøvereInvestorer engler eller togrøvere
Investorer engler eller togrøvereKjell Steffner
 
Endringer i kontraktsperioden
Endringer i kontraktsperiodenEndringer i kontraktsperioden
Endringer i kontraktsperiodenKjell Steffner
 
GDPR datainnsamling på web
GDPR datainnsamling på webGDPR datainnsamling på web
GDPR datainnsamling på webKjell Steffner
 
GDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserGDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserKjell Steffner
 
Nye anskaffelsesregler - heldagskurs fra Nima
Nye anskaffelsesregler - heldagskurs fra NimaNye anskaffelsesregler - heldagskurs fra Nima
Nye anskaffelsesregler - heldagskurs fra NimaKjell Steffner
 
Nye regler for offentlige anskaffelser
Nye regler for offentlige anskaffelserNye regler for offentlige anskaffelser
Nye regler for offentlige anskaffelserKjell Steffner
 
Nye spilleregler offentlige anskaffelser difi
Nye spilleregler offentlige anskaffelser difiNye spilleregler offentlige anskaffelser difi
Nye spilleregler offentlige anskaffelser difiKjell Steffner
 
Risikostyring av kontrakter
Risikostyring av kontrakterRisikostyring av kontrakter
Risikostyring av kontrakterKjell Steffner
 
It-kontrakter for løsningsarkitekter
It-kontrakter for løsningsarkitekterIt-kontrakter for løsningsarkitekter
It-kontrakter for løsningsarkitekterKjell Steffner
 
Inngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterInngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterKjell Steffner
 
Legal risk management: Hvordan styre risiko i kontrakter
Legal risk management: Hvordan styre risiko i kontrakterLegal risk management: Hvordan styre risiko i kontrakter
Legal risk management: Hvordan styre risiko i kontrakterKjell Steffner
 
Risikostyring og kravspesifikasjon
Risikostyring og kravspesifikasjonRisikostyring og kravspesifikasjon
Risikostyring og kravspesifikasjonKjell Steffner
 
Risikostyring av it-kontrakter
Risikostyring av it-kontrakterRisikostyring av it-kontrakter
Risikostyring av it-kontrakterKjell Steffner
 
Inngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterInngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterKjell Steffner
 
Risikoanalyse av it-kontrakter
Risikoanalyse av it-kontrakterRisikoanalyse av it-kontrakter
Risikoanalyse av it-kontrakterKjell Steffner
 
Kontrakten som verktøy i ikt-prosjekter
Kontrakten som verktøy i ikt-prosjekterKontrakten som verktøy i ikt-prosjekter
Kontrakten som verktøy i ikt-prosjekterKjell Steffner
 

Plus de Kjell Steffner (20)

GDPR-helsesjekk
GDPR-helsesjekkGDPR-helsesjekk
GDPR-helsesjekk
 
Investorer engler eller togrøvere
Investorer engler eller togrøvereInvestorer engler eller togrøvere
Investorer engler eller togrøvere
 
Endringer i kontraktsperioden
Endringer i kontraktsperiodenEndringer i kontraktsperioden
Endringer i kontraktsperioden
 
GDPR datainnsamling på web
GDPR datainnsamling på webGDPR datainnsamling på web
GDPR datainnsamling på web
 
GDPR i offentlige anskaffelser
GDPR i offentlige anskaffelserGDPR i offentlige anskaffelser
GDPR i offentlige anskaffelser
 
Nye anskaffelsesregler - heldagskurs fra Nima
Nye anskaffelsesregler - heldagskurs fra NimaNye anskaffelsesregler - heldagskurs fra Nima
Nye anskaffelsesregler - heldagskurs fra Nima
 
Nye regler for offentlige anskaffelser
Nye regler for offentlige anskaffelserNye regler for offentlige anskaffelser
Nye regler for offentlige anskaffelser
 
Nye spilleregler offentlige anskaffelser difi
Nye spilleregler offentlige anskaffelser difiNye spilleregler offentlige anskaffelser difi
Nye spilleregler offentlige anskaffelser difi
 
Risikostyring av kontrakter
Risikostyring av kontrakterRisikostyring av kontrakter
Risikostyring av kontrakter
 
It-kontrakter for løsningsarkitekter
It-kontrakter for løsningsarkitekterIt-kontrakter for løsningsarkitekter
It-kontrakter for løsningsarkitekter
 
Contract management
Contract managementContract management
Contract management
 
Inngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterInngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakter
 
