<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bodle Law</title>
	<atom:link href="http://www.bodlelaw.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bodlelaw.com</link>
	<description>SaaS and the legal cloud made simple</description>
	<lastBuildDate>Mon, 14 May 2012 09:00:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Website Legal Requirements &#8211; Cookies &#8211; New Guidelines</title>
		<link>http://www.bodlelaw.com/saas/website-legal-requirements-data-protection-new-cookies-guidelines</link>
		<comments>http://www.bodlelaw.com/saas/website-legal-requirements-data-protection-new-cookies-guidelines#comments</comments>
		<pubDate>Mon, 14 May 2012 09:00:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[13 years experience]]></category>
		<category><![CDATA[26th May 2012]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[cookie audit]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[Data Commissioner]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Data Protection Act]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[footer]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[IAB]]></category>
		<category><![CDATA[ICC]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[icon]]></category>
		<category><![CDATA[information commissioner]]></category>
		<category><![CDATA[International Chamber of Commerce]]></category>
		<category><![CDATA[Internet law]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[legal requirement]]></category>
		<category><![CDATA[mandatory rules]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[pop-ups]]></category>
		<category><![CDATA[popups]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>
		<category><![CDATA[terms and conditions]]></category>
		<category><![CDATA[UK Chamber of Commerce]]></category>
		<category><![CDATA[Website]]></category>
		<category><![CDATA[website content]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2407</guid>
		<description><![CDATA[From the 26th of May 2012 the UK Information Commissioners Office (ICO) will start prosecuting companies for breaches of the Privacy and Electronic Communications (Amendment) Regulations. These set out the obligations of website operators to provide users with information about cookies and obtain their consent when using cookies. Failure to comply with the rules can result in a fine of up to £500,000.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fwebsite-legal-requirements-data-protection-new-cookies-guidelines"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fwebsite-legal-requirements-data-protection-new-cookies-guidelines&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">From the 26th of May 2012 the UK Information Commissioners Office (ICO) will start prosecuting companies for breaches of <a title="Website Legal Requirements - New Cookie Rules" href="../e-commerce/website-legal-requirements-cookies-and-consent-from-the-26th-of-may-2011" target="_blank">the Privacy and Electronic Communications (Amendment)</a> Regulations. These set out the obligations of website operators to provide users with information about cookies and obtain their consent when using cookies. Failure to comply with the rules can result in a fine of up to £500,000.</p>
<h3><strong>What is a Cookie?</strong></h3>
<p style="text-align: justify;">Cookies are small text files placed on a user’s computer which record online activity. The majority of websites use cookies to measure visits and the use of websites (analytics cookies). Cookies are often also used to save user names, passwords and user preferences to make repeated use of a website more comfortable for the user. However, increasingly cookies are being used to collect information about users for the purposes of targeted marketing.</p>
<h3><strong>The New Rules</strong></h3>
<p style="text-align: justify;">The new rules apply to the use of all cookies or similar technologies for storing information such as flash cookies, web beacons or bugs. No distinction is made between different types of cookies in the rules. They apply to both session and persistent cookies and first party and third party cookies.</p>
<h3 style="text-align: justify;">Consent</h3>
<p style="text-align: justify;">Consent must be freely given, specific and informed, unless the cookie is ‘necessary’ for the delivery of the service, for example, where the cookie takes the user from a product page to a payment page. This generally means that a user needs to “opt in” to the use of cookies.</p>
<p style="text-align: justify;">The more specific the consent is the less likely it is that you will be in breach of the rule.  For example, if you obtain consent before the cookie is set you will have specific consent. If you rely on implied consent you will need to show that the user has taken some positive action to imply consent. The UK Chamber of Commerce has provided some suggested wording for use on websites.</p>
<h3 style="text-align: justify;">Cookie Information</h3>
<p style="text-align: justify;">Clear and comprehensive information about the type of cookies being used and the purposes for which these are being set must be provided. The UK Chamber of Commerce suggests categorising cookies into 4 groups – strictly necessary, performance, functionality and targeting/ or advertising cookies.</p>
<h3><strong>Who do the Rules Apply to?</strong></h3>
<p style="text-align: justify;">The Regulations do not define who is responsible for complying with the rules so primarily it is the person/company setting the cookie. Where third party cookies are used both parties will have a responsibility for ensuring users are clearly informed about cookies and for obtaining consent.</p>
<p style="text-align: justify;">Organisations based in the UK will be subject to the rules even if their website is hosted outside of the UK. If organisations are based outside of the EU but their websites are designed or products and/or services are directed at EU customers they should provide information and choices about cookies that comply with the rules.</p>
<h3><strong>Guidance on How to Comply with the New Rules</strong></h3>
<p style="text-align: justify;">The ICO has issued non-binding guidance suggesting ways in which consent to the setting of cookies can be obtained and the International Chamber of Commerce (ICC) UK&#8217;s guidance also suggests various methods for complying with the notice requirements. A summary of these suggestions and some examples from the guides have been set out below.</p>
<ul>
<li style="text-align: justify;">Terms and Conditions: When users sign-up for using a website, consent to the use of cookies should be obtained on registration, specifically or by reference to a privacy policy, cookie policy or terms and conditions. This does not however cover the problem of obtaining consent from existing users.</li>
<li style="text-align: justify;">Banners /Footers: Where websites have cookies built into the landing page the use of cookies should be highlighted in a prominent place on the landing page i.e. via a banner &#8211; as on the ICO home page,  or in a footer or information box &#8211; as on the bt.com website.</li>
<li style="text-align: justify;">Pop-ups: Each time a cookie is to be set a pop-up will inform the user. By continuing to use the website, the user will be deemed to have consented to the cookie. However in practice, these are not a very practical solution, particularly where numerous cookies are used.</li>
