SlideShare una empresa de Scribd logo
1 de 64
SYNEXUS Data Protection Training ,[object Object],[object Object],[object Object]
Experience ,[object Object],[object Object],[object Object],[object Object]
Training Objectives ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Agenda ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Why Comply? ,[object Object],[object Object],[object Object],[object Object]
Background to UK Data Protection ,[object Object],[object Object],[object Object],[object Object]
EC Directive on Privacy and Electronic Communications 2002 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
The European Dimension ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Case 43/75, Defrenne v. Sabena, 1976 E.C.R. 455.  ,[object Object],[object Object]
[object Object],[object Object],[object Object]
Meaning of Indirect Effect ,[object Object],[object Object],[object Object]
Implementation of the EU Data Protection Directive ,[object Object],[object Object],[object Object]
Essential Definitions ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Data ,[object Object],[object Object],[object Object]
Personal Data ,[object Object],[object Object],[object Object]
Personal Data ,[object Object],[object Object],[object Object],[object Object]
Sensitive Personal Data ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Processing ,[object Object],[object Object],[object Object]
(c) disclosure of the information or data by transmission, dissemination or otherwise making available, or (d) alignment, combination, blocking, erasure or destruction of the information or data Difficult to imagine any action which is not processing
Data Subject ,[object Object],[object Object],[object Object],[object Object]
Data Controller ,[object Object],[object Object],[object Object]
Data Processor ,[object Object],[object Object],[object Object],[object Object]
Data Protection Act 1998 The Data Protection Principles
Eight Data Protection Principles ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Fair and Lawful Processing ,[object Object],[object Object],[object Object],[object Object],[object Object]
Rights of the Data Subject ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Security ,[object Object],[object Object],[object Object],[object Object],[object Object]
International Transfers ,[object Object],[object Object],[object Object]
International Transfers ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
International Transfers ,[object Object],[object Object],[object Object]
International Transfers ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
The Law of Direct Marketing ,[object Object],[object Object]
The following main statutory provisions regulate direct marketing in the UK ,[object Object]
Example of related Statutory Instrument ,[object Object]
Consumer Protection (Distance Selling) Regulations 2000 ,[object Object],[object Object]
Distance Contract ,[object Object]
Means of Distance Communication ,[object Object]
The Notification Requirement  ,[object Object],[object Object],[object Object]
IT IS A CRIMINAL OFFENCE TO PROCESS PERSONAL DATA WITHOUT AN APPROPRIATE ENTRY ON THE REGISTER OF DATA CONTROLLERS
Where direct marketing is carried on by a business, the appropriate additional register entries will be either or both of the following:
[object Object],[object Object]
The register may be searched at ,[object Object]
The Right to Prevent Direct Marketing ,[object Object],[object Object]
S11 DPA ,[object Object],[object Object]
The Preference Services ,[object Object],[object Object],[object Object],[object Object]
Related Rights ,[object Object],[object Object],[object Object],[object Object]
Related Rights ,[object Object],[object Object],[object Object],[object Object]
Automated Decisions ,[object Object],[object Object]
Compensation for Damage/Distress ,[object Object]
Request for Assessment ,[object Object]
However the Commissioner does have some discretion as to the manner in which an assessment is to be carried out and factors that can be taken into account in this regard are ,[object Object],[object Object],[object Object]
Rectification, Blocking, Erasure & Destruction ,[object Object]
Legitimising Direct Marketing ,[object Object],[object Object],[object Object],[object Object],[object Object]
Legitimising Direct Marketing ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],Legitimising Direct Marketing
7. Obtaining consent for Direct Marketing ,[object Object],[object Object],[object Object]
Example 2 (OPT OUT) ,[object Object]
Example 3 (OPT IN) ,[object Object]
Thank You for Listening!

