Draft of Agreement on Data Processing (research) between (org nr...) og Akershus University Hospital HF (org nr )

Size: px
Start display at page:

Download "Draft of Agreement on Data Processing (research) between (org nr...) og Akershus University Hospital HF (org nr )"

Transcription

1 Versjon 2 Draft of Agreement on Data Processing (research) between (org nr...) og Akershus University Hospital HF (org nr ) 1 The parties of the agreement Purpose and area for the agreement Duration and termination of the agreement The obligations for the parties according to the Act on Personal Data Termination of agreement Replacement of data Data subject to deletion or destruction Purpose of the use of Personal Data under the agreement Specification of Data related to identification of patients Persons in charge during running of the agreement Requirements (standards of) to information security Request to technical measures Entrance control Requests to control on entrance of Processor s site Security audit, verification and testing Secrecy Breach of Agreement and sanctions Reliability of subcontractors Transport of the Agreement Choice of law and legal venue Law relevant to the Agreement Signing... 5 Where text in yellow or italics: delet instructions and ad relevant text 1 The parties of the agreement This agreement is set up for the following parties Akershus University Hospital HF as the controller (the data controller, hereafter called Ahus) and name of firm... (the data processor, hereafter called the Processor). 2 Purpose and area for the agreement The purpose of this Agreement is to state what purpose the information in question can be expoited for as to the use and security of Personal data which are handed over by Ahus to Processor. If for any reason Processor wants to entrust personal data from Ahus to a third party or subcontractor for storing, analyze or otherwise use the data, this must be described in this Agreement. Title of the project: xxxxxxxxx (When research or responsible person on other kind of project) Personal data delivered or derived according to this Agreement might be saved in different formats as a file, system, application or on a server, back-up copies and alike, will further on in this Agreement be called the Datasystem. 3 Duration and termination of the agreement This agreement is valid from, and has a duration until. On xx months written notice the agreement may be terminated. 4 The obligations for the parties according to the Act on Personal Data Ahus is responsible to the Norwegian authorities in accordance to the Personal Data Act, and regulations by the Authorities, (see no 15 for full naming): o Personal Health Data Filing System Act o Secondary law of Personal Data Agreement on Data processing (research)_v1 Side 1 av 6

2 o «Code of Conduct» This implies that Ahus is responsible to see to that the claims in the acts and regulations also are fulfilled at the Processors site regarding handling of Personal Data by Processor belonging to Ahus. This is according to Data Personal Act 15 and the secondary law of personal data Other use of the Personal Data, require prior written consent from Ahus. When processing personal data on behalf of Ahus, the Processor is obliged to follow the routines and instructions set by Ahus at any given time. When the set of data include health information combined to facts which can lead to reveal the personal identity of single patients, that is through coded lists, personal numbers, date of birth, number from the national registration authorities (NPR-number), telephone number or other likewise; the Act Personal Health Data Filing System, also sets limits to the purpose of use of the data. The Processor is obliged to give Ahus access to his written technical and organizational measures for security, and to provide assistance so that Ahus can fulfill its responsibilities pursuant to the Acts and the Regulations which are the sources of the Code of Conduct. Unless otherwise agreed or pursuant to statutory regulations, Ahus is entitled to get access to all personal Data being processed on behalf of Ahus and the Datasystems used for this purpose. The Processor shall provide the necessary assistance for this without cost for Ahus. The Processor must observe professional secrecy in regard to the documentation and Personal Data to which he has access in accordance with this agreement. This provision also applies after the agreement has been discontinued without limitation to time. Security measures must be established to keep Personal Data related to Ahus, divided from those of other agreements with other Controllers as well as the Processor s own. In case the agreement has a longitude of more than 3 years, the Processor must every third year, report to Ahus on whether (if) Personal Data are still stored according to the Code of Conduct including Acts and regulations. This is the case also if no alterations have taken place. 5 Termination of agreement 5.1 Replacement of data At termination of the agreement all data related and in possession of Processor must be replaced or delivered in return to Ahus. 5.2 Data subject to deletion or destruction Processor must delete or destroy all material in a secure and definite/irreversible manner which contains data such as documents, data, diskettes, CDs, backup-copies, storage devices and so forth, or return it all to Ahus. 6 Purpose of the use of Personal Data under the agreement <Fill in, and tell what use the data is meant for. If in any case data from Ahus will be connected to other sets of data prior written consent must be given by Ahus. > 7 Specification of Data related to identification of patients <Fill inn, and explain whether data under the agreement either directly tells the identity of patients or the signs of identity are deleted. If there is a key to the identity this must be described along with how, where and by whom it is stored. > 8 Persons in charge during running of the agreement Persons in charge of the parties during this agreement: Ahus: <name, address, and phone number, role >,... Processor: < name, address, and phone number, role >,... Agreement on Data processing (research)_v1 Side 2 av 6

