SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Contracts and compliance with GDPR requirements

  Quote
Guest
Guest user Created:   Mar 16, 2018 Last commented:   Mar 16, 2018

Contracts and compliance with GDPR requirements

1) Contracts are part of our business and we need to understand what to do with current active contracts. What will be the practical steps to bring contracts into compliance with GDPR requirements? Do we need to include data protection clauses into all contracts (including employment contracts with residents and non-residents of EU)? In which cases we may not include such clauses (if possible)?
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Mar 16, 2018

2) Do we need to obtain consents from impacted personnel of third parties (e.g., we concluding contract with consulting firm or non-EU financial institution)?

Answers:

1. When acting as a controller or example for the processing of personal of your employees you would need to inform them about the processing activities . You can do that by using a “Privacy Notice” which is aimed at explaining to the employees the Employee Privacy Notice can be delivered to the new employees when sign the labor agreement. The employees do not have to agree with the content of Notice but just have to acknowledge it. For existing employees you can chose to post the Notice on your internet and inform them that they can access it at any time. We are currently working on an Employee Privacy Notice that should be with you sometime next week.

Regarding your contracts with your that process data on your behalf you will need to have in place a Supplier Data Processing Agreement which you can find in folder 7. Third Party Compliance in our EU GDPR Documentation Toolkit.

If you want to find out more about the impact of EU GDPR on your HR activities you can check out our article “How the GDPR could impact your HR department” - https://advisera.com/eugdpracademy/blog/2018/02/22/how-the-gdpr-could-impact-your-hr-department

2. If you are transferring personal data outside the EEA is not necessarily to have the consent of the data subject. You need, however, to notify him/her about the cross border data transfer. If you transfer data outside the EEA just make sure that you use the Standard Contractual Clauses you find in folder 6. Personal data transfers.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 16, 2018

Mar 16, 2018

Suggested Topics

Guest user Created:   Feb 07, 2020 EU GDPR
Replies: 1
0 0

Questions regarding GDPR

Guest user Created:   Apr 07, 2018 EU GDPR
Replies: 1
0 0

Databases compliant with the GDPR

Guest user Created:   Aug 06, 2023 EU GDPR
Replies: 1
0 0

Do we need VPN to comply with GDPR?