Más contenido relacionado

La actualidad más candente

Privacy and Data Protection in South Africa
Privacy and Data Protection in South AfricaPrivacy and Data Protection in South Africa
Privacy and Data Protection in South Africablogzilla
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the PhilippinesShirley Ingles-Cruz
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Quotient Consulting
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal InformationFrancois Naude Jr.
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Werksmans Attorneys
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Jay Castillo
 
Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Kirk Go
 
Privacy and Protection of Personal Information law seminar
Privacy and Protection of Personal Information law seminarPrivacy and Protection of Personal Information law seminar
Privacy and Protection of Personal Information law seminarLance Michalson
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theftAmber Gupta
 
Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Werksmans Attorneys
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentationOvationsGroup
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 

La actualidad más candente (20)

Privacy and Data Protection in South Africa
Privacy and Data Protection in South AfricaPrivacy and Data Protection in South Africa
Privacy and Data Protection in South Africa
 
Data privacy act of 2012 presentation
Data privacy act of 2012 presentationData privacy act of 2012 presentation
Data privacy act of 2012 presentation
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
Data Privacy Act in the Philippines
Data Privacy Act in the PhilippinesData Privacy Act in the Philippines
Data Privacy Act in the Philippines
 
CEU DPA
CEU DPACEU DPA
CEU DPA
 
Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711Half day public-seminar_on_pdpa_2010_-_250711
Half day public-seminar_on_pdpa_2010_-_250711
 
Protection of Personal Information
Protection of Personal InformationProtection of Personal Information
Protection of Personal Information
 
Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...Put your left leg in, put your left leg out: the exclusions and exemptions of...
Put your left leg in, put your left leg out: the exclusions and exemptions of...
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
 
Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)Philippine Data Privacy Act of 2012 (RA 10173)
Philippine Data Privacy Act of 2012 (RA 10173)
 
Privacy and Protection of Personal Information law seminar
Privacy and Protection of Personal Information law seminarPrivacy and Protection of Personal Information law seminar
Privacy and Protection of Personal Information law seminar
 
Werksmans presentations on popi
Werksmans presentations on popiWerksmans presentations on popi
Werksmans presentations on popi
 
Data Privacy in India and data theft
Data Privacy in India and data theftData Privacy in India and data theft
Data Privacy in India and data theft
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
 
Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...Documents, documents and more documents - is it time to spring clean? - Ahmor...
Documents, documents and more documents - is it time to spring clean? - Ahmor...
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentation
 
FOI Executive Order (Freedom of Information)
FOI Executive Order (Freedom of Information) FOI Executive Order (Freedom of Information)
FOI Executive Order (Freedom of Information)
 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
 
POPI Seminar FINAL
POPI Seminar FINALPOPI Seminar FINAL
POPI Seminar FINAL
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 

Similar a Data Protection Act

3e - Data Protection
3e - Data Protection3e - Data Protection
3e - Data ProtectionMISY
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Edouard Nguyen
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protectionInterlogica
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiKrowdthink
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...Dr. Oliver Massmann
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018TRA - Tax Representative Alliance
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationN N
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulationFahad Ameen
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization Vishnuvarthanan Moorthy
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityEmerson Bryan
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPRAfraAlZadjali
 

Similar a Data Protection Act (20)

3e - Data Protection
3e - Data Protection3e - Data Protection
3e - Data Protection
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?
 
GDPR - The new era of data protection
GDPR - The new era of data protectionGDPR - The new era of data protection
GDPR - The new era of data protection
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
Data Protection Factsheet
Data Protection FactsheetData Protection Factsheet
Data Protection Factsheet
 
The Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech WiewiorowskiThe Privacy Advantage 2016 - Wojciech Wiewiorowski
The Privacy Advantage 2016 - Wojciech Wiewiorowski
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
"The EU General Data Protection Regulation: GDPR" - TRA Annual Meeting 2018
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
General data protection regulation
General data protection regulationGeneral data protection regulation
General data protection regulation
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Are you compliant?
Are you compliant?Are you compliant?
Are you compliant?
 
GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization  GDPR – Readiness in IT offshore organization
GDPR – Readiness in IT offshore organization
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
GDPR
GDPRGDPR
GDPR
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPR
 