3 9 Requirements (standards of) to information security Both parties are at any time during the agreement, responsible to ensure that requirements to security of Personal Data are treated according to the Personal Data Act 13 and the secondary personal Data, and its Chapter 2. Data on health must also be treated according to requirements set forth in the Personal Health Data Filing System Act and according to Code of Conduct and its best practice routines. Processor must report on risks according to likelihood of an incident occurring and on the consequence of such an incident at Processors or Suppliers sites and/or devices. Such documentation must be brought forth at the request of Ahus, see Code of Conduct and best practice routine no 7. Processor is expected to have set defined goals as to measure accepted risks on security, strategy, organization and liability according to the Code of Conduct and its best practice routines as described in the sheets following, and necessary system for internal control. Suspicion on or breach of confidentiality, availability, integrity or quality for Personal Health Data is to be reported to the Personal data ombudsman at Ahus immediately. Processor is obliged to have routines on logging of mistakes and discrepancies of importance to the security derived from Ahus. When if such incidents are revealed processor must as soon as possible and within 24 hours warn Ahus and immediately take charge to minimize the damage to the interests of Ahus. Security audits at Processors site by Ahus may take place on files, systems, application routines etc covered by this agreement. The purpose will be to validate that the practicing of this agreement is according to standards set by Code of Conduct. Periodical internal reports from Processor may be included to the verification. 9.1 Request to technical measures Requests to technical measures: Access to Personal Data covered by this agreement has to be authorized through individual codes of authentication combined to passing codes in numbers: Authorizes personal only must be given access to data stored and belonging to Ahus. Sensitive personal data must be protected against unintended, unlawful sharing and delivery to strangers. Hinderances to unauthorized moving and or copying of sensitive personal data from devices designed for storage must be established. Encrypted communication is requested if when sensitive personal data is passed through networks which lacks security level Entrance control Processor is responsible regarding handling of information by employees and that of Subprocessors, Written prior statement on confidentiality of both given access to Personal Data under this agreement and deriving from Ahus must be available on request. The statement must be valid forever even after the end of access and running time of the Agreement, and until Ahus gives written consent to evoke the confidentiality. Processor must have routines which covers authorization and authentication to verify that access has been limited to those persons who are in need to cope with tasks he is dedicated to. Level of access must be within necessary limits to fulfill the Agreement. Processor must keep overview of authorizes personal, which can be made available on the request of Ahus. In case Ahus find that one person should not deal with the Agreement the person in question will be taken off. In case Processor use portable client machinery to carry out the agreement, Processor must have routines to ensure they are used only for the purpose of this agreement and to get support from subcontractors on running application or giving advice to users. Agreement on Data processing (research)_v1 Side 3 av 6

4 In case third parties or subcontractors are given access preliminary authorization and authentication must be used, and verification must be available as mentioned elsewhere in this Agreement. 9.3 Requests to control on entrance of Processor s site Personal ID-card with mechanisms for authorization and authentication or alike must be in use. Limited entrance to specific areas (rooms for running and server) according to need must be set. Unauthorized persons must be followed. Automatically locks must be installed on doors at following kind of areas: datahall/room for servers, rooms for running and support, technical rooms for connections, switches and routers, and the like. 9.4 Security audit, verification and testing Ahus is entitled to view and make visits for verification on site as to see how the systems are set up including what security measures which are in use. This also includes access to documentation, interviews, notes form meetings, tests, measures of control on movements (traffic) on net, as well as at activities on server, supplied with other kinds of verification, which Ahus finds relevant. Processor accepts that Ahus may carry out such steps itself, or chose a third party to perform the verification. All technical devices, documentation on organization and those which describe administering of the service which is delivered to Ahus, may be subject to verification. On two weeks written notice Processor will perform the documentation mentioned above. If Ahus during verification finds breaches on security to data Processor immediately and without delay un necessary delay will take steps to make corrections. Plans to carry out corrections and identification on the items will be presented. As part of the agreement and without costs to Ahus, Processor will contribute with personal of relevant professional skills, for necessary amount of time for corrections related to reestablishment of security of the Datasystem in question. This will be the case of breaches and in case of necessity for restorations are due to actions or lack of such, at hands of Processor and / or subcontractor. 10 Secrecy All information derived from this agreement will by both parties, be treated according to professional secrecy. This includes information which is confidential such as personal data, security or contractual measures and information which may be of vital importance to the owner or which may harm the owner if the information came to knowledge of a third professional party. This provision includes all personal responsible to Processor and his subcontractors given access on his behalf to carry out the agreement. They all must sign a declaration on secrecy. On request a copy must be available from Processor to Ahus. The content of the declaration must be in accordance to that of Ahus, and may be subject to change if Ahus finds it not in accordance to the Code of Conduct. Precautions must be taken by both parties to storage devices regarding unlawfully use or access from unauthorized persons or at the hands of a third party. This provision also applies indefinitely of time and without regard to the continuation of the Agreement, and including all personal or others who has had access to the practicing this Agreement. 11 Breach of Agreement and sanctions In the event of breach of this agreement, Ahus can instruct the Processor to stop further handling of the information with immediate effect. Breach of agreement will be stated if one of the parties does not fulfill his obligations described in the agreement or Code of Conduct, unless this is due to situations of Force Majeur. Written statement of breach of Agreement must be presented without unduly delay to be valid. The party which states breach of agreement is entitled to keep back his obligations described in the Agreement, limited to within reasonable time for the responsible party to take necessary steps to diminish or repair the effect of the breach. Both parties are obliged to ensure as little damage to the Data is made until the case is settled as to whom is responsible for the trouble caused. Agreement on Data processing (research)_v1 Side 4 av 6

5 In the event of thoroughly breach of the agreement, the other party may after written notice with due time to repair the damage terminate the agreement immediately and claim for compensation for loss this may have caused him. 12 Reliability of subcontractors If one of the parties engages subcontractors to fulfill his part of the agreement, the party is still responsible to carry out the agreement as described as if he himself had fulfilled the agreement. Prior written consent from Ahus is pursuant to engage subcontractors by Processor. Subcontractors must sign on a statement which describes that he will be loyal to the agreement included questions related to secrecy and according to Code of Conduct. 13 Transport of the Agreement In the event other governmental institutions of Norway should take over the agreement from Ahus as a whole or for parts, the agreement will still be valid on the same conditions. Processor may claim his costs related to this covered by Ahus. Processor may transport the agreement upon prior written acceptance by Ahus. Denial of acceptance is only due on fair reasons. Economical claims related to the transport of this Agreement is allowed but Processor is still obliged to carry out his obligations as described in the agreement until his successor is able to take over in full scale. 14 Choice of law and legal venue This agreement is subject to Norwegian jurisdiction and the parties agree on The District Court of Nedre Romerike as the legal venue. This also applies after termination of the agreement. 15 Law relevant to the Agreement Act , Act relating to personal health data filing systems and the processing of health data; called Personal Health Data Filing System Act Secondary law on personal data Act relating to the processing of personal data; called Personal Data Act Code of conduct for information security in the healthcare, care, and social services sector (Normen, called Code)) is primarily based upon the privacy and health legislation s requirements to establish satisfactory information security for systems containing health and personal data, as described and agreed upon by individual organizations and the sector in general. 16 Signing This agreement has been drawn up in 2 two copies, of which the parties retain one copy each. Nordbyhagen, the.... Akershus University Hospital HF (signatur) Assistant Managing director Tone IkdahlDirector research and innovation Tormod Fladby Processor (signatur) Agreement on Data processing (research)_v1 Side 5 av 6