Legal risk management: Hvordan styre risiko i kontrakter
Legal risk management: Hvordan styre risiko i kontrakterLegal risk management: Hvordan styre risiko i kontrakter
Legal risk management: Hvordan styre risiko i kontrakter
 
Risikostyring og kravspesifikasjon
Risikostyring og kravspesifikasjonRisikostyring og kravspesifikasjon
Risikostyring og kravspesifikasjon
 
Kravspesifikasjon
KravspesifikasjonKravspesifikasjon
Kravspesifikasjon
 
Forhandlingsteknikk
ForhandlingsteknikkForhandlingsteknikk
Forhandlingsteknikk
 
Risikostyring av it-kontrakter
Risikostyring av it-kontrakterRisikostyring av it-kontrakter
Risikostyring av it-kontrakter
 
Inngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakterInngåelse og oppfølging av it kontrakter
Inngåelse og oppfølging av it kontrakter
 
Risikoanalyse av it-kontrakter
Risikoanalyse av it-kontrakterRisikoanalyse av it-kontrakter
Risikoanalyse av it-kontrakter
 
Kontrakten som verktøy i ikt-prosjekter
Kontrakten som verktøy i ikt-prosjekterKontrakten som verktøy i ikt-prosjekter
Kontrakten som verktøy i ikt-prosjekter
 

Dernier

8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Anamaria Contreras
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfrichard876048
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessSeta Wicaksana
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfShashank Mehta
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxsaniyaimamuddin
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Peter Ward
 

Dernier (20)

8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 
Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.Traction part 2 - EOS Model JAX Bridges.
Traction part 2 - EOS Model JAX Bridges.
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdf
 
Organizational Structure Running A Successful Business
Organizational Structure Running A Successful BusinessOrganizational Structure Running A Successful Business
Organizational Structure Running A Successful Business
 
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdf
 
Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptxFinancial-Statement-Analysis-of-Coca-cola-Company.pptx
Financial-Statement-Analysis-of-Coca-cola-Company.pptx
 
Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...Fordham -How effective decision-making is within the IT department - Analysis...
Fordham -How effective decision-making is within the IT department - Analysis...
 