Data Protection Act

  • 1.
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15.
  • 16.
  • 17.
  • 18.
  • 19. (c) disclosure of the information or data by transmission, dissemination or otherwise making available, or (d) alignment, combination, blocking, erasure or destruction of the information or data Difficult to imagine any action which is not processing
  • 20.
  • 21.
  • 22.
  • 23. Data Protection Act 1998 The Data Protection Principles
  • 24.
  • 25.
  • 26.
  • 27.
  • 28.
  • 29.
  • 30.
  • 31.
  • 32.
  • 33.
  • 34.
  • 35.
  • 36.
  • 37.
  • 38.
  • 39.
  • 40.
  • 41.
  • 42.
  • 43.
  • 44. IT IS A CRIMINAL OFFENCE TO PROCESS PERSONAL DATA WITHOUT AN APPROPRIATE ENTRY ON THE REGISTER OF DATA CONTROLLERS
  • 45. Where direct marketing is carried on by a business, the appropriate additional register entries will be either or both of the following:
  • 46.
  • 47.
  • 48.
  • 49.
  • 50.
  • 51.
  • 52.
  • 53.
  • 54.
  • 55.
  • 56.
  • 57.
  • 58.
  • 59.
  • 60.
  • 61.
  • 62.
  • 63.
  • 64. Thank You for Listening!