6 Position:.. Name: (in typed letters) Position:.. Name: Agreement on Data processing (research)_v1 Side 6 av 6

Annex 1: Standard Contractual Clauses (processors)

Annex 1: Standard Contractual Clauses (processors) Annex 1: Standard Contractual Clauses (processors) For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure

More information

SUPPLIER DATA PROCESSING AGREEMENT

SUPPLIER DATA PROCESSING AGREEMENT SUPPLIER DATA PROCESSING AGREEMENT This Data Protection Agreement ("Agreement"), dated ("Agreement Effective Date") forms part of the ("Principal Agreement") between: [Company name] (hereinafter referred

More information

OTrack Data Processing Terms

OTrack Data Processing Terms BACKGROUND These Personal Data Processing Terms (the Agreement ) are entered into between Optimum Records Limited ( Optimum ) and the school using the services provided by Optimum (the School ) whose details

More information

Processor Agreement SURF Model Agreement

Processor Agreement SURF Model Agreement Processor Agreement SURF Model Agreement Utrecht, 18 November 2016 Version: 1.1 About this publication Processor Agreement SURF Model Agreement SURF P.O. Box 19035 NL-3501 DA Utrecht T +31 88 787 30 00

More information

DATA PROCESSING AGREEMENT. between [Customer] (the "Controller") and LINK Mobility (the "Processor")

DATA PROCESSING AGREEMENT. between [Customer] (the Controller) and LINK Mobility (the Processor) DATA PROCESSING AGREEMENT between [Customer] (the "Controller") and LINK Mobility (the "Processor") Controller Contact Information Name: Title: Address: Phone: Email: Processor Contact Information Name:

More information

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection Commission Decision C(2010)593 Standard Contractual Clauses (processors)

More information

Template Commission pursuant to Section 11 BDSG

Template Commission pursuant to Section 11 BDSG Template Commission pursuant to Section 11 BDSG Agreement between... - (the Principal ) - and... - (the Agent ) - 1. Subject-matter and duration of the commission Subject-matter of the commission: The

More information

Data Processing Agreement. <<Health Service Provider>> The National Message Broker Service known as Healthlink

Data Processing Agreement. <<Health Service Provider>> The National Message Broker Service known as Healthlink Between And The National Message Broker Service known as Healthlink THIS AGREEMENT is dated and made between: (1) , which has its principle administrative

More information

TEMPLATE FOR PROCESSOR AGREEMENTS BETWEEN MUNICIPALITIES AND IT SUPPLIERS - version 1.0 of 3 April 2017

TEMPLATE FOR PROCESSOR AGREEMENTS BETWEEN MUNICIPALITIES AND IT SUPPLIERS - version 1.0 of 3 April 2017 TEMPLATE FOR PROCESSOR AGREEMENTS BETWEEN MUNICIPALITIES AND IT SUPPLIERS - version 1.0 of 3 April 2017 Dette er et bud på en engelsk oversættelse af Skabelon for databehandleraftaler mellem kommuner og

More information

AGREEMENT FOR ACCESS, WHICH MAY RESULT IN PERSONAL DATA PROCESSING

AGREEMENT FOR ACCESS, WHICH MAY RESULT IN PERSONAL DATA PROCESSING AGREEMENT FOR ACCESS, WHICH MAY RESULT IN PERSONAL DATA PROCESSING Between K MEDIA TECH Ltd, a company established and existing in accordance with the laws of the Republic of Bulgaria, with seat and registered

More information

BASECONE DATA PROCESSING AGREEMENT (BASECONE AS PROCESSOR)

BASECONE DATA PROCESSING AGREEMENT (BASECONE AS PROCESSOR) BASECONE DATA PROCESSING AGREEMENT (BASECONE AS PROCESSOR) The undersigned: Basecone N.V., a corporation established under Dutch law, with its corporate domicile at Eemweg 8, 3742 LB Baarn, the Netherlands

More information

PERSONAL DATA PROCESSING AGREEMENT

PERSONAL DATA PROCESSING AGREEMENT PERSONAL DATA PROCESSING AGREEMENT between the following parties: 1. Name:............... Registration number / VAT ID:... Address:... Signed by:... Signature:... (hereinafter as Controller ) and 2. Name:

More information

DATA PROCESSING ADDENDUM. 1.1 The User and When I Work, Inc. ("WIW") have entered into the Terms of Service, for the provision of the Service.