Binding Corporate Rules for International Data Transfers

  • 1. Binding Corporate Rules     -­‐Overføring  av  personopplysninger  2l  tredjestater   5.  mars  2013  v/Inger  Anne  Folkestad  Tornes  og  Kjell  Steffner  
  • 2. Overføring av personopplysninger til utlandet Typisk   – Skytjenester  /  cloud  compuCng   – Interne  datasystemer  i   internasjonale  konsern,  f.eks.  HR  
  • 3. Utfordring i internasjonale konsern Lovlig håndtering av personopplysninger   på tvers av jurisdiksjoner
  • 4. BCR •  Konsernregler  for  internasjonale   organisasjoner   •  Muliggjør  lovlig  transport  av  data  ut  fra  EU/ EØS-­‐området    -­‐  innenfor  egen  organisasjon   •  Gjelder  nå  både  for  databehandlere  og   behandlingsansvarlige  
  • 5. The eighth data protection principle and international data transfers ”Personal data shall not be transferred to a country or territory outside the EEA unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.”
  • 6. Frykten for Hva som skjer når Data krysser grensen •  Tredjestater  er  stater  uten  for  EU/EØS,   evt.  ikke  særskilt  godkjent   •  ”Safe  Harbor”  gjelder  amerikanske   selskap   •  Mister  personopplysninger  sin   beskySelse  i  det  de  forlater  EU/EØS?  
  • 7. Art. 25 Personverndirektivet European  Data  Protec6on  Direc6ve  (Direc6ve  95/46/EC,  the  “Direc6ve”)       Eksport er mulig når… tredjestat  sørger  for  et  Clstrekkelig  vernenivå   –  opplysningenes  art,  planlagte  behandlings  formål   og  varighet,  opprinnelsesstat,  endelig   bestemmelsesstat  etc.  etc.  etc.   Andorra,  ArgenCna,  Canada,  Færøyene,  Guernsey,  Isle  of   Man,  Israel,  Jersey,  New  Zealand,  Sveits,  Uruguay  
  • 8. Art. 26 Personverndirektivet - unntak …eller f.eks. ved bruk av •  Binding  Corporate  Rules   •  EU  Model  Contractual  Clauses   •  Samtykke  fra  den  registrerte…  
  • 9. Standard application for approval Binding corporate rules for the transfer of personal data WP133
  • 10. PART 1 APPLICANT INFORMATION •  If  the  Group  has  its  headquarters  in  the  EEA  the   form  should  be  filled  out  and  submiSed  by  that   EEA  enCty.     •  If  the  Group  has  its  headquarters  outside  the   EEA,  then  the  Group  should  appoint  a  Group   enCty  located  inside  the  EEA  –  preferably   established  in  the  country  of  the  presumpCve   lead  DPA  -­‐  as  the  Group  member  with  “delegated   data  protecCon  responsibiliCes”.  This  is  the  enCty   which  should  then  submit  the  applicaCon  on   behalf  of  the  Group.  
  • 11. Section 2: Short description of data flows •  Brief  descripCon  of  the  scope  and  nature  of  the  data  flows   from  the  EEA  for  which  approval  is  sought.   •  Nature  of  the  data  covered  by  BCRs,  and  in  parCcular,  if   they  apply  to  one  category  of  data  or  to  more  than  one   category  (for  instance  human  resources,  customers,...).     •  Do  the  BCRs  only  apply  to  transfers  from  the  EEA,  or  do   they  apply  to  all  transfers  between  members  of  the  group?     •  From  which  country  most  of  the  data  are  transferred   outside  the  EEA:     –  Extent  of  the  transfers  within  the  Group  that  are  covered  by  the   BCRs;  including  a  descripCon  of  any  Group  members  in  the  EEA   or  outside  EEA  to  which  personal  data  may  be  transferred.  
  • 12. Section 3: Determination of the Lead Data Protection Authority •  LocaCon  of  the  Group’s  EEA  Headquarters.     •  If  the  Group  is  not  headquartered  in  the  EEA,  the  locaCon   in  the  EEA  of  the  Group  enCty  with  delegated  data   protecCon  responsibiliCes.     •  The  locaCon  of  the  company  which  is  best  placed  (in  terms   of  management  funcCon,  administraCve  burden,  etc.)  to   deal  with  the  applicaCon  and  to  enforce  the  binding   corporate  rules  in  the  Group.     •  Country  where  most  of  the  decisions  in  terms  of  the   purposes  and  the  means  of  the  data  processing  are  taken.     •  EEA  Member  States  from  which  most  of  the  transfers   outside  the  EEA  will  take  place.  
  • 13. BINDING NATURE OF THE BCRs •  Measures  or  rules  that  are  legally  binding  on  all  members  of   the  Group  Contracts  between  the  members  of  the  Group   •  Unilateral  declaraCons  or  undertakings  made  or  given  by  the   parent  company  which  are  binding  on  the  other  members  of   the  Group   •  IncorporaCon  of  other  regulatory  measures  (e.g.  obligaCons   contained  in  statutory  codes  within  a  defined  legal   framework)     •  IncorporaCon  of  the  BCRs  within  the  general  business   principles  of  a  Group  backed  by  appropriate  policies,  audits   and  sancCons   •  members  of  the  corporate  group,  as  well  as  each  employee   within  it,  will  feel  compelled  to  comply  with  the  internal  rules  