<li style="text-align: justify;">Settings /Features: Where users can choose preferences when using a website for example via the use of videos that remember how users personalise their interaction, these settings/feature could be used to obtain consent.</li>
</ul>
<p style="text-align: justify;">Additionally, the Internet Advertising Bureau Europe (IAB) has developed a voluntary code using the display of an icon on a website whenever an advert tracks a users&#8217; behaviour. By clicking on the icon the user can switch off behavioural adverts. However this only apples to the adverts of companies who are members of the scheme.</p>
<h3><strong>How to Avoid Fines</strong></h3>
<p style="text-align: justify;">Despite the impending May deadline, many companies have not taken any action to amend their websites and are simply waiting to see what happens. In light of the guidance from the ICO this is not advisable.</p>
<p style="text-align: justify;">You should be carrying out a cookie audit, if you have not already done so to review the use of cookies on your website. You will need to assess what type of cookies you use, how long they are being used and remove any redundant or unnecessary cookies.</p>
<p style="text-align: justify;">Thereafter you should update the information you provide about cookies in your privacy policy or create a separate cookie policy, ensuring that this information is easy to find on your website. You need to state the type of cookies you use, why you use them and how users can opt out of you using such cookies.</p>
<p style="text-align: justify;">You also need to review the steps that you take to obtain consent to any cookies you use. How and when the consent is obtained. Is it implied, or specific. Also do not forget to provide information about any third party cookies that are placed and provide links to information about these that third parties may provide.</p>
<h3><strong>Enforcement by the ICO</strong></h3>
<p style="text-align: justify;">From 26<sup>th</sup> May 2012 you must comply with the new rules and the ICO will start taking formal action. The ICO has stated that they will be selective. For example, they have clearly indicated that they are unlikely to prosecute companies who only use analytic cookies and will concentrate on websites where no steps have been taken towards collecting consent or where particularly intrusive cookies are used.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in Internet Law and <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">SaaS</a> Agreements with over 10 years experience in the IT sector. If you require assistance with any Internet Law, SaaS, <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">ASP</a>, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong>Other related articles:</strong></span></p>
<ul>
<li><a title="Cookies and Consent" href="http://www.bodlelaw.com/e-commerce/websites-legal-requirements-%E2%80%93-cookies-and-consent" target="_blank">Website &#8211; Legal Requirements &#8211; Cookies and Consent</a></li>
<li><a title="Cookies and Consent Policies" href="http://www.bodlelaw.com/it-law/website-legal-requirements-cookies-and-consent-policies" target="_blank">Website &#8211; Legal Requirements &#8211; Cookies and Consent Policies</a></li>
<li><a title="Web Site - Legal Healthcheck" href="../e-commerce/web-site-legal-healthcheck" target="_blank">Website &#8211; Legal Requirements</a></li>
<li><a title="Ecommerce rules" href="http://www.bodlelaw.com/e-commerce/websites-legal-requirements-ecommerce-rules">Website &#8211; Legal Requirements &#8211; Ecommerce Rules</a></li>
<li><a title="Website Legal Requirements - New ASA Code" href="http://www.bodlelaw.com/e-commerce/websites-legal-requirements-asa-rules-apply-to-websites-from-1st-march-2011" target="_blank">Website &#8211; Legal Requirements &#8211; New ASA Rules</a></li>
<li><a title="Contact and Company Information" href="../e-commerce/website-legal-requirements-contact-information" target="_blank">Website &#8211; Legal Requirements &#8211; Contact and Company Information</a></li>
<li><a title="Google Adwords - Trade Mark Infringement" href="../trademarks/google-adwords-trademark-infringement" target="_blank">Google Adwords &amp; Trademark Infringement</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="Data Commissioner Fines" href="../saas/saas-agreements-data-protection-information-commissioner-imposes-first-fines-in-the-uk" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner Issues First Fines in UK</a></li>
<li><a title="SaaS Agreement - Distributor or Agent?" href="../saas/saas-agreement-distributor-or-agent" target="_blank">SaaS Agreements &#8211; Distributor or Agent &#8211; Is There a Difference?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">Cloud Computing and the Legal Cloud</a></li>
</ul>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/website-legal-requirements-data-protection-new-cookies-guidelines/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Data Protection &#8211; The UK Patriot Act</title>
		<link>http://www.bodlelaw.com/saas/2376</link>
		<comments>http://www.bodlelaw.com/saas/2376#comments</comments>
		<pubDate>Mon, 30 Apr 2012 09:00:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[anti-terrorism law]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[disclosure request]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[EU citizen]]></category>
		<category><![CDATA[EU data protection]]></category>
		<category><![CDATA[hosting in US]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[MLAT]]></category>
		<category><![CDATA[Patriot Act]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS template]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>
		<category><![CDATA[UK Patriot Act]]></category>
		<category><![CDATA[US authorities]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2376</guid>
		<description><![CDATA[Recently SaaS suppliers have seen a marked increase in EU customers raising concerns about disclosure of their data to US law enforcement authorities under the Patriot Act - an American anti-terrorism law - particularly where the SaaS supplier has a parent company in the USA or data is being hosted or processed in the USA.  Now to add to your problems, the UK Government plans to introduce its own "Patriot Act" type law in the near future.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2F2376"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2F2376&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">Recently <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">SaaS</a> suppliers have seen a marked increase in EU customers raising concerns about disclosure of their data to US law enforcement authorities under the <a href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act">Patriot Act</a> &#8211; an American anti-terrorism law &#8211; particularly where the SaaS supplier has a parent company in the USA or data is being hosted or processed in the USA.  Now to add to your problems, the UK Government plans to introduce its own &#8220;Patriot Act&#8221; type law in the near future.</p>
<h3><strong>Proposed Increase in E-Mail and Web Monitoring  in the UK<br />
</strong></h3>
<p style="text-align: justify;">According to the BBC and Guardian websites, a controversial new English law is expected to be announced in the Queen’s speech on the 9<sup>th</sup> of May. The proposed new law will allow the UK police and <a href="http://www.bodlelaw.com/slas/saas-agreements-sla-security-issues">security</a> services to access the Web and Internet phone traffic of all UK residents. This will include access to all phone calls (made via the Internet), emails, social media exchanges and website visits.</p>