DATA PROCESSING ADDENDUM. 1.1 The User and When I Work, Inc. (WIW) have entered into the Terms of Service, for the provision of the Service. DATA PROCESSING ADDENDUM 1. BACKGROUND 1.1 The User and When I Work, Inc. ("WIW") have entered into the Terms of Service, for the provision of the Service. 1.2 In the event that WIW Processes User Personal

More information

Zab Zab Application Privacy Policy Terms and Conditions

Zab Zab Application Privacy Policy Terms and Conditions Zab Zab Application Privacy Policy Terms and Conditions Zab Zab is an application available for Android/iOS mobile devices, which allows Users to see nearby parties hosted by private individuals (so-called

More information

Exhibit MC - Standard Contractual Clauses (processors)

Exhibit MC - Standard Contractual Clauses (processors) Exhibit MC - Standard Contractual Clauses (processors) For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not

More information

Data Protection Transfer Agreement. Reference Number: CORP_142-a01 Policy

Data Protection Transfer Agreement. Reference Number: CORP_142-a01 Policy Data Protection Transfer Agreement Reference Number: CORP_142-a01 Policy Revision History Version Last revised Next review date Policy Owner Notes 1.0 6 January 2014 30 September 2014 Pauline McKendrick

More information

Instructions on the processing of personal data in the election process

Instructions on the processing of personal data in the election process Unofficial translation Instructions on the processing of personal data in the election process The present instructions are developed in accordance with the provisions of Art. 20 para. (1) letter c) of

More information

EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS

EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS EU GDPR - DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CDNETWORKS CUSTOMERS Who? This Data Processing Addendum ( DPA, Addendum ) has been prepared for those customers of CDNetworks that are data controllers

More information

CHAPTER I. Definitions

CHAPTER I. Definitions 13 FEBRUARY 2001 Royal Decree implementing the Act of 8 December 1992 on the protection of privacy in relation to the processing of personal data Unofficial translation September 2009 ALBERT II, King of

More information

Security Video Surveillance Policy

Security Video Surveillance Policy Security Video Surveillance Policy Policy Statement The Municipality of Central Elgin (the Municipality) recognizes the need to balance an individual s right to privacy and the need to ensure the safety

More information

Telekom Austria Group Standard Data Processing Agreement

Telekom Austria Group Standard Data Processing Agreement Telekom Austria Group Standard Data Processing Agreement This Agreement is entered into by and between: I. [TAG Company NAME], a company duly established and existing under the laws of [COUNTRY] with its

More information

STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT

STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT STATOIL BINDING CORPORATE RULES - PUBLIC DOCUMENT The purpose of this Statoil Binding Corporate Rules Public Document is to explain the content of the Binding Corporate Rules (BCR) and help ensure that

More information

1. Processing of personal data legal basis, purpose and scope Legal basis fulfillment of statutory legal requirements

1. Processing of personal data legal basis, purpose and scope Legal basis fulfillment of statutory legal requirements PRIVACY NOTICE OF PERSONAL DATA PROCESSING FOR DATA SUBJECT NON-EMPLOYEES Of U. S. Steel Košice, s.r.o. pursuant to Regulation of the European Parliament and the Council (EU) 2016/679 U. S. Steel Košice,

More information

DATA PROCESSING AGREEMENT. (1) You or your organization or entity as The Data Controller ( The Client or The Data Controller ); and

DATA PROCESSING AGREEMENT. (1) You or your organization or entity as The Data Controller ( The Client or The Data Controller ); and DATA PROCESSING AGREEMENT BETWEEN: (1) You or your organization or entity as The Data Controller ( The Client or The Data Controller ); and (2) Moodle Pty Ltd being a company registered within Australia

More information

SIMON READHEAD Q.C. PRIVACY NOTICE

SIMON READHEAD Q.C. PRIVACY NOTICE SIMON READHEAD Q.C. PRIVACY NOTICE Introduction 1. I am committed to handling your personal information fairly, lawfully and securely in accordance with current data protection laws. This privacy notice

More information

DATA SHARING AND PROCESSING

DATA SHARING AND PROCESSING DATA SHARING AND PROCESSING Capita Business Services Limited March 2016 Version 1.3 TABLE OF CONTENTS: Item Heading Page 1 Data Processing Agreement 2 2 Data Protection Act 1998 2 3 Data Protection Act

More information

EMPOWER SOFTWARE HOSTED SERVICES AGREEMENT

EMPOWER SOFTWARE HOSTED SERVICES AGREEMENT EMPOWER SOFTWARE HOSTED SERVICES AGREEMENT 1. AGREEMENT. THIS HOSTED SERVICES AGREEMENT IS A BINDING CONTRACT between Empower Software, Inc. ( Empower or we ) and you and/or the company or other legal

More information

Nestlé Canada Inc. Privacy Policies and Practices April 13, 2012

Nestlé Canada Inc. Privacy Policies and Practices April 13, 2012 Nestlé Canada Inc. Privacy Policies and Practices April 13, 2012 Glossary of Terms... 3 The Privacy Principles at Nestlé Canada... 5 Accountability... 5 Identifying Purpose... 5 Consent... 6 Obtaining

More information

Charities & Not-for-Profits Overview of Data Protection Law

Charities & Not-for-Profits Overview of Data Protection Law Charities & Not-for-Profits Overview of Data Protection Law The Data Protection Law provides a framework for the processing of data relating to individuals that serves to balance the needs of organisations

More information

General Rules on the Processing of Personal Data SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)...

General Rules on the Processing of Personal Data SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... DATA PROTECTION REGULATIONS 2015 DATA PROTECTION REGULATIONS 2015 General Rules on the Processing of Personal Data... 1 Rights of Data Subjects... 6 Notifications to the Registrar... 7 The Registrar...

More information

Appendix 1 Data Processing Agreement

Appendix 1 Data Processing Agreement Appendix 1 Data Processing Agreement Except as modified below, the terms of the Agreement shall remain in full force and effect. The Agreement and this DPA are connected and cannot be terminated separately.

More information

Fragomen Privacy Notice

Fragomen Privacy Notice Effective Date: May 14, 2018 Fragomen Privacy Notice Fragomen, Del Rey, Bernsen & Loewy, LLP, Fragomen Global LLP, and our related affiliates and subsidiaries 1 (collectively, Fragomen or "we") want to

More information

Model Data Processing Agreement (GDPR)

Model Data Processing Agreement (GDPR) Johan Vandendriessche Partner Erkelens Law Visiting Professor ICT Law UGent Visiting Professor ICT and Data Protection Law HoWest Johan.vandendriessche@erkelenslaw.com Isaure de Villenfagne Attorney-at-Law

More information

FUJITSU Cloud Service K5: Data Protection Addendum

FUJITSU Cloud Service K5: Data Protection Addendum FUJITSU Cloud Service K5: Data Protection Addendum May 24, 2018 This Data Protection Addendum (the "Addendum") forms part of the FUJITSU Cloud Service K5: TERMS OF USE (the "Agreement") between the Customer

More information

DocuSign Envelope ID: 93578C7C-0B BEE9-0536AB6EDE32

DocuSign Envelope ID: 93578C7C-0B BEE9-0536AB6EDE32 For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, Customer

More information

PIPEDA and Your Practice

PIPEDA and Your Practice Office of the Privacy Commissioner of Canada A Privacy Handbook for Lawyers PIPEDA and Your Practice Table of Contents INTRODUCTION...1 Lawyers and privacy... 1 Scope of this handbook... 1 Application

More information

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection Commission Decision C(2004)5721 SET II Standard contractual clauses for

More information

Data processing agreement

Data processing agreement Data processing agreement between....(client) (data controller) and Key-Systems GmbH (contractor) (data processor) PREAMBLE The processing is based on the agreement between the parties for the provision

More information

BINDING CORPORATE RULES PRIVACY policy. Telekom Albania. Çaste që na lidhin.

BINDING CORPORATE RULES PRIVACY policy. Telekom Albania. Çaste që na lidhin. BINDING CORPORATE RULES PRIVACY policy Telekom Albania Çaste që na lidhin. Table of Contents preamble...... 4 1 SCOPE..... 5 1.1 Legal Nature of the Binding Corporate Rules Privacy..... 5 1.2 Area of Application...

More information

Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service )

Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service ) Terms of Service Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service ) to an agreement concluded via the Meisterplan Webshop or concluded in any other way

More information

The Ministry of Technology, Communication and Innovation and The Data Protection Office. Workshop On DATA PROTECTION ACT 2017

The Ministry of Technology, Communication and Innovation and The Data Protection Office. Workshop On DATA PROTECTION ACT 2017 The Ministry of Technology, Communication and Innovation and The Data Protection Office Workshop On DATA PROTECTION ACT 2017 Tuesday 06 March 2018 from 08.30 hrs 15.30 hrs InterContinental Mauritius Resort,

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum The parties conclude this Data Processing Addendum ( DPA ), which forms part of the Agreement between Customer and Licensor ( Epignosis ), to reflect our agreement about the Processing

More information

Sales Order (Processing Services)

Sales Order (Processing Services) SO# DIRECT CUST# INDIRECT CUST# Sales Order (Processing Services) Note: RelayHealth will assign CUST# s and SO# will be completed upon receipt. Sold To ( End User ): Bill To: Note: cannot be a P.O. Box

More information

Terms of Use Terminated-Vested Cashout Website

Terms of Use Terminated-Vested Cashout Website Terms of Use Terminated-Vested Cashout Website This Terms of Use page provides important information regarding the scope, duration and terms of any service you may obtain from this website ( Service ),

More information

The whistleblowing procedure is based on the following principles:

The whistleblowing procedure is based on the following principles: The HeINeKeN code of Whistle Blowing INTroduCTIoN HeINeKeN has introduced the HeINeKeN Business principles (as defined hereafter) setting out the guiding business ethics principles for HeINeKeN s business

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM Based on European Commission Decision 2010/87/EU Standard Contractual Clauses (processors) DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) supplements any current Terms of Service or other

More information

A combined file and information system description and information document regarding the Data System for Administrative Matters

A combined file and information system description and information document regarding the Data System for Administrative Matters Privacy statement ID-1641657 1 (10) 2.2.2017 POL-2016-17613 A combined file and information system description and information document regarding the Data System for Administrative Matters Personal Data

More information

DocuSign Envelope ID: D3C1EE91-4BC9-4BA9-B2CF-C0DE318DB461

DocuSign Envelope ID: D3C1EE91-4BC9-4BA9-B2CF-C0DE318DB461 Spanning Data Protection Addendum and Incorporating Standard Contractual Clauses for Controller to Processor Transfers of Personal Data from the EEA to a Third Country This Data Protection Addendum ("

More information

Privacy Policy. This Privacy Policy sets out the Law Society's policies in relation to the management of Personal Information.

Privacy Policy. This Privacy Policy sets out the Law Society's policies in relation to the management of Personal Information. Privacy Policy Law Society of South Australia Privacy Policy The Law Society of South Australia (Law Society or we, us or our) deals with information privacy in accordance with the Privacy Act 1988 (Cth)

More information

Estonian National Electoral Committee. E-Voting System. General Overview

Estonian National Electoral Committee. E-Voting System. General Overview Estonian National Electoral Committee E-Voting System General Overview Tallinn 2005-2010 Annotation This paper gives an overview of the technical and organisational aspects of the Estonian e-voting system.