  • 14. Binding upon the employees •  Work  employment  contract     •  CollecCve  agreements  (approved  by  workers  commiSee/ another  body)     •  Employees  must  sign  or  aSest  to  have  read  the  BCRs  or   related  ethics  guidelines  in  which  the  BCRs  are   incorporated     •  BCRs  have  been  incorporated  in  relevant  company  policies     •  Disciplinary  sancCons  for  failing  to  comply  with  relevant   company  policies,  including  dismissal  for  violaCon     •  Summary  supported  by  extracts  from  policies  and   procedures  or  confidenCality  agreements  as  appropriate  to   explain  how  the  BCRs  are  binding  upon  employees.    
  • 15. Fordelene ved å implementere Binding corporate rules i organisasjonen
  • 16. Hva er essensen? •  Transportere  data  friS  innen  egen   organisasjon   •  Organisasjonen  blir  en  trygg  havn  med   Clstrekkelig  vernenivå   •  Markedsmessig  fortrinn  å  ha  sterk   databeskySelse  og  personvern-­‐compliance  
  • 18. personvernprinsippene 1.  2.  3.  4.  5.  6.  7.  8.  Samtykke  eller  annet  reSslig  grunnlag   Proporsjonalitet   Formålsbestemthet   Relevans  og  minimalitet   Fullstendighet  og  kvalitet   Informasjon  og  innsyn   Informasjonssikkerhet   Særlig  strenge  regler  ved  behandling  av   sensiCve  personopplysninger   9.  Anonymitet  og  sporfri  ferdsel  
  • 19. Grunnleggende personvernprinsipper NOU 2009:1 ReSmessig  og  rererdig  behandling   •  All  behandling  av  personopplysninger  krever  reSslig  grunnlag,  og  den  behandlingsansvarlige  skal  ta   Clbørlig  hensyn  Cl  den  registrertes  beresgede  personverninteresser.  SensiCve  personopplysninger  er   underlagt  strengere  vern  enn  alminnelige  personopplysninger.   Brukermedvirkning  og  kontroll   •  Den  behandlingsansvarlige  skal  gjøre  behandlingen  transparent  og  forståelig  for  den  registrerte,  slik  at   denne  gjøres  i  stand  Cl  å  overskue  behandlingens  konsekvenser  og  er  i  stand  Cl  å  ivareta  sine   personverninteresser.   Formålsbestemthet   •  Den  behandlingsansvarlige  skal  før  innsamling  og  behandling  av  personopplysninger  angi  et  klart  og   uSrykkelig  formål  med  behandlingen.  Opplysningene  skal  ikke  senere  benySes  for  uforenlige  formål.   Minimalitet   •  Personopplysninger  bare  skal  innhentes,  lagres  og  behandles  i  den  grad  de  er  nødvendige  for  å  oppnå   formålet  med  behandlingen  av  opplysningene.   Datakvalitet   •  Personopplysninger  skal  ha  Clstrekkelig  kvalitet  i  forhold  Cl  det  formålet  de  skal  anvendes  Cl.  DeSe   innebærer  blant  annet  at  opplysningene  skal  være  Clstrekkelig  oppdaterte,  presise  og  relevante  seS  opp   mot  formålet  med  behandlingen.   Informasjonssikkerhet   •  Den  behandlingsansvarlige  (og  databehandleren)  skal  sørge  for  ClfredssCllende  informasjonssikkerhet   med  hensyn  Cl  konfidensialitet,  integritet  og  Clgjengelighet  ved  behandling  av  personopplysninger.  
  • 20. EU directive / OECD principles 1.  No2ce—data  subjects  should  be  given  noCce  when  their  data  is  being   collected;   2.  Purpose—data  should  only  be  used  for  the  purpose  stated  and  not  for   any  other  purposes;   3.  Consent—data  should  not  be  disclosed  without  the  data  subject’s   consent;   4.  Security—collected  data  should  be  kept  secure  from  any  potenCal   abuses;   5.  Disclosure—data  subjects  should  be  informed  as  to  who  is  collecCng   their  data;   6.  Access—data  subjects  should  be  allowed  to  access  their  data  and  make   correcCons  to  any  inaccurate  data;  and   7.  Accountability—data  subjects  should  have  a  method  available  to  them   to  hold  data  collectors  accountable  for  following  the  above  principles.  
  • 21. International Safe Harbor Privacy Principles 1.  No2ce  -­‐  Individuals  must  be  informed  that  their  data  is  being   collected  and  about  how  it  will  be  used.   2.  Choice  -­‐  Individuals  must  have  the  ability  to  opt  out  of  the   collecCon  and  forward  transfer  of  the  data  to  third  parCes.   3.  Onward  Transfer  -­‐  Transfers  of  data  to  third  parCes  may  only   occur  to  other  organizaCons  that  follow  adequate  data  protecCon   principles.   4.  Security  -­‐  Reasonable  efforts  must  be  made  to  prevent  loss  of   collected  informaCon.   5.  Data  Integrity  -­‐  Data  must  be  relevant  and  reliable  for  the  purpose   it  was  collected  for.   6.  Access  -­‐  Individuals  must  be  able  to  access  informaCon  held  about   them,  and  correct  or  delete  it  if  it  is  inaccurate.   7.  Enforcement  -­‐  There  must  be  effecCve  means  of  enforcing  these   rules.x  
  • 22. Inger Anne Folkestad Tornes •  Advokatfullmektig •  Rådgivning for IKT-sektoren •  Jobber med kontraktsrett, personvern og e-handel, samt offentlige anskaffelser •  Tlf. 970 99 524 ift@lynxlaw.no Kjell Steffner •  Advokat, partner •  Særskilt bransjekompetanse innen IKT •  God forståelse for teknologi, prosjektmetodikk og strategi •  Jobber med kontraktsrett, forhandlinger, offentlige anskaffelser og personvern •  Tlf. 905 11 901 ks@lynxlaw.no
  • 23. LYNX  advokaQirma  DA   Hieronymus  Heyerdahls  gate  1   N-­‐0160  Oslo     hSp://lynxlaw.no/