<h3>Information that may be Disclosed</h3>
<p>The proposals will grant UK police and security services the right to see:</p>
<ul>
<li>the time of a call, email, or website visit;</li>
<li>the duration of the call or visit;</li>
<li>which websites or phone numbers were called; and</li>
<li>details of the sender and recipient of emails, such as IP addresses;</li>
</ul>
<p>without any need for first obtaining a court warrant.</p>
<p>If a warrant is obtained, then the content of such messages will also be disclosed upon request.</p>
<h3>Justifications for the New Law</h3>
<p style="text-align: justify;">The proposed legislation will loosen the existing surveillance arrangements set out in the Regulation of Investigatory Powers Act. The Government claims these new rights are needed to give the police and security services extended powers to enable them to investigate serious crime and terrorism. The same argument used in the USA prior to the introduction of the Patriot Act. The new law will in effect give the UK police and security services rights very similar to those granted to US authorities under the Patriot Act.</p>
<h3>Problem for SaaS Suppliers</h3>
<p style="text-align: justify;">If this proposed new law is adopted, UK based SaaS suppliers will face increased difficulties in:</p>
<ul>
<li>persuading customers to move across from more traditional suppliers to the SaaS model; and</li>
<li>allying customer concerns about the security and confidentiality of data.</li>
</ul>
<p style="text-align: justify;">Previous problems raised by SaaS customers over the application of the Patriot Act will fade into insignificance in comparison with these new UK rights.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">ASP</a>, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<strong><span style="color: #800000;"> www.bodlelaw.com</span></strong></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><strong><span style="color: #800000;">______________________________________________________</span></strong></p>
<p><strong><span style="color: #800000;">Other related articles:</span></strong></p>
<ul>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Patriot Act  - Renewed Customer Concerns" href="http://www.bodlelaw.com/saas/saas-agreements-return-of-patriot-act-concerns" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Renewed Customer Concerns About the Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="FAQs - Hosting" href="http://www.bodlelaw.com/slas/saas-agreements-faqs-hosting" target="_blank">SaaS Agreements &#8211; FAQs &#8211; Hosting</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="Software on Demand" href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused" target="_blank">SaaS Agreements &#8211; SaaS, Software on Demand, Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements &#8211; Cloud Computing and the Legal Cloud</a></li>
<li><a title="Cloud based Technologies and Services" href="http://www.bodlelaw.com/saas/cloud-based-software-cloud-based-technologies-cloud-based-services" target="_blank">SaaS Agreements &#8211; Cloud based Technology and Services</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/2376/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Patriot Act &#8211; Renewed Customer Concerns</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-return-of-patriot-act-concerns</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-return-of-patriot-act-concerns#comments</comments>
		<pubDate>Mon, 16 Apr 2012 09:00:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[13 years experience]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[anti-terrorism law]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[disclosure request]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[EU citizen]]></category>
		<category><![CDATA[EU data protection]]></category>
		<category><![CDATA[hosting in US]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[MLAT]]></category>
		<category><![CDATA[Patriot Act]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS template]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>
		<category><![CDATA[US authorities]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2328</guid>
		<description><![CDATA[Recently SaaS suppliers have seen a marked increase in EU customers raising concerns about disclosure of their data to US law enforcement authorities under the Patriot Act - an American anti-terrorism law - particularly where the SaaS supplier has a parent company in the USA or data is being hosted or processed in the USA.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-return-of-patriot-act-concerns"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-return-of-patriot-act-concerns&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">Recently <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">SaaS</a> suppliers have seen a marked increase in EU customers raising concerns about disclosure of their data to US law enforcement authorities under the <a href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act">Patriot Act</a> &#8211; an American anti-terrorism law &#8211; particularly where the SaaS supplier has a parent company in the USA or data is being hosted or processed in the USA.</p>
<h3><strong>High Profile Cases</strong></h3>
<p style="text-align: justify;">Microsoft recently admitted that United States law enforcement authorities can access their European customer data without having to obtain a court order, ask for consent or even inform data subjects of the disclosure under the terms of the Patriot Act. To add to SaaS suppliers worries it is believed that BAE recently withdrew from contract negations for a Microsoft SaaS product due to fears that defence secrets could be accessed by the US authorities under the Act.</p>
<p style="text-align: justify;">The recent publication of the new proposed EU <a href="http://www.bodlelaw.com/saas/data-protection">data protection</a> regulation has also added to customer fears that data is not safe from disclosure under the Patriot Act. The new regulation attempts to counter the application of the US Patriot Act by stating that non-EU companies will have to comply with EU data protection rules when accessing EU citizen data.</p>
<h3><strong>The Patriot Act v European Data Protection Laws</strong></h3>
<p>The provisions of the Patriot Act conflict directly with English and EU data protection laws.</p>
<p style="text-align: justify;">The Patriot Act gives US law enforcement authorities the right to access personal data held by SaaS suppliers, regardless of where in the world the data is stored. The Act also gives US law enforcers the right to prevent SaaS suppliers from informing their customers that they have had to hand over their personal data.</p>
<p style="text-align: justify;">Data protection laws in the 27 countries of the EU all prohibit the disclosure of personal data without a data subject’s consent or knowledge.</p>
<p style="text-align: justify;">Therefore if a EU company is faced with a Patriot Act disclosure request it is impossible to comply with both the US law and the EU company’s local data protection laws. In practice the US law usually prevails. Some of the largest global software and search engine companies have admitted that EU customer data has already been disclosed by them as a consequence of requests under the Patriot Act.</p>