More information

LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS

LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS LAW OF THE REPUBLIC OF ARMENIA ON PROTECTION OF PERSONAL DATA CHAPTER 1 GENERAL PROVISIONS Article 1. Subject matter of the Law 1. This Law shall regulate the procedure and conditions for processing personal

More information

FULLY EXECUTED Contract Number: Contract Effective Date: 08/08/2014 Valid From: 07/01/2014 To: 12/31/2099

FULLY EXECUTED Contract Number: Contract Effective Date: 08/08/2014 Valid From: 07/01/2014 To: 12/31/2099 FULLY EXECUTED Contract Number: 4400013601 Contract Effective Date: 08/08/2014 Valid From: 07/01/2014 To: 12/31/2099 Page 1 of 1 All using Agencies of the Commonwealth, Participating Political Subdivision,

More information

Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject)

Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject) Information leaflet about processing of personal data for Newsletter Recipients (hereinafter Data Subject) In accordance with articles 13 and 14 of the regulation (EU) 2016/679 OF the European Parliament

More information

Customer Data Annual Privacy Agreement

Customer Data Annual Privacy Agreement Customer Data Annual Privacy Agreement Capita Children s Services, a trading name of Capita Business Services Ltd, is serious about the privacy of your data. This Agreement relates to written consent for

More information

Between. address (which you used when signing the Main Contract with Shore) - the "Principal" - and

Between.  address (which you used when signing the Main Contract with Shore) - the Principal - and Data protection and data security regulation for commission-based relationships according to Section 11 of the German Federal Data Protection Act (BDSG) Between (1) Name or company Street and house number

More information

Policy To Protect Personal Information

Policy To Protect Personal Information Policy To Protect Personal Information 1. Accountability 1.1. Melody Deeley is hereby appointed as the Personal Information Compliance Officer (the Officer ) for Summit Pacific College ( SPC ). 1.2. All

More information

Interstate Commission for Adult Offender Supervision

Interstate Commission for Adult Offender Supervision Interstate Commission for Adult Offender Supervision Privacy Policy Interstate Compact Offender Tracking System Version 3.0 Approved 04/23/2009 Revised on 4/18/2017 1.0 Statement of Purpose The goal of

More information

SSLI \6.0 v1.0

SSLI \6.0 v1.0 SCHEDULE 3 STANDARD CONTRACTUAL CLAUSES (PROCESSORS) For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of Personal Data to Processors established in third countries which do not

More information

Working document 01/2014 on Draft Ad hoc contractual clauses EU data processor to non-eu sub-processor"

Working document 01/2014 on Draft Ad hoc contractual clauses EU data processor to non-eu sub-processor ARTICLE 29 DATA PROTECTION WORKING PARTY 757/14/EN WP 214 Working document 01/2014 on Draft Ad hoc contractual clauses EU data processor to non-eu sub-processor" Adopted on 21 March 2014 This Working Party

More information

SUBSIDIARY LEGISLATION DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS

SUBSIDIARY LEGISLATION DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) [S.L.440.05 1 SUBSIDIARY LEGISLATION 440.05 DATA PROTECTION (PROCESSING OF PERSONAL DATA IN THE POLICE SECTOR) REGULATIONS 30th September,

More information

Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service )

Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service ) Terms of Service Meisterplan Software as a Service Terms and Conditions (hereinafter referred to as Terms of Service ) to an agreement concluded via the Meisterplan Webshop or concluded in any other way

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement This Data Protection Addendum ("Addendum") forms part of the Master Subscription Agreement ("Principal Agreement") between: (i) Inspectlet ("Vendor") acting on its own behalf

More information

Morningstar ByAllAccounts Service User Agreement

Morningstar ByAllAccounts Service User Agreement Morningstar ByAllAccounts Service User Agreement This Morningstar ByAllAccounts Service User Agreement (the "Agreement") is a legal agreement between you and Morningstar, Inc., ("Morningstar") for the

More information

IRB RELIANCE EXCHANGE PORTAL AGREEMENT

IRB RELIANCE EXCHANGE PORTAL AGREEMENT IRB RELIANCE EXCHANGE PORTAL AGREEMENT This Portal Access Agreement ( Agreement ) is entered into between Vanderbilt University Medical Center, a not for profit hospital system located at 11211 Medical

More information

GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS

GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS June 2017 Status: Approved Print Date: 6/29/2017 Page 1 of 18 Section 1: Introduction GUIDELINES FOR THE USE OF ELECTORAL PRODUCTS The Election Act requires

More information

FOUR SEASONS HOTELS BOGOTÁ PERSONAL DATA TREATMENT POLICY HOTELES CHARLESTON BOGOTÁ S.A.S.

FOUR SEASONS HOTELS BOGOTÁ PERSONAL DATA TREATMENT POLICY HOTELES CHARLESTON BOGOTÁ S.A.S. FOUR SEASONS HOTELS BOGOTÁ PERSONAL DATA TREATMENT POLICY HOTELES CHARLESTON BOGOTÁ S.A.S. 1. Introduction: According to Law 1581, 2012 and Decree 1377, 2013 and other applicable norms in relation to protection

More information

THE PROCESSING OF PERSONAL DATA (PROTECTION OF INDIVIDUALS) LAW 138 (I) 2001 PART I GENERAL PROVISIONS

THE PROCESSING OF PERSONAL DATA (PROTECTION OF INDIVIDUALS) LAW 138 (I) 2001 PART I GENERAL PROVISIONS THE PROCESSING OF PERSONAL DATA (PROTECTION OF INDIVIDUALS) LAW 138 (I) 2001 PART I GENERAL PROVISIONS Short title. 1. This Law may be cited as the Processing of Personal Data (Protection of Individuals)

More information

TEXAS DEPARTMENT OF PUBLIC SAFETY 5805 NORTH LAMAR BOULEVARD POST OFFICE BOX 4087, AUSTIN, TX /

TEXAS DEPARTMENT OF PUBLIC SAFETY 5805 NORTH LAMAR BOULEVARD POST OFFICE BOX 4087, AUSTIN, TX / TEXAS DEPARTMENT OF PUBLIC SAFETY 5805 NORTH LAMAR BOULEVARD POST OFFICE BOX 4087, AUSTIN, TX 78773-0252 512/424-2365 THOMAS A. DAVIS, JR. DIRECTOR DAVID McEATHRON ASST. DIRECTOR SCHOOL CONTRACTOR DOCUMENT

More information

CLINICAL TRIAL AGREEMENT [Identification of the trial, Person in charge of research] Sponsor of the Trial: Institution:

CLINICAL TRIAL AGREEMENT [Identification of the trial, Person in charge of research] Sponsor of the Trial: Institution: CLINICAL TRIAL AGREEMENT [Identification of the trial, Person in charge of research] Sponsor of the Trial: Institution: 2 (20) APPENDIX 1 Parties................................ 4 2 Scope of the agreement................................4

More information

DATA PROTECTION POLICY STATUTORY

DATA PROTECTION POLICY STATUTORY DATA PROTECTION POLICY MAIDEN ERLEGH TRUST STATUTORY INITIAL APPROVAL July 2017 REVIEW FREQUENCY At least every two years REVIEWED CONTENTS PART ONE: POLICY STATEMENT & OBJECTIVES PART TWO: STATUS OF THE

More information

ENERCALC Software License Agreement

ENERCALC Software License Agreement ENERCALC Software License Agreement 1 Jan 2009, revised 18-Feb-2014 & 1-Jun-2015, 9-Jun-2017 This license agreement applies to: Structural Engineering Library, STRUCTURE, RetainPro, RETAIN and 3D PLEASE

More information

Attachment 1. Commission Decision C(2010)593 Standard Contractual Clauses (processors)

Attachment 1. Commission Decision C(2010)593 Standard Contractual Clauses (processors) Attachment 1 Commission Decision C(2010)593 Standard Contractual Clauses (processors) For the transfer of Personal Data to processors established in third countries which do not ensure an adequate level

More information

The NATIONAL CONGRESS decrees: CHAPTER I PRELIMINARY PROVISIONS

The NATIONAL CONGRESS decrees: CHAPTER I PRELIMINARY PROVISIONS Provides for the protection of personal data and changes Law No. 12,965, of April 23, 2014 (the Brazilian Internet Law ). The NATIONAL CONGRESS decrees: CHAPTER I PRELIMINARY PROVISIONS Art. 1 This Law

More information

SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY

SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY SKILLSTAR 2018 NONPROFIT KFT. DATA PROTECTION POLICY 1. OBJECT AND THE SCOPE OF THE POLICY 1.1. Object of the policy The General Data Protection Regulation, which entered into force on 25 th May 2018,

More information

Conditions for Processing Banking Transactions via the Corporate Banking Portal and HBCI/FinTS Service

Conditions for Processing Banking Transactions via the Corporate Banking Portal and HBCI/FinTS Service Corporate Banking Conditions for Processing Banking Transactions via the Corporate Banking Portal and HBCI/FinTS Service (Status 13 January 2018) 1. Scope of services (1) The Customer and its authorised

More information

PRIVACY POLICY. 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way.

PRIVACY POLICY. 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way. Page 1 of 10 1. OVERVIEW MEGT is committed to protecting privacy and will manage personal information in an open and transparent way. MEGT will fulfil its obligations under the Privacy Amendment (Enhancing

More information

HIPAA DATA USE AGREEMENT

HIPAA DATA USE AGREEMENT HIPAA DATA USE AGREEMENT This Data Use Agreement (this "Agreement") is entered into effective as of 20 and until months thereafter the Effective Date by and among St. Jude Children s Research Hospital,

More information

Key Considerations for Implementing Bodies and Oversight Actors

Key Considerations for Implementing Bodies and Oversight Actors Implementing and Overseeing Electronic Voting and Counting Technologies Key Considerations for Implementing Bodies and Oversight Actors Lead Authors Ben Goldsmith Holly Ruthrauff This publication is made

More information

Provider Electronic Trading Partner Agreement

Provider Electronic Trading Partner Agreement This Electronic Trading Partner Agreement ( Agreement ) is entered into as of the Day day of, 20 ( Effective Date ), by and between Blue Cross Month Year and Blue Shield of South Carolina and its subsidiaries,

More information

Personal Data Protection Law

Personal Data Protection Law Personal Data Protection Law 25.326 General Provisions. General principles related to the protection of data. Rights of data owners. Users and individuals in charge of files, records, and databases. Oversight.

More information

DFN-AAI Service Provider Agreement

DFN-AAI Service Provider Agreement DFN-AAI Service Provider Agreement (the Agreement) between DFN-Verein, Alexanderplatz 1, 10178 Berlin and (the Parties and each a Party) WHEREIN: A. The DFN-AAI is an infrastructure (Federation) for a

More information

END USER APPLICATION, LICENSE, NON-DISCLOSURE AND COMPLIANCE WITH EXPORT REGULATIONS AGREEMENT (EULA)

END USER APPLICATION, LICENSE, NON-DISCLOSURE AND COMPLIANCE WITH EXPORT REGULATIONS AGREEMENT (EULA) END USER APPLICATION, LICENSE, NON-DISCLOSURE AND COMPLIANCE WITH EXPORT REGULATIONS AGREEMENT (EULA) This End User License and Non-Disclosure Agreement (the Agreement ), effective as of the date on which

More information

THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL

THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL PRIOR PRINTER'S NO. PRINTER'S NO. THE GENERAL ASSEMBLY OF PENNSYLVANIA HOUSE BILL No. 1 Session of 01 INTRODUCED BY ELLIS, IRVIN, RABB, MILNE, PICKETT, BAKER, DAVIS, QUIGLEY, BOBACK, CHARLTON, O'NEILL,

More information

Certified Translation from German. Licence Agreement. 1. Subject-matter of the Agreement

Certified Translation from German. Licence Agreement. 1. Subject-matter of the Agreement Certified Translation from German Licence Agreement 1. Subject-matter of the Agreement 1.1 The Supplier has the right to use the Move IT software licence products (as per Annex 1). This software package

More information

The Lawyer s Ethical and Legal Duties to protect Private Information

The Lawyer s Ethical and Legal Duties to protect Private Information The Lawyer s Ethical and Legal Duties to protect Private Information Claude E. Ducloux Attorney At Law Board Certified Texas Board of Legal Specialization Civil Trial Law Civil Appellate Law Director of

More information

Data Protection Policy. Malta Gaming Authority

Data Protection Policy. Malta Gaming Authority Data Protection Policy Malta Gaming Authority Contents 1 Purpose and Scope... 3 2 Data Protection Officer... 3 3 Principles for Processing Personal Data... 3 3.1 Lawfulness, Fairness and Transparency...

