Search

How can we help?

Privacy and Data Protection

Privacy documentation

 

The right privacy documentation demonstrates a commitment to information protection, building trust and confidence in your organisation and earning the loyalty of those you work with – whether customers, clients or staff.  

Our team can provide a full suite of data protection documentation including privacy statements, cookie use policies, internal policies and procedures, data sharing and processing agreements. 

“Very professional, knowledgeable and accessible lawyers.” 

Chambers and Partners

FAQs – Privacy Documents

This is any document containing data privacy information. It can range from privacy statements and cookie use policies, to internal policies and procedures that your employees will have to comply with to meet their data protection obligations.

There are various documents, however we have listed the main documents below:

  1. Data Protection Policy
  2. Privacy Notice
  3. Employee Privacy Notice
  4. Data Retention Policy
  5. Data Retention Schedule
  6. Data Subject Consent Form
  7. DPIA Register
  8. Supplier Data Processing Agreement
  9. Data Breach Response and Notification Procedure/Policy

There are certain steps and documentation needed to demonstrate compliance. These include, but are not limited to:

  • Testing and auditing data protection measures
  • Implementing technical measures to ensure compliance
  • Documenting and recording compliance measures
  • Determining and documenting a lawful basis for each instance of personal data processing
  1. Lawfulness, fairness and transparency in processing of personal data
  2. Collecting personal data for specified, explicit and legitimate purposes
  3. Accuracy in holding personal data and keeping it up to date
  4. Processing in a manner that ensures appropriate security of the personal data

Article 30 of the UK GDPR imposes documentation requirements on controllers and processors, which includes the purposes of processing personal data; the categories of individuals whose personal data is being processed; the name of any third countries or international organisations that you transfer personal data to; and a general description of your organisation’s technical and organisational security measures to protect the personal data.

Key contacts

Read, listen and watch our latest insights

art
  • 30 December 2022
  • Privacy and Data Protection

UK Data Protection: Development round-up 2022 and 2023 trends

We review the key developments of 2022 and what you should look out for in the New Year.

art
  • 30 November 2022
  • Privacy and Data Protection

Clarkslegal act for a multi-national company on an International Data Transfer Agreement

We recently acted for the UK arm of a multi-national company in connection with the transfer of personal data to an HR services-provider based in the United States. 

Pub
  • 23 November 2022
  • Privacy and Data Protection

Latest developments in UK data protection and cybersecurity

The UK data protection landscape has been everchanging particularly since the Government’s announcement to reform its data protection legislation following Brexit through the Data Protection and Digital Information Bill, and the updated process on international data transfers.

art
  • 14 November 2022
  • Privacy and Data Protection

ICO takes action for failure to protect personal data

This week the Information Commissioner’s Office (ICO) handed Interserve a £4.4 million fine for failing to put appropriate measures in place to prevent unauthorised access of private data.

Pub
  • 04 November 2022
  • Privacy and Data Protection

The seriousness of non-compliance with DSARs

In this podcast Melanie Pimenta and Sana Nahas members of the Data Protection team at Clarkslegal discuss some of the issues surrounding non-compliance with subject access requests, commonly known as “DSARs”.

art
  • 02 November 2022
  • Privacy and Data Protection

Breaches of personal data – notification under UK GDPR

The European Data Protection Board has opened a public consultation in relation to one of its guidelines on personal data breach notification under the GDPR.