<h3><strong>The Cloud is not the Problem</strong></h3>
<p style="text-align: justify;">SaaS customers often falsely believe that their data is not safe from disclosure due to the cross-border nature of <a href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud">cloud computing</a>. However this problem applies to all data whether or not it is stored or processed in a SaaS model. Most countries (the UK, France, Spain and Belgium to name a few) have laws similar to the Patriot Act that <strong>all, </strong>not just SaaS suppliers must comply with i.e. in the UK the Regulation of Investigatory Powers Act 2000 (RIPA) requires disclosure of the content of communications to police forces.</p>
<p style="text-align: justify;">Also data stored or processed anywhere outside of the <a href="http://www.bodlelaw.com/saas/transfer-of-personal-data-outside-of-the-eu">EEA</a>, in a country which does not have equivalent protection will be subject to all local disclosure laws i.e. in China and India, and such local laws may be less restrictive than the Patriot Act with regard to the type of data that must be disclosed.</p>
<p style="text-align: justify;">In any event, regardless of whether or not the Patriot Act applies to customer data, the US authorities can access customer data even when it is hosted outside of the USA and there is no company presence in the USA under Mutual Assistance Legal Treaties (MLAT)</p>
<h3><strong>Assessing the Actual Risk of Disclosure</strong></h3>
<p>SaaS customer concerns about the Patriot Act are valid but these must be considered in light of:</p>
<ul>
<li>The type of data covered by a request for disclosure under the Patriot Act;</li>
<li>The likelihood of the customer data ever being requested; and</li>
<li style="text-align: justify;">The fact that customer data is already subject to similar disclosure obligations to the UK government and foreign governments under other existing laws.</li>
</ul>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, <a href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused">ASP</a>, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><span style="color: #000000;"><strong>To register for my newsletter<span style="color: #3366ff;"> <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank"><span style="color: #3366ff;">click here</span></a></span></strong></span></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;">Other related articles:</span></p>
<ul>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Patriot Act - Renewed Customer Concerns" href="http://www.bodlelaw.com/saas/saas-agreements-return-of-patriot-act-concerns" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Renewed Customer Concerns about the Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="FAQs - Hosting" href="http://www.bodlelaw.com/slas/saas-agreements-faqs-hosting" target="_blank">SaaS Agreements &#8211; FAQs &#8211; Hosting</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="Software on Demand" href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused" target="_blank">SaaS Agreements &#8211; SaaS, Software on Demand, Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements &#8211; Cloud Computing and the Legal Cloud</a></li>
<li><a title="Cloud based Technologies and Services" href="http://www.bodlelaw.com/saas/cloud-based-software-cloud-based-technologies-cloud-based-services" target="_blank">SaaS Agreements &#8211; Cloud based Technology and Services</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-return-of-patriot-act-concerns/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; FAQs &#8211; Hosting</title>
		<link>http://www.bodlelaw.com/slas/saas-agreements-faqs-hosting</link>
		<comments>http://www.bodlelaw.com/slas/saas-agreements-faqs-hosting#comments</comments>
		<pubDate>Mon, 02 Apr 2012 08:30:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SAAS]]></category>
		<category><![CDATA[SLAs]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[data centre]]></category>
		<category><![CDATA[dedicated hosting]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[hosting agreement]]></category>
		<category><![CDATA[hosting provider]]></category>
		<category><![CDATA[hosting services]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[physical location]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS template]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[service level agreement]]></category>
		<category><![CDATA[shared hosting]]></category>
		<category><![CDATA[SLA]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2296</guid>
		<description><![CDATA[Under the terms of your SaaS agreement you will be storing, processing and publishing customer content and data on the Internet using servers located and operated at the data centre of a third party. The third party operating the servers is known as a hosting provider. The hosting services are provided from a data centre owned and operated by the hosting provider.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fslas%2Fsaas-agreements-faqs-hosting"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fslas%2Fsaas-agreements-faqs-hosting&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">When negotiating a <a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS agreement</a> you may come across the term hosting. What is hosting and is a hosting agreement necessary?</p>
<h3><strong>SaaS and Hosting</strong></h3>
<p style="text-align: justify;">Under the terms of your SaaS agreement you will be storing, processing and publishing customer content and data on the Internet using servers located and operated at the data centre of a third party. The third party operating the servers is known as a hosting provider. The hosting services are provided from a data centre owned and operated by the hosting provider.</p>
<p style="text-align: justify;">Usually the hosting provider owns and maintains the servers in the data centre, however increasingly it is becoming more common for SaaS suppliers to rent “space” in a data centre and then store and maintain their own servers there.</p>
<p style="text-align: justify;">The type, scope and specific nature of the hosting services to be supplied by the hosting provider will be set out in a hosting agreement.</p>
<h3><strong>Hosting Agreement</strong></h3>
<p>The hosting agreement specifies:</p>
<ul>
<li style="text-align: justify;">the scope, type and nature of the hosting services being provided to the SaaS supplier; and</li>
<li style="text-align: justify;">the terms on which the SaaS software, content and customer data will be stored on behalf of the SaaS supplier.</li>
</ul>
<p style="text-align: justify;">The agreement is entered into between the SaaS supplier and the hosting provider.</p>
<p style="text-align: justify;">As the customer has no agreement with the hosting provider it is essential that the relevant terms of the hosting agreement are reflected in the service level agreement (<a title="SLAs - Essential Elements" href="http://www.bodlelaw.com/slas/slas" target="_blank">SLA</a>) between the SaaS supplier and the customer, as hosting problems could have a critical impact on the customer’s business.</p>
<h3><strong>Negotiating a Hosting Agreement</strong></h3>