More information

WITNESSETH: 2.1 NAME (Print Provider Name)

WITNESSETH: 2.1 NAME (Print Provider Name) AGREEMENT between OKLAHOMA HEALTH CARE AUTHORITY and SPEECH-LANGUAGE PATHOLOGIST WITNESSETH: Based upon the following recitals, the Oklahoma Health Care Authority (OHCA hereafter) and (PROVIDER hereafter)

More information

Access to Information and Protection of Privacy Act

Access to Information and Protection of Privacy Act Access to Information and Protection of Privacy Act Health Information Privacy and Management Act Regulations - Public Consultation Information and Privacy Commissioner s Comments Opening Remarks The Health

More information

MARYLAND Maryland MVA Real ID Act - Impact Analysis

MARYLAND Maryland MVA Real ID Act - Impact Analysis MARYLAND Maryland MVA Real ID Act - Impact Analysis REAL ID ACT REQUIREMENT IMPACT ASSUMPTIONS Full Legal Name into Driver Licensing System (DLS) (In Record, on Document) Modify DLS application and databases.

More information

EU STANDARD CONTRACTUAL CLAUSES (PROCESSORS)

EU STANDARD CONTRACTUAL CLAUSES (PROCESSORS) EU STANDARD CONTRACTUAL CLAUSES (PROCESSORS) For the purposes of transfer of personal data to processors established in third countries outside of the European Union which do not ensure an adequate level

More information

SOFTWARE AS A SERVICE (SaaS) TERMS and CONDITIONS FOR REMOTE ACCESS SERVICE SOLD BY VIDEOJET

SOFTWARE AS A SERVICE (SaaS) TERMS and CONDITIONS FOR REMOTE ACCESS SERVICE SOLD BY VIDEOJET SOFTWARE AS A SERVICE (SaaS) TERMS and CONDITIONS FOR REMOTE ACCESS SERVICE SOLD BY VIDEOJET These Software as a Service Terms and Conditions SaaS Terms and Conditions are by and between the Videojet entity

More information

PERSONAL INFORMATION PROTECTION ACT

PERSONAL INFORMATION PROTECTION ACT PERSONAL INFORMATION PROTECTION ACT Promulgated on March 29, 2011 Effective on September 30, 2011 CHAPTER I. GENERAL PROVISIONS Article 1 (Purpose) The purpose of this Act is to provide for the processing

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT WHEREAS, the American Osteopathic Board of Orthopedic Surgery (AOBOS) provides certain board certification services to osteopathic physicians who complete appropriate postdoctoral

More information

SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... 16

SCHEDULE 1 DATA TRANSFER AGREEMENT (Data Controller to Data Controller transfers)... 16 DATA PROTECTION REGULATIONS 2015 DATA PROTECTION REGULATIONS 2015 Part 1 General Rules on the Processing of Personal Data... 1 Part 2 Rights of Data Subjects... 7 Part 3 Notifications to the Registrar...

More information

Coordinated text from 10 August 2011 Version applicable from 1 September 2011

Coordinated text from 10 August 2011 Version applicable from 1 September 2011 Coordinated text of the Act of 30 May 2005 - laying down specific provisions for the protection of persons with regard to the processing of personal data in the electronic communications sector and - amending

More information

DATA PROTECTION LAWS OF THE WORLD. Egypt

DATA PROTECTION LAWS OF THE WORLD. Egypt DATA PROTECTION LAWS OF THE WORLD Egypt Downloaded: 21 July 2018 EGYPT Last modified 26 January 2017 LAW Egypt does not have a law which regulates protection of personal data. However, there are some piecemeal

More information

AGE FOTOSTOCK SPAIN, S.L. NON-EXCLUSIVE PHOTOGRAPHER AGREEMENT FOR RIGHTS MANAGED LICENSING

AGE FOTOSTOCK SPAIN, S.L. NON-EXCLUSIVE PHOTOGRAPHER AGREEMENT FOR RIGHTS MANAGED LICENSING AGE FOTOSTOCK SPAIN, S.L. NON-EXCLUSIVE PHOTOGRAPHER AGREEMENT FOR RIGHTS MANAGED LICENSING This contract (hereinafter referred to as the Agreement ) made on the day of 20 by and between age fotostock

More information

UGANDA REVENUE AUTHORITY TERMS AND CONDITIONS FOR WEB PORTAL USE

UGANDA REVENUE AUTHORITY TERMS AND CONDITIONS FOR WEB PORTAL USE 1. DISCLAIMER NOTICE UGANDA REVENUE AUTHORITY TERMS AND CONDITIONS FOR WEB PORTAL USE The information provided by UGANDA REVENUE AUTHORITY (URA) on the web portal relating to products and services (or

More information

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Commission Decision C(2010)593 Standard Contractual Clauses (processors)

EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE. Commission Decision C(2010)593 Standard Contractual Clauses (processors) EUROPEAN COMMISSION DIRECTORATE-GENERAL JUSTICE Directorate C: Fundamental rights and Union citizenship Unit C.3: Data protection Commission Decision C(2010)593 Standard Contractual Clauses (processors)

More information

HOUSE RESEARCH Bill Summary

HOUSE RESEARCH Bill Summary HOUSE RESEARCH Bill Summary FILE NUMBER: H.F. 1351 DATE: May 8, 2009 Version: Delete-everything amendment (H1351DE1) Authors: Subject: Winkler Elections Analyst: Matt Gehring, 651-296-5052 This publication

More information