Monthly Archives: November 2017

UK Government endorses new data security standards and greater patient control over use of health data

The Department of Health published its Review of Data Security, Consent and Opt-Outs (the “Review”) earlier this year. Incidents such as WannaCry (refer to article above for more detail) have created awareness of the ease and speed with which cyber-attacks … Continue reading

Leave a Comment

Filed under Cyber Security, Data Protection, GDPR, National privacy law

Draft Data Protection Bill published – no major surprises for businesses

Following its Second Reading in the House of Lords, on 22 November 2017 the draft Data Protection Bill (the “Bill”) passed the Committee Stage and will next be considered at the Report Stage on 11 December 2017. The Bill was … Continue reading

Leave a Comment

Filed under Data Protection, GDPR, National privacy law

The GDPR: Practical European Guidance on personal data breach notification requirements

The GDPR introduces a new mandatory requirement for all controllers to notify the appropriate data protection authority of a “personal data breach” likely to result in a risk to people’s rights and freedoms, for example following a cyber-attack. This will … Continue reading

Leave a Comment

Filed under Controllers, Data breach, Data Protection, Data subject rights, GDPR

The GDPR: ICO issues draft guidance on data controller and processor liability

In the run up to the GDPR applying from next year, there has been a variety of practical guidance for compliance at the European level through the Article 29 Working Party (“WP29”) (which reflects the consolidated view of national supervisory … Continue reading

Leave a Comment

Filed under Controllers, Data Protection, GDPR, Processors

Morrisons – the first successful class action in the UK for data breach

On 1 December 2017, the High Court handed down its judgment on the UK’s first class action arising from a data breach (Various Claimants v Morrisons). The High Court allowed the claim and deemed Morrisons to be vicariously liable for … Continue reading

Leave a Comment

Filed under Data breach, Data Protection, Enforcement