<p style="text-align: justify;">Hosting providers are usually large telecoms or Internet service providers (ISPs). They use standard terms and conditions which are usually non-negotiable and very favourable to them. However, depending upon your bargaining power it may be possible to individually negotiate some terms of the hosting agreement for example, <a title="SLAs - Service Credits" href="http://www.bodlelaw.com/slas/saas-agreements-sla-service-credits" target="_blank">service credits</a>, availability, liability and exclusions.</p>
<h3><strong>Dedicated or Shared Services</strong></h3>
<p style="text-align: justify;">Depending on the price paid for the hosting services and the industry sector in which your customers operate, you may need “dedicated” rather than “shared” hosting services. Dedicated hosting services involve the storage of each individual customer’s website and content on a single server. If you decide to use a shared hosting option the content and websites of multiple customers will be stored on the same server.</p>
<p style="text-align: justify;">Most SaaS suppliers use shared servers, where this is acceptable to customers, as hosting on dedicated servers is more expensive.</p>
<h3><strong>Location of the Data Centre</strong></h3>
<p style="text-align: justify;">The physical location of the data centre used by your hosting provider is very important to SaaS customers. Due to ever increasing and evolving <a title="SLAs - Security" href="http://www.bodlelaw.com/slas/security" target="_blank">security </a>and <a href="http://www.bodlelaw.com/saas/data-protection">data protection</a> laws, rules and guidelines, it is essential that you consider:</p>
<ul>
<li>the needs and requirements of your customers;</li>
<li>your long term business expansion plans;</li>
<li><a title="FAQs - Data Protection" href="http://www.bodlelaw.com/saas/data-protection" target="_blank">relevant data protection laws</a>; and</li>
<li>the physical location of your customers;</li>
</ul>
<p>when selecting your hosting provider.</p>
<p style="text-align: justify;">If you decide to use a hosting provider with servers located outside of the UK for a UK government customer, even if the hosting provider itself is located within the UK you will encounter serious issues. Conversely, if you decide to use a hosting provider with servers located in the UK for a German customer, you will also encounter problems.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><strong><span style="color: #800000;">______________________________________________________</span></strong></p>
<p><strong><span style="color: #800000;">Other related articles:</span></strong></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="Software on Demand" href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused" target="_blank">SaaS Agreements &#8211; SaaS, Software on Demand, Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements &#8211; Cloud Computing and the Legal Cloud</a></li>
<li><a title="Cloud based Technologies and Services" href="http://www.bodlelaw.com/saas/cloud-based-software-cloud-based-technologies-cloud-based-services" target="_blank">SaaS Agreements &#8211; Cloud based Technology and Services</a></li>
<li><a title="SaaS Agreements - Jurisdiction - Info made Available on Internet" href="http://www.bodlelaw.com/saas/saas-agreements-jurisidiction-infromation-made-available-on-internet" target="_blank">SaaS Agreements &#8211; Jurisdiction &#8211; Info made Available on Internet</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/slas/saas-agreements-faqs-hosting/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; SaaS, PaaS, IaaS &#8211; Is There a Difference?</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-saas-paas-iaas-is-there-a-difference</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-saas-paas-iaas-is-there-a-difference#comments</comments>
		<pubDate>Thu, 22 Mar 2012 09:30:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[hardware as a service]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[HRM]]></category>
		<category><![CDATA[IaaS]]></category>
		<category><![CDATA[infrastructure as a service]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[PaaS]]></category>
		<category><![CDATA[platform as a service]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS template]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>
		<category><![CDATA[talent management]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2291</guid>
		<description><![CDATA[Cloud computing services comprise of – Platform as a Service (PaaS), Infrastructure as a Service (IaaS) and Software as a Service (SaaS). These terms are commonly used to describe the different levels and combinations of services which are together commonly referred to as “cloud computing”.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-saas-paas-iaas-is-there-a-difference"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-saas-paas-iaas-is-there-a-difference&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;"><a href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud">Cloud computing</a> services comprise of – Platform as a Service (PaaS), Infrastructure as a Service (IaaS) and Software as a Service (<a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS</a>). These terms are commonly used to describe the different levels and combinations of services which are together commonly referred to as “<a title="What is Cloud Computing" href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud" target="_blank">cloud computing</a>”.</p>
<h3><strong>SaaS – Software as a Service</strong></h3>
<p>Sometimes referred to as “<a title="Software on Demand" href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused" target="_blank">software on-demand</a>”, SaaS is a software delivery model in which software and data are hosted centrally and accessed using a web browser via the Internet.</p>
<p>Examples of common SaaS applications are:</p>
<ul>
<li>email accounts such as Hotmail or Google;</li>
<li>CRM (customer relationship management) systems such as Salesforce;</li>
<li><a title="HRM" href="http://www.bodlelaw.com/?s=human+resource" target="_blank">HCM</a> (human capital management or talent management) systems.</li>
</ul>
<p>Important features of SaaS are that:</p>
<ul>
<li>customer data can be added to the software application;</li>
<li>the software application can be accessed without the need to use additional hardware or software;</li>
<li>data and the software application are hosted centrally.</li>
</ul>
<h3><strong>PaaS – Platform as a Service</strong></h3>
<p style="text-align: justify;">PaaS provides developers with a platform to write and create their own SaaS application.  PaaS provides developers with the necessary tools to create, test, host and maintain the applications they have created. This alleviates the need for developers to buy and maintain the underlying hardware, software and hosting facilities for their SaaS applications.</p>
<p>The most well known PaaS is Facebook.</p>
<p style="text-align: justify;">Within the classic layered structure of cloud computing PaaS forms the middle layer sitting between between SaaS at the top and IaaS at the bottom.</p>
<p>Important features of PaaS are:</p>
<ul>
<li>application hosting, development, testing and deployment environment;</li>
<li>other integrated services such as database integration, <a href="http://www.bodlelaw.com/slas/saas-agreements-sla-security-issues">security</a> and storage.</li>
</ul>
<h3><strong>IaaS – Infrastructure as a Service</strong></h3>
<p style="text-align: justify;">Sometimes referred to as “hardware as a service”, IaaS is an outsourcing model under which users rent equipment accessed via the Internet to <a href="http://www.bodlelaw.com/slas/saas-agreement-%E2%80%93-sla-maintenance-and-support-requirements">support</a> their operations.</p>
<p style="text-align: justify;">One of the most well known forms of IaaS is Amazon.com, which provides the computing power behind many major online services, for example Foursquare.</p>
<p style="text-align: justify;">The IaaS supplier owns all equipment and is responsible for housing, running and maintaining the equipment. The user simply pays a usage rental fee for accessing the outsourced services via the Internet.</p>
<h3><strong>Summary</strong></h3>
<p style="text-align: justify;">SaaS is a software distribution model in which a third party hosts and makes software applications available to end users via the Internet. PaaS is a framework for delivering operating systems and associated services via the Internet, which does not involve any software downloads or installation. IaaS is a form of equipment outsourcing via the Internet used to support a company’s operations.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><strong><span style="color: #800000;">______________________________________________________</span></strong></p>
<p><strong><span style="color: #800000;">Other related articles:</span></strong></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="Software on Demand" href="http://www.bodlelaw.com/slas/saas-asp-software-on-demand-confused" target="_blank">SaaS Agreements &#8211; SaaS, Software on Demand, Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="http://www.bodlelaw.com/saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements &#8211; Cloud Computing and the Legal Cloud</a></li>
<li><a title="Cloud based Technologies and Services" href="http://www.bodlelaw.com/saas/cloud-based-software-cloud-based-technologies-cloud-based-services" target="_blank">SaaS Agreements &#8211; Cloud based Technology and Services</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SaaS Agreements - Jurisdiction - Info made Available on Internet" href="http://www.bodlelaw.com/saas/saas-agreements-jurisidiction-infromation-made-available-on-internet" target="_blank">SaaS Agreements &#8211; Jurisdiction &#8211; Info made Available on Internet</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-saas-paas-iaas-is-there-a-difference/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Data Protection &#8211; New Proposed EU Rules &#8211; Part 2</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-2</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-2#comments</comments>
		<pubDate>Mon, 12 Mar 2012 09:30:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[copy of data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection officer]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[EU data protection]]></category>
		<category><![CDATA[EU regulation]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[proposed new regulation]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2267</guid>
		<description><![CDATA[On the 25th of January 2012 the European Commission published a proposal for a new Data Protection Regulation to replace the existing EU Data Protection Directive. The proposal sets out a general data protection framework aimed at unifying the current differing data protection rules in the EU. Following on from my first article - part 1, I have summarised the remainder of the major changes this will make to EU data protection law below.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-data-protection-new-proposed-eu-rules-part-2"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-data-protection-new-proposed-eu-rules-part-2&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">On the 25<sup>th</sup> of January 2012 the European Commission published a proposal for a <a title="New Proposed EU Data Protection Regulation 25.01.2012" href="http://http://www.ec.europa.eu/justice/data-protection/document/review2012/com_2012_11_en.pdf" target="_blank">new Data Protection Regulation</a> to replace the <a title="current Data Protection Directive " href="http://www.http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:en:HTML" target="_blank">existing EU Data Protection Directive</a>. The proposal sets out a general data protection framework aimed at unifying the current differing data protection rules in the EU. Following on from my first article &#8211; part 1, I have summarised the remainder of the major changes this will make to EU data protection law below and how this will effect <a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS </a>suppliers and customers.</p>
<h3><strong>Data Protection Officer</strong></h3>
<p style="text-align: justify;">An independent data protection officer must be appointed by public authorities and businesses with 250 or more employees or businesses whose core activities involve processing operations which require regular and systematic monitoring. The data protection officer must maintain an internal register which the DPA has the right to inspect.</p>
<h3><strong>Data Controller                                                                                              </strong></h3>
<p>Stricter express duties will be imposed on <a title="Data Controller" href="http://www.bodlelaw.com/saas/data-protection" target="_blank">data controllers</a>. For example they must:</p>
<ul>
<li>maintain documents regarding all processing;</li>
<li>implement specific <a href="http://www.bodlelaw.com/slas/saas-agreements-sla-security-issues">data security</a> requirements;</li>
<li>perform data processing impact assessments; and</li>
<li>obtain prior authorisation for certain processing activities.</li>
</ul>
<h3><strong>Data Processor</strong></h3>
<p>The obligations and duties of <a title="Data Processor" href="http://www.bodlelaw.com/saas/data-protection" target="_blank">data processors</a> will be more specifically defined. For example they should:</p>
<ul>
<li>only employ staff who have given confidentiality undertakings or commitments;</li>
<li>obtain the permission of the data controller before employing a sub-processor;</li>
<li>ensure that security measures are implemented; and</li>
<li>maintain documentation of all processing operations.</li>
</ul>
<h3><strong>Consent</strong></h3>
<p style="text-align: justify;">Explicit consent must be obtained from <a title="Data Subjects" href="http://www.bodlelaw.com/saas/data-protection" target="_blank">data subjects</a> by SaaS customers. It will not be acceptable for customers to assume consent from a data subject’s silence or inactivity or through generic terms and conditions. Consent must be given by a data subject in a clear statement or via an affirmative action (i.e. ticking a consent box when visiting a website). The data subject must have the right to withdraw consent at any time.</p>
<p style="text-align: justify;">There is an additional requirement that explicit parental consent must be given when processing the data of a child under the age of 13.</p>
<h3><strong>Right to be Forgotten</strong></h3>
<p style="text-align: justify;">Data subjects will have the right to be forgotten. This will allow individuals to have all personal data that a SaaS supplier holds on them deleted. This will include all photos and any public links to, or copies of, personal data that can be found on the Internet, for example in social networks or via search engines.  SaaS suppliers will be required to permanently delete the individual’s data unless there are legitimate grounds for retaining it.</p>
<h3><strong>Right to Copy of Personal Data</strong></h3>
<p style="text-align: justify;">In certain circumstances individuals will be able to obtain a copy of their personal data. They will also have the right to have their data transferred automatically between SaaS suppliers, for example from one social network to another. This means that SaaS suppliers will need to implement data exporting tools to enable users to download their data and move it to another provider.</p>
<h3><strong>When will the Rules Change</strong></h3>
<p style="text-align: justify;">The draft Regulation must be approved by all EU countries and the European Parliament before it comes into effect, probably in about 3 years time. The rules will introduce significant and onerous new obligations upon SaaS suppliers, who will need to implement time consuming measures to ensure compliance, in order to avoid the risks of facing substantial fines.</p>
<h3><strong>Preparing for Change</strong></h3>
<p style="text-align: justify;">Although the proposals could be substantially amended before they are approved, it is advisable that businesses start to prepare for the proposed changes now. For example by appointing a data protection officer (where appropriate), devising a documentation system for recording data processing activities, reviewing how consent is obtained from data subjects and revising all data processing agreements.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong>Other related articles:</strong></span></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Data Stored in the USA" href="http://www.bodlelaw.com/saas/saas-data-protection-data-stored-in-the-usa" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Stored in the USA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Safe Harbor Issues with German Customers" href="../saas/data-protection-german-saas-problems-if-using-a-us-data-centre" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Safe Harbor, German Customers</a></li>
<li><a title="Google Analytics in Germany" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-google-analytics-in-germany" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Google Analytics in Germany</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
<li><a title="SaaS Agreement - Distributor or Agent?" href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent" target="_blank">SaaS Agreements &#8211; Distributor or Agent &#8211; Is There a Difference?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">Cloud Computing and the Legal Cloud</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Data Protection &#8211; New Proposed EU Rules &#8211; Part 1</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-1</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-1#comments</comments>
		<pubDate>Fri, 02 Mar 2012 09:30:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[copy of data]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection authority]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[data protection officer]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[EU data protection]]></category>
		<category><![CDATA[EU regulation]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[IT lawyer]]></category>
		<category><![CDATA[lawyer Berlin]]></category>
		<category><![CDATA[lawyer Germany]]></category>
		<category><![CDATA[lead authority]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[penalties for breach]]></category>
		<category><![CDATA[proposed new regulation]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SaaS UK]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2261</guid>
		<description><![CDATA[On the 25th of January 2012 the European Commission published a proposal for a new Data Protection Regulation to replace the existing EU Data Protection Directive. The proposal sets out a general data protection framework aimed at unifying the current differing data protection rules in the EU.  I have summarised the major changes this will make to EU data protection law in two articles, part 1 of which is set out below.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-data-protection-new-proposed-eu-rules-part-1"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-data-protection-new-proposed-eu-rules-part-1&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">On the 25<sup>th</sup> of January 2012 the European Commission published a proposal for a <a title="New Proposed EU Data Protection Regulation 25.01.2012" href="http://http://www.ec.europa.eu/justice/data-protection/document/review2012/com_2012_11_en.pdf" target="_blank">new Data Protection Regulation</a> to replace the <a title="current Data Protection Directive " href="http://www.http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:31995L0046:en:HTML" target="_blank">existing EU Data Protection Directive</a>. The proposal sets out a general data protection framework aimed at unifying the current differing data protection rules in the EU.  I have summarised the major changes this will make to EU data protection law in two articles, part 1 of which is set out below and how this will effect <a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SAAS </a>suppliers and customers.<strong></strong></p>
<p style="text-align: justify;"><strong> Data Protection Authority</strong></p>
<p style="text-align: justify;">Currently each EU country has its own data protection agency which enforces that country’s law. Processing of personal data by businesses established in more than one EU country will in the future be monitored by one single data processing authority (DPA) – the “lead authority”. Generally the lead authority will be the DPA of the country where the business has its main establishment.</p>
<p style="text-align: justify;">The main establishment of a business will be determined according to objective criteria, such as where the central administration of a business is located i.e. the headquarters where management decisions are usually made. However, individuals located in other EU countries, will still be able to refer privacy complaints to their local supervisory DPA.</p>
<h3><strong>One EU-wide Data Protection Law </strong></h3>
<p style="text-align: justify;">If the Regulation is adopted, there will be one EU data protection law that SaaS suppliers will need to comply with. The new rules will apply throughout the EU and SaaS suppliers established in more than one EU country will no longer need to cope with the national rules of each relevant EU country. In the long term this means that current local data protection provisions – mainly exemptions that have been introduced by EU countries for national reasons – would disappear.</p>
<h3><strong>Non-EU Companies</strong></h3>
<p style="text-align: justify;">The new data protection rules will also apply to non-EU based businesses who offer their goods or services to EU customers based in the EU (or who monitor their behaviour). For example a US company with a subsidiary in the EU will be required to comply with the new EU data protection law as well as their own local US laws.</p>
