<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Sharing &#8211; DPO Centre</title>
	<atom:link href="https://www.dpocentre.ca/blog/category/data-sharing/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dpocentre.ca</link>
	<description>Empowering Compliance, Protecting Data, Ensuring Trust. - DPO Centre</description>
	<lastBuildDate>Mon, 07 Apr 2025 11:34:22 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.dpocentre.ca/wp-content/uploads/2024/07/cropped-dpo-favicon_512x512-32x32.png</url>
	<title>Data Sharing &#8211; DPO Centre</title>
	<link>https://www.dpocentre.ca</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Quebec’s Law 25: A guide to support privacy compliance</title>
		<link>https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 13 May 2024 21:26:14 +0000</pubDate>
				<category><![CDATA[Data Privacy Officer]]></category>
		<category><![CDATA[Data Sharing]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20828</guid>

					<description><![CDATA[<p>Organizations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s Law 25. This new legislation was adopted in September 2021 and has been implemented in stages, with the final stage coming into effect on September 22, 2024.&#160; Law 25 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/">Quebec’s Law 25: A guide to support privacy compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Organizations that collect, process and store the personal information of Quebec individuals must ensure their existing privacy programs are in line with the provisions of Quebec’s Law 25. This new legislation was adopted in September 2021 and has been implemented in stages, with the final stage coming into effect on September 22, 2024.&nbsp;</p>



<p>Law 25 represents a milestone for provincial privacy legislation. It marks a complete overhaul of Quebec’s privacy regime, strengthening privacy rights for individuals and updating organisational requirements.&nbsp;</p>



<p>In this guide, we provide essential information to help support your journey towards achieving and maintaining compliance. We explain which organizations Law 25 affects and detail what each stage of its provisions include.&nbsp;</p>



<h2 class="wp-block-heading">What is Quebec’s Law 25?</h2>



<p>Law 25 introduces several key concepts to modernize data protection practices in Quebec and strengthen privacy rights for individuals.</p>



<p>The legislation has been brought into effect in stages, over a three-year period, which has allowed organizations to adapt gradually to the new privacy requirements.&nbsp;By September 2024 organizations should ensure all provisions are fully implemented.&nbsp;</p>



<p>Fines for non-compliance can range between CA$15,000 and CA$25,000,000 or 4% of worldwide turnover for the previous year, whichever is greater. </p>



<figure class="wp-block-image size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="289" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1024x289.jpg" alt="Preparing for Quebecs Law 25 changes A guide for Sept 2024" class="wp-image-20829" style="width:800px" title="Quebec’s Law 25: A guide to support privacy compliance 1" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1024x289.jpg 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-300x85.jpg 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-768x217.jpg 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-1536x434.jpg 1536w, https://www.dpocentre.ca/wp-content/uploads/2024/06/Preparing-for-Quebecs-Law-25-changes-A-guide-for-Sept-2024-2048x578.jpg 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Who does Law 25 apply to?</h2>



<p>Law 25 applies to all businesses, including non-profits, operating in Quebec that collect, process, use or disclose the data of Quebec residents, regardless of size, revenue or location of the business.&nbsp;</p>



<h2 class="wp-block-heading">Quebec’s Law 25:&nbsp;A guide to support privacy compliance</h2>



<p>Law 25 imposes a range of obligations on businesses, with the aim of striking a balance between privacy protection, individual rights, and business accountability.&nbsp;</p>



<p>To ensure compliance with the new regulations, you should complete a&nbsp;<strong>gap analysis of your current privacy programs</strong>. This will identify any required updates that need to be made to policies, procedures and data handling practices.&nbsp;</p>



<p>If you are operating within the province of Quebec and process personal data, these are the important aspects you should already have in place or need to address by September 22, 2024:&nbsp;</p>



<h3 class="wp-block-heading"><strong>Appoint a Data Privacy Officer&nbsp;</strong></h3>



<p>The&nbsp;Data Privacy Officer&nbsp;role shares a similarity with the EU’s requirement for a&nbsp;Data Protection Officer (DPO).&nbsp;However, unlike the GDPR, the Privacy Officer role defaults to the highest-ranking individual in an organization, if one is not otherwise appointed.&nbsp;</p>



<p><strong>Many organizations may not be aware of the defaulting nature of the Privacy Officer role. Where a Privacy Officer is not explicitly appointed, the responsibility falls to the CEO or MD.&nbsp;</strong>&nbsp;</p>



<p><strong>What you need to do:</strong>&nbsp;It is crucial for organizations of any size or industry sector to recognize the importance of this role. A Privacy Officer should have the expertise and specialist knowledge to ensure compliance with privacy laws and understand the complexities of global data protection legislation.&nbsp;</p>



<ul class="wp-block-list">
<li>Appoint an in-house Privacy Officer or outsource to an external professional </li>
</ul>



<p>For a comparison between in-house and outsourced options, see this link to download our infographic:</p>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.dpocentre.ca/resources/in-house-dpo-vs-outsourced-dpo-infographic/">Download Infographic</a></div>
</div>



<p></p>



<p>The infographic covers these important considerations for choosing between an in-house or outsourced Privacy Officer:</p>



<ul class="wp-block-list">
<li>Speed to hire,</li>



<li>Scalability</li>



<li>Experience and expertise</li>



<li>Risk management</li>



<li>Annual investment</li>
</ul>



<h3 class="wp-block-heading"><strong>Breach reporting&nbsp;</strong>&nbsp;</h3>



<p>Organizations must ensure that breach management processes are in place. Data breaches must be reported to the&nbsp;<strong>Commission d’accès à l’information&nbsp;(CAI)</strong><strong>&nbsp;</strong>and all affected individuals as soon as possible.&nbsp;</p>



<p><strong>What you need to do:&nbsp;</strong>Create and test a data breach response protocol. When identifying a potential data breach, you must assess whether an incident poses a “risk of serious injury” based on information sensitivity, anticipated consequences and likelihood of harmful use.&nbsp;</p>



<p>Your data breach response protocol should include:&nbsp;</p>



<ul class="wp-block-list">
<li>Employee roles and responsibilities </li>



<li>Workflows </li>



<li>Template breach reporting document </li>
</ul>



<h3 class="wp-block-heading"><strong>Biometrics disclosure</strong>&nbsp;</h3>



<p>Biometric data collection includes physical features such as fingerprints, facial features and iris patterns.&nbsp;</p>



<p><strong>What you need to do:&nbsp;</strong>&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Express consent requirements</strong> – Obtain express consent from individuals and ensure it is specific to the purpose of collecting and using biometrics </li>



<li><strong>Disclosure requirements</strong> – Inform the Commission d’acc`es ““““`a l’information du Québec (CAI) of your intention to use biometric processes at least 60 days before implementing the biometric system </li>



<li><strong>Privacy by Design</strong> – Implement privacy-enhancing measures when handling biometric data and consider Privacy Impact Assessments (PIAs) to mitigate any potential harms </li>
</ul>



<h3 class="wp-block-heading"><strong>Privacy Policy</strong>&nbsp;</h3>



<p>All organizations operating in Quebec must have a comprehensive Privacy Policy that outlines data handling practices.&nbsp;</p>



<p><strong>What you need to do:&nbsp;</strong>Create a Privacy Policy to include these important details:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Purpose</strong> – Clearly state the purpose of your privacy policy and outline how your organization collects, uses, discloses and protects personal information </li>



<li><strong>Scope</strong> – Specify that the policy applies to all individuals whose data you process </li>



<li><strong>Type of information</strong> – For example names, addresses, credit card numbers </li>



<li><strong>Security measures</strong> – For example, encryption, access controls, regular audits, and employee training </li>



<li><strong>Third parties and sharing</strong> – Explain the purpose of any such sharing and ensure transparency </li>



<li><strong>Individual rights</strong> – Inform individuals of their rights and provide instructions on how they can exercise these rights </li>



<li><strong>Contact information</strong> – For inquiries, requests and complaints related to privacy, include details of the designated Data Privacy Officer </li>



<li><strong>Updates and accessibility </strong>– Commit to keeping the Privacy Policy up to date and ensure it is easily accessible and in a prominent place on your website </li>
</ul>



<h3 class="wp-block-heading"><strong>Privacy Impact Assessment (PIA)</strong>&nbsp;</h3>



<p>A PIA is a systematic process to evaluate the impact of data processing activities on individuals’ privacy rights&nbsp;</p>



<p><strong>What you need to do:</strong>&nbsp;</p>



<p>Under Law 25, organizations must conduct a Privacy Impact Assessment (PIA) for:&nbsp;</p>



<ul class="wp-block-list">
<li>High risk data processing activities (e.g., large-scale data collection, profiling, biometrics) </li>



<li>Data transfers to other provinces, third countries, or international organizations </li>



<li>Implementation of new technologies (e.g., AI, IoT, facial recognition) </li>
</ul>



<h3 class="wp-block-heading"><strong>Cross-border transfers</strong>&nbsp;</h3>



<p>These are transfers that involve moving personal data from Quebec to another jurisdiction outside Canada (or to another province).&nbsp;</p>



<p><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Inform individuals about cross-border transfers in your Privacy Policy </li>



<li>Undertake a PIA (see details in the section above) </li>



<li>Enact contractual safeguards to ensure adequate protection in the jurisdiction of transfer </li>
</ul>



<h3 class="wp-block-heading"><strong>Enhanced Consent</strong>&nbsp;</h3>



<p>Law 25 sets stricter rules for acquiring permission before using people’s personal information. Organizations must obtain explicit opt-in consent before collecting, storing, processing, and sharing personal information. Additionally, for children under 14, you will need the parent’s permission first.&nbsp;</p>



<p><strong>What you need to do:&nbsp;</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Provide comprehensive information about why and how their data will be used </li>



<li>Ensure the consent request is prominant and stands out from general terms and conditions </li>



<li>Use clear and concise language with an opt-in requirement </li>



<li>Inform individuals of their right to withdraw consent at any time </li>



<li>List any non-Quebec third parties that you are sharing the personal information with </li>



<li>Maintain documentation of how and when consent was given </li>
</ul>



<h3 class="wp-block-heading"><strong>Data minimization</strong>&nbsp;</h3>



<p>Law 25 emphasises the importance of collecting only the essential data for the intended purpose. Organizations must avoid excessive data collection and retain only relevant information.&nbsp;</p>



<p><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Clearly define the purpose for which the data will be used in your privacy policy </li>



<li>Then only collect the minimum amount of data required to achieve that purpose  </li>



<li>Define clear retention periods for different types of data </li>
</ul>



<h3 class="wp-block-heading"><strong>Subject rights</strong>&nbsp;</h3>



<p>These rights came into effect September 2023, with the right to data portability effective in September 2024 (see below section).&nbsp;</p>



<p>Subject rights include:&nbsp;</p>



<ul class="wp-block-list">
<li>Right to be informed </li>



<li>Right to access </li>



<li>Right to rectification </li>



<li>Right to erasure </li>



<li>Right to withdraw consent </li>



<li>Right to restrict processing </li>



<li>Right to data portability </li>
</ul>



<p><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Ensure individuals are informed about your data practices </li>



<li>Privacy Officers should respond promptly to any access requests, within 30 days, and provide the relevant details (with redactions, as necessary) </li>
</ul>



<h3 class="wp-block-heading"><strong>Data portability rights – comes into effect September 2024</strong>&nbsp;</h3>



<p>With this specific area of Law 25, individuals have the right to have their personal data seamlessly transitioned between service providers.&nbsp;</p>



<p>What this means is that you are obliged to provide the requested information in a specified format.&nbsp;</p>



<p><strong>What you need to do:</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>You must provide the individual’s personal data in a structured, commonly used, and machine-readable format </li>



<li>Share the requested information with any authorized person or organization </li>
</ul>



<h2 class="wp-block-heading"><strong>Summary</strong>&nbsp;</h2>



<p>The final stage of Quebec’s Law 25 comes into effect on September 22, 2024.&nbsp;</p>



<p>Organizations operating within the province of Quebec must implement the necessary operational and procedural changes by that date to ensure compliance with the new regulations.&nbsp;</p>



<p>We covered the key aspects of Law 25 in the above sections, but these are the main elements to consider:&nbsp;</p>



<ul class="wp-block-list">
<li>All organizations must have a Privacy Officer in place </li>



<li>If you don’t specify a Privacy Officer, the CEO/MD will be automatically assigned </li>



<li>Complete a Privacy Impact Assessment (PIA) for all data transfers and new technologies </li>



<li>Implement a robust breach notification protocol with workflows and reporting documents </li>
</ul>



<h2 class="wp-block-heading"><strong>The DPO Centre Canada</strong>&nbsp;</h2>



<p>From our offices in Toronto, Ontario, The DPO Centre Canada provides outsourced Canadian Privacy Officers to organizations operating across Quebec and other provinces.&nbsp;&nbsp;</p>



<p>If you would like to discuss how our range of specialist services can support your organization’s privacy governance, please contact&nbsp;<a href="https://www.dpocentre.ca/contact-us/" target="_blank" rel="noreferrer noopener"><strong>The DPO Centre Canada.</strong></a>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/quebecs-law-25-a-guide-to-support-privacy-compliance/">Quebec’s Law 25: A guide to support privacy compliance</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</title>
		<link>https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sun, 21 Jan 2024 22:23:56 +0000</pubDate>
				<category><![CDATA[Data Sharing]]></category>
		<category><![CDATA[Global data privacy laws]]></category>
		<category><![CDATA[International data transfers]]></category>
		<category><![CDATA[Policies & Documentation]]></category>
		<guid isPermaLink="false">https://dpoca.server.terryh.uk/?p=20824</guid>

					<description><![CDATA[<p>EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&#160; With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>EU and UK-based organisations regularly need to transfer personal data to different countries for a variety of reasons – project collaborations, partnerships, service providers etc.&nbsp;</p>



<p>With the increasing complexity of global privacy legislation, it is vital for organisations to have the appropriate safeguards in place for these transfers. This ensures compliance with data protection laws, mitigates the risk of a data breach, and helps to maintain the trust of customers, stakeholders, and employees.&nbsp;</p>



<p>There are several safeguarding options, depending on the nature of the data, where the individuals are located, and where the data is being sent.&nbsp;</p>



<p>In this blog, we take a look at the EU Standard Contractual Clauses (EU SCCs), the UK Addendum, and the UK International Data Transfer Agreement (IDTA), explaining the suitability of each mechanism for EU and UK personal data transfers and the factors to consider.&nbsp;</p>



<h2 class="wp-block-heading">EU&nbsp;Standard Contractual Clauses (EU&nbsp;SCCs)&nbsp;</h2>



<p>EU SCCs are one of the most commonly used data transfer mechanisms. They are popular because they have pre-approval by the European Commission and a level of assurance for compliance with the General Data Protection Regulation (GDPR).&nbsp;</p>



<p>The European Commission published new EU SCCs on 4 June 2021, allowing organisations to use these for data transfers from the European Economic Area (EEA) to third countries from 27 June 2021.&nbsp;</p>



<h2 class="wp-block-heading">UK Addendum</h2>



<p>As the UK is no longer part of the EEA, UK organisations cannot rely on the new EU SCCs. Only the old EU SCCs were valid in the UK until the Information Commissioner’s Office (ICO) introduced their own solution in the form of an Addendum, which came into force on 21 March 2022.&nbsp;</p>



<p>The UK Addendum allows organisations to use the new EU SCCs for UK personal data transfers, ensuring compliance with both EU and UK data protection laws. A helpful solution for organisations with locations across the EU and the UK.&nbsp;</p>



<p><strong>The old EU SCCs expired on 27 December 2022. Any existing UK contracts have until 21 March 2024 to transition to the new EU SCCs with UK Addendum or the IDTA.</strong>&nbsp;</p>



<h2 class="wp-block-heading">UK&nbsp;International Data Transfer Agreement (IDTA)&nbsp;</h2>



<p>The International Data Transfer Agreement (IDTA) was developed by the UK’s Information Commissioner’s Office (ICO) and has been in force since 21 March 2022. It is a legal framework for transferring personal data from the UK to countries outside the European Economic Area (EEA) not covered by adequacy decisions (these are known as UK Restricted Transfers).&nbsp;</p>



<p>The IDTA is an alternative to the EU SCCs with the UK Addendum but is only suitable for transferring personal data from the UK.&nbsp;</p>



<p>The IDTA sets out contractual obligations for both the data exporter (in the UK) and the data importer (in the third country) to protect the privacy and rights of individuals whose data is being transferred. It includes clauses on data handling, processing, security measures, and the rights of individuals.&nbsp;</p>



<h2 class="wp-block-heading">Should you use&nbsp;EU SCCs, UK IDTA or UK Addendum?&nbsp;</h2>



<p>There are fundamental questions you should ask when choosing the most appropriate data transfer mechanism for your organisation. These include understanding the type of data being transferred, the frequency and volumes, and the countries involved.&nbsp;</p>



<p>Here’s a helpful list of questions to consider and an overview of which mechanism to use for EU or UK data:&nbsp;&nbsp;</p>



<ul class="wp-block-list">
<li>Where do the individuals reside? EU, UK or both? </li>



<li>Are there any inter-company binding rules in place? If so, further mechanisms may not be required </li>



<li>Are you transferring data to an adequate country? If yes, the transfer can proceed, following the specific adequacy decision frameworks </li>



<li>Are you making a regular transfer to a non-adequate country? If yes, see EU SCCs or UK Addendum or IDTA  </li>
</ul>



<figure class="wp-block-image size-large is-resized"><img decoding="async" width="1024" height="189" src="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png" alt="SCCs IDTA UK Addendum" class="wp-image-20826" style="width:800px" title="International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA 2" srcset="https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-1024x189.png 1024w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-300x55.png 300w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum-768x142.png 768w, https://www.dpocentre.ca/wp-content/uploads/2024/06/SCCs-IDTA-UK-Addendum.png 1080w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">The DPO Centre can help with your international data transfer queries </h2>



<ul class="wp-block-list">
<li>One of the largest teams of outsourced Data Protection Officers (DPOs) available </li>



<li>GDPR EU and UK Representatives </li>



<li>Specialist Advice Line offering a rapid response to important data protection queries </li>



<li>Highly cost-effective solutions </li>
</ul>



<p>We have worked with over 800 clients globally across the spectrum of industry sectors, supporting their data protection compliance and bringing peace of mind.&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.dpocentre.ca/blog/international-data-transfers-explaining-eu-sccs-uk-addendum-and-uk-idta/">International Data Transfers: Explaining EU SCCs, UK Addendum and UK IDTA</a> appeared first on <a rel="nofollow" href="https://www.dpocentre.ca">DPO Centre</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
