Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Summary

Summary Lecture 3 - Data protection in commercial practice

Rating
3.5
(2)
Sold
-
Pages
6
Uploaded on
27-11-2016
Written in
2016/2017

Summary of 6 pages for the course Capita Selecta Privacy and Data Protection at UVT (Lecture 3)

Institution
Module

Content preview

Data protection in commercial practice

An important distinction is made between privacy policies and data processing agreements. Privacy
policies ensure data transparency towards data subjects and are very important in practice as they
tell people what you’re going to be doing with their data. The GDPR encourages you to use average
language that actual people will understand so try to avoid jargon and be as brief as possible. Data
processing agreements are contracts that are principally concluded between controller and
processor, so in a business to business context, applying to:

I. Controller to controller agreements, where you’re transferring data from one organization to
another but each are processing data for their own purposes and means.
II. Controller to processor environment, where as a company you’re using a service provider to
process the data for your own benefit and own instructions.

In data processing agreements, a lot more work has to be done here and more attention is paid to
details.

Drafting a data protection clause

You’re going to hand over data to an external hosting (analytics) company. They will take a look at it
and hand it back over to us in order to have a better understanding of the market. A written
agreement on the how and why needs to be drafted for the processing to be done.

The learning stage makes clear not to start negotiating if you don’t have all the answers to the
questions yet. Don’t say that you have you template and start working on that already and figure out
what the issues are later on. Stop for a moment and check whether you have all the vital
information. Always ask for data and not for personal data to prevent the discussion on what
personal data is. Where is the data located, where did it come from and where it will be transferred
to? Who can access the data, who is using it right now, who will in the future, what they will be doing
with it for which purposes and how it will be stored.

In the drafting of the agreement stage there is essential information that needs to be contractually
fixed to know how the work will be organized. Clarify who is acting as a controller, whether there is a
processor, whether there is a co-controllership and where the allocations of responsibilities happen.
The security measures to protect data against breaches and incidents need to be well fixed.
Moreover, you need to implement necessary implementation instruments, such as whether a DPO
will be appointed, how they will address data breaches and which controls are implemented to
ensure that staff is appropriately trained.

The evaluating stage entails that you need to make sure that the final agreements and relevant
documents are properly documented, such as that you can find it again in case of an incident. There
need to be procedures in order to make sure that incidents can be identified, a system needs to be in
place to ensure questions that people might come across. They need to know where to find you,
otherwise they will operate on their own instincts which will not turn out positively in practice.
Finally, sanctions need to be included in case contracts are breached.

Law: the rules and what they really mean in practice

The notion of personal data as laid down in the law is very obvious, but in practice it hardly ever is
like that. It will evolve around the notion and you’ll get cases in which it is very unclear whether
something is personal data or not. For example; when trying to anonymize data, people often
remove the most obvious links and assume that it’s sufficient. They do so as then they don’t need to

Written for

Institution
Study
Module

Document information

Uploaded on
November 27, 2016
Number of pages
6
Written in
2016/2017
Type
SUMMARY

Subjects

$4.09
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Reviews from verified buyers

Showing all 2 reviews
8 year ago

8 year ago

3.5

2 reviews

5
0
4
1
3
1
2
0
1
0
Trustworthy reviews on Stuvia

All reviews are made by real Stuvia users after verified purchases.

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Safari Maastricht University
Follow You need to be logged in order to follow users or courses
Sold
89
Member since
13 year
Number of followers
72
Documents
134
Last sold
2 year ago

3.4

46 reviews

5
9
4
18
3
10
2
0
1
9

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions