Before committing to a purchase and full deployment, a prospective customer may require a trial or ‘proof of concept’ (POC) of the supplier’s technology. Although a trial will be limited in both duration and scope, many of the implementation, licensing, data processing and liability issues that apply to full deployment will also apply to a trial.
Issues to consider when negotiating a trial/POC agreement include:
- How long will the trial continue? Does the customer have an option to extend the trial?
- What is the scope of the trial? Is the trial limited to a testing or staging environment, or is the customer entitled to deploy the technology in a live, production environment?
- Will the customer provide the supplier with formal feedback during or following the trial? Will the supplier be entitled to use data from the trial and/or customer feedback for marketing purposes?
- Is the customer paying for the trial? Can the customer deduct the trial payment against the charges for a purchase of a full deployment?
- If the trial involves the use of any supplier hardware or other equipment, who is responsible for any loss or damage during the trial?
- Does the trial involve the processing of the customer’s personal data, and require data processing terms to be agreed?
29/12/20 – Prior to the announcement of the EU-UK Trade and Cooperation Agreement [1], I was having to explain to a client that it was looking increasing likely that, from 1st January 2021, transfers of personal data from organisations located in EEA countries to the UK would no longer be lawful. Read the rest of this entry »
19/11/20 – By way of background, transfers of EU citizens’ personal data to locations outside the European Economic Area (EEA) require a GDPR-permitted transfer mechanism. Read the rest of this entry »
Ok, let’s start with the basics. What is ‘special category data’?
Article 9 of the GDPR (as incorporated into UK law, and amended) (“UK GDPR”) defines special category data as:
- Personal data revealing:
- racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership.
- Data concerning:
- health
- a person’s sex life
- a person’s sexual orientation.
- Genetic data.
- Biometric data (where used for identification purposes).
In short, special category data is personal data that needs more protection because it is sensitive.
And what does ‘more protection’ mean?
It means that, in addition to ensuring that the processing is generally lawful, fair and transparent, and that it complies with all the other principles and requirements of the UK GDPR, you must comply with the following requirements:
- Prior to processing any special category data, you must not only identify and document a lawful basis under Article 6 (as required for all processing of personal data), but you must also satisfy at least one of the conditions for processing special category data listed in Article 9.
- Of the 10 conditions for processing special category data in Article 9, five require you to meet additional conditions and safeguards set out in Schedule 1 of the Data Protection Act 2018 (“Schedule 1 conditions”). For some Schedule 1 conditions you also need to put in place an ‘appropriate policy document’. The ICO has provided an appropriate policy document template.
- In practice, you may need to use the explicit consent condition for the special category data processing (Article 9(2)(a)). If so, then bear in mind that the individual’s consent must be:
- freely given
- specific, i.e. it must specify the nature of the special category data, and be separate from any other consents
- affirmative, i.e. opt-in
- unambiguous
- capable of being withdrawn at any time.
- Article 35 requires you to do a Data Protection Impact Assessment (DPIA) for any type of processing that “is likely to result in a high risk to the rights and freedoms of natural persons”. This is more likely to be the case when processing special category data.
- Article 30 requires controllers to maintain a record of processing activities. The exemption from this obligation for organisations employing fewer than 250 persons (Article 30(5)) does not apply where the processing includes special categories of data.
- Update your privacy notice with specific information about your processing of special category data.
21/09/20 – On 2 September 2020, the European Data Protection Board (EDPB) adopted ‘Guidelines 07/2020 on the concepts of controller and processor in the GDPR’. The Guidelines deal with the principles underpinning the differences between controllers and processors, and also delve into the more esoteric world of joint controllers. Read the rest of this entry »
23/07/20 – If you, as a ‘data exporter’, want to transfer personal data to a country outside the EEA (and which is not one of the 12 countries that have been granted an adequacy decision by the European Commission), then you need to use one of the GDPR-approved ‘transfer mechanisms’. Read the rest of this entry »
13/07/20 – The EU Platform to Business Regulation (the ‘P2B Regulation’) came into effect on 12 July 2020. The P2B Regulation applies to all online platforms and search engines which provide services to business users in the EU, where those business users offer goods or services to consumers in the EU. Read the rest of this entry »
Issues to consider when drafting, reviewing or negotiating service levels include:
Service levels
- Are uptime service levels measured monthly, or over a different period? (A 99.9% uptime service level measured monthly allows for a single outage of approx. 43 minutes; measured quarterly, that increases to more than two hours.)
- Are out-of-hours outages dealt with in the same way as outages during business hours?
- What types of downtime excluded from the availability calculation, e.g. planned maintenance or Force Majeure events?
- For response/resolution service levels, are different severities of fault subject to different service levels? Does a workaround constitute a resolution for the purpose of the service level?
- Do the service levels apply from Day 1, or does the supplier have a grace period to allow the service to be ‘bedded in’?
- Are there any ‘chronic’ service levels’, which if breached entitle the customer to terminate the agreement?
Service credits
- If service credits are payable for breach of service levels, are the service credits subject to a cap? If a default results in breaches of multiple service levels, can the customer claim multiple service credits?
- Does a service credit constitute the customer’s sole remedy, or is the customer able to claim against the supplier if its actual losses exceed the value of the service credit?
- How and when does the customer claim service credits?
Issues to consider when negotiating a SaaS (Software as a Service) agreement include:
- How is the customer on-boarded/integrated? What remote or physical access to the customer’s IT systems does the supplier need?
- Are there any other customer dependencies? What happens if the supplier fails to meet the installation or go-live date?
- Is there a minimum term during which the customer is unable terminate? After the end of the minimum term, does the term renew for a further fixed period, or can it then be terminated at any time? Can the customer terminate during the minimum term/renewal term, but subject to an early termination payment?
- Will the supplier be accessing, storing or otherwise processing any of the customer’s personal data? If so, have the parties agreed data processing terms?
- What IT and other security measures will the supplier maintain in relation to the customer’s data?
- What service levels apply to the services, particularly regarding availability and fault fixing times? Is the customer entitled to service credits and/or to terminate the agreement if service levels are not met?
12/03/20 – The UK government has issued a Statement in response to the Law Commission’s report on Electronic execution of documents. My article on the Law Commission’s report can be accessed here.
Key takeaways from the government’s Statement:
- The government agrees with the report’s conclusion that businesses and individuals can feel confident in using e-signatures in without the need for primary legislation.
- The government accepts the report’s recommendation that an Industry Working Group should be established to consider, in particular, the security and technology of electronic signatures.
- The Industry Working Group will also be asked to consider the question of video witnessing of electronic signatures.
- In accordance with the report’s recommendation, the government will ask the Law Commission to undertake a broader review of the law of deeds. The timing for the review will however be subject to government and Law Commission priorities given the existing volume of law reform work.