Notas del editor

  1. EC Directive on Privacy and Electronic Communications 2002 The EC Directive on Privacy and Electronic Communications 2002 was brought into force in the UK on 11 December 2003 under the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“the Regulations”). The Regulations set out requirements for EU Member States to introduce new laws regulating the use of: unsolicited commercial communications, which includes spam cookies location and traffic data, and publicly available directories. Those affected by the Regulations are: providers of public communications networks and services businesses operating their own web sites pure e-commerce companies. Breach of the Regulations can result in regulatory investigations, fines, civil damages actions and criminal liability. Criminal sanctions may be imposed on company directors , as well as the company. The Areas of concern for companies and entities active in the UK market are: 1. Unsolicited Communications & the Opting In The sending of unsolicited electronic commercial communications, such as email, SMS or MMS communications is prohibited under the Regulations if the recipient has not previously specifically “opted in” to receive such communications. Consent may be obtained by, for example, the ticking a box, clicking an icon during a registration process or by way of a specific email request for information. However, if there is a pre-existing customer relationship, the “opt in” requirement may be disregarded, provided that three criteria are filled: The sender has obtained contact details of the recipient in the course of sale or negotiations for the sale of a product or service to the individual. The communication is made regarding the sender’s similar products and services only. The recipient has access to a simple means of declining the use of their contact details for the purposes of sending such communications, both at the time of the initial collection of the details, and at the time of each subsequent communication. 2. Opting Out Individuals have a perpetual right to “opt out” of receiving further communications at any time. Senders of unsolicited commercial communications are under an obligation not to disguise their identity and to provide a valid contact address for the recipient to contact the sender. The process provided to do so must not be complicated. 3. Corporate Subscribers The Regulations aim to protect individuals from direct marketing and also seeks to a lesser extent corporate subscribers. Sole traders and non-limited liability partnerships fall within the definition of corporate subscribers. It is unclear whether the Regulations apply to individuals at corporate entities; it may be difficult to know whether an email address is that of an individual or a corporate subscriber. 4. Cookies The Regulations introduces controls on the use of cookies or similar devices on web sites and individuals must be: provided with clear information about the purposes of the specific information being collected; and is given the opportunity to refuse the storage of, to access to, that information. A guide for business can be found on http:// www.allaboutcookies.org / , and includes: a compliance statement template, a compliance checklist and a template to help web sites develop their statement on cookie policy. 5. Faxes There is a distinction between faxes to businesses and those to private members of the public. The Regulations give private individuals the right to opt in, and businesses the right to opt out. Contact details should be attached to each fax sent out. Unsolicited faxes may not be sent to those registered with OFCOM. 6. Telephone calls Private individuals and businesses are both given the option of opting-out. Caller details must be supplied each time a call is made; the name of the caller must be given and if the individual requests, the address of the caller of a free-phone telephone number. As with faxes, those registered with OFCOM cannot be contacted. 7. Automated calls and Dialling Machines The Regulations provide that the only permitted use of such systems is when the person called has previously notified the caller for consent to being called. The individual must be given the option of opting-out of such communications. Considerations for Business: Direct Marketing Businesses which participate in direct marketing must take into account: What activities they are undertaking and how information is obtained from customers The content of their privacy or data protection notices What information is obtained from and given to customers and potential customers via online registration forms, or arising from telephone or fax contact. Furthermore, they must consider whether the information has been fairly obtained, in accordance with the Data Protection Act 1998 . The provisions relating to the protection of personal data in the Data Protection Act have not been replaced by these Regulations, so direct marketing activities should be considered in light of both the Act and the Regulations. Whether the company are properly registered under the Data Protection Act 1998 . Whether the individuals contact details have been obtained from list renters. This is primarily a concern for unsolicited emails, and businesses must check that the individuals opted in to contact thorough such means, to prevent any unlawfulness. Checks should be made with the Mailing Preference Service, Telephone Preference Service, or Fax Preference Service, in order to establish whether the customer has registered with any of these services. The Privacy and Electronic Communications (EC Directive) Regulations 2003 are one of the sets regulations introduced to accommodate the expansion of the so called "Information Society". These Regulations are fundamental to conducting business in the online environment and with the use of telecommunications networks.
  2. Case 43/75, Defrenne v. Sabena, 1976 E.C.R. 455. Facts : the applicant brought an action before the Tribunal du travail, in Brussels for compensation for the loss she had incurred in terms of salary, allowance on termination of contract and pension in comparison with male members of the crew performing identical duties. The Belgian appeal court referred the case to the ECJ Holding : The ECJ held that the equal pay provision of Article 119 had as its aims both economic and social functions. It ruled that article 119 EC "forms part for the social objectives of the Community, which is not merely an economic union, but at the same time intended, by common action, to ensure social progress and seek constant improvement of the living and working conditions". Reasoning : the principle of equal pay for equal work would be binding not only upon member states but also, directly, upon private employers. So an individual can rely on some Treaty articles to enforce rights against another individual in the national courts. Direct and overt discrimination can be identified by the criteria set out under Article 119 of equal pay for equal work, whereas indirect and covert discrimination can be identified by reference to more explicit implementing provisions of a Community or national character. Direct forms of discrimination included discrimination that had their origins in legislative provisions or collective labour agreements that can be detected on the basis of a purely legal analysis of the situation  
  3. See handout – Implementation and Text of EU Data Protection Directive
  4. Section 1(1) DPA 1998
  5. [Section 1(1) DPA 1998] [Schedule 2 DPA 1998]
  6. NB – Names of business contacts are included in the definition
  7. [Section 2 DPA 1998] [Schedule 3 DPA 1998]
  8. [Section 1(1) DPA 1998]
  9. [Schedule 1 Part II DAP 1998]
  10. Section 7 DPA Section 10 DPA Section 11 DPA Section 12 DPA Section 13 DPA Section 14 DPA
  11. [Schedule 1 Part II Paragraph 9-12 DPA]
  12. [EEA is EU Member States plus Iceland, Liechtenstein ad Norway]
  13. Consumer Protection (Distance Selling) Regulations 2000 Information Requirements In good time prior to the conclusion of the contract the supplier shall – Provide to the consumer the following information- (i) the identity of the supplier and, where the contract requires payment in advance, the supplier’s address; (ii) a description of the main characteristics of the goods or services; (iii) the price of the goods or services including all taxes; (iv) delivery costs where appropriate; (v) the arrangement for payment, delivery or performance; (vi) the existence of a right of cancellation except in the cases referred to in regulation 13; (vii) the cost of using the means of distance communication where it is calculated other than at the basic rate; (viii) the period for which the offer or the price remains valid; and (ix) where appropriate, the minimum duration of the contract, in the case of contracts for the supply of goods or services to be performed or recurrently; Inform the consumer if he proposes, in the event of the goods or services ordered by the consumer being unavailable, to provide substitute goods or services 9as the case may be) of equivalent quality and price; and Inform the consumer that the cost of returning any substitute goods to the supplier in the event of cancellation by the consumer would be met by the supplier.
  14. NB. This right is exercisable by any living individual NB. The need for CRM systems to be compliant
  15. See Catherine Zeta Jones case (Hello Magazinne). Photographs are personal data. Data protection added as a cause of action. The Information Commissioner has to investigate every complaint.
  16. Very high risk area from a compliance point of view
  17. See British Gas example. Put a brochure in with customer bills. One person complained to Data Protection Registrar (Now Information Commissioner). Went to Data Protection Tribunal. Brochure stopped being put in with gas bill. British Gas had been relying on implied consent. British Gas was promoting third party goods and services.
  18. Note: Personal Data is the oil of the 21 st Century.