<p style="text-align: justify;">There are exceptions where the data controller (SaaS customer) is established in a country outside the <a title="EEA" href="http://www.bodlelaw.com/saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">EEA</a> that ensures an adequate level of protection (for example a business registered under the <a title="Safe Harbor" href="http://www.bodlelaw.com/saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">Safe Harbor</a> scheme in the USA), or if the data controller acts for a small or medium sized business or public authority.</p>
<h3><strong>Penalties for Breaches  </strong></h3>
<p style="text-align: justify;">A breach of the new data protection rules could result in a fine of up to €1 million or 2% of the global annual turnover of a company. Fines will be imposed by the DPA. Currently the maximum fine in the UK for a breach of data protection law is £500,000.</p>
<h3><strong>Notification </strong></h3>
<p style="text-align: justify;">Serious data protection breaches must be notified to both the DPA and data subjects, although it is not clear whether the lead authority or the company itself will be obliged to inform the public of data protection breaches.</p>
<p style="text-align: justify;">Notification should be without undue delay and, where feasible, within 24 hours. Companies will need to have adequate procedures in place to deal with these new requirements and it may be worth considering purchasing obtaining cyber risk insurance.</p>
<h3><strong>When will the Rules Change</strong></h3>
<p style="text-align: justify;">The draft Regulation must be approved by all EU countries and the European Parliament before it comes into effect, possibly in about 3 years time. The rules will introduce significant and onerous new obligations upon SaaS suppliers and customers, who will need to implement time consuming measures to ensure compliance, in order to avoid the risks of facing substantial fines.</p>
<h3><strong>Preparing for Change</strong></h3>
<p style="text-align: justify;">Although the proposals could be substantially amended before they are approved, it is advisable that SaaS suppliers and customers start to prepare for the proposed changes. For example, by devising a documentation system for recording data processing activities, reviewing how consent is obtained from data subjects and revising all data processing agreements.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong>Other related articles:</strong></span></p>
<ul>
<li><a title="Data Protection - New Proposed Rules Part 2" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-2" target="_blank">SaaS Agreements &#8211; Data Protection -New Proposed Rules Part 2</a></li>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Data Stored in the USA" href="http://www.bodlelaw.com/saas/saas-data-protection-data-stored-in-the-usa" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Stored in the USA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Google Analytics in Germany" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-google-analytics-in-germany" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Google Analytics in Germany</a></li>
<li><a title="Safe Harbor Issues with German Customers" href="../saas/data-protection-german-saas-problems-if-using-a-us-data-centre" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Safe Harbor, German Customers</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreemnt</a></li>
<li><a title="SaaS Agreement - Distributor or Agent?" href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent" target="_blank">SaaS Agreements &#8211; Distributor or Agent &#8211; Is There a Difference?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">Cloud Computing and the Legal Cloud</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-1/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Liability &#8211; Online Comments</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-liability-online-comments</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-liability-online-comments#comments</comments>
		<pubDate>Sun, 19 Feb 2012 10:00:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[defamation]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[liability for online comment]]></category>
		<category><![CDATA[online comments]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SAS institute and world programming]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software functionality]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2232</guid>
		<description><![CDATA[New proposed UK defamation laws recommend that web hosts (SaaS suppliers) and ISPs should be allowed to keep allegedly defamatory comments online, as long as the author of the comment is identified and a notice of complaint is published next to the comment.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-liability-online-comments"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-liability-online-comments&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">New proposed UK defamation laws recommend that web hosts (<a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS</a> suppliers) and ISPs (internet service providers) should be allowed to keep allegedly defamatory comments online, as long as the author of the comment is identified and a notice of complaint is published next to the comment.</p>
<h3>Current Law and Liability</h3>
<p style="text-align: justify;">Currently web hosts and ISPs must immediately remove online comments upon gaining actual knowledge that the comments are defamatory. Failure to remove defamatory comments exposes the web host/ISP to a claim for damages for defamation. Actual knowledge is deemed to occur once the web host/ISP is informed that the comments are defamatory or the web host/ISP moderates comments on the website.</p>
<p style="text-align: justify;">Under the E-Commerce Regulations SaaS suppliers are usually exempt from liability for defamation if they merely act as conduit or cache or host material, provided that they:</p>
<ul>
<li>do not initiate the transmission of defamatory comments;</li>
<li>do not select who receives the comments; or</li>
<li>do not select or modify information in the transmission of the comments.</li>
</ul>
<h3 style="text-align: justify;">New Proposed Rules</h3>
<p>Currently most web hosts/ISPs do not moderate comments or content on websites in order to take advantage of the exclusion set out above. Thus they avoid having “actual knowledge” of any defamatory comments on websites that they host.</p>
<p style="text-align: justify;">The proposed change to defamation laws aims to incentivize web hosts and ISPs to moderate comments and/or content. SaaS suppliers should comply with the rules set out below taking into account the new distinction between anonymous and identified author comments.</p>
<h3>Anonymous Comments</h3>
<p style="text-align: justify;">Upon receipt of a complaint a SaaS supplier should immediately taken down anonymous comments unless;</p>
<ul>
<li>the SaaS supplier believes that it is in the public interest for the material to remain on the website i.e. whistle blowing; or</li>
<li>the author promptly responds positively to a request to identify themselves, then a notice of complaint should be posted.</li>
</ul>
<h3 style="text-align: justify;">Identified Author Comments</h3>
<p style="text-align: justify;">Upon receipt of a complaint a SaaS supplier should;</p>
<ul>
<li>publish a complaint notice beside the comment; and</li>
<li>then have a judge decide whether or not the comment should be removed.</li>
</ul>
<h3 style="text-align: justify;">Avoiding Liability</h3>
<p style="text-align: justify;">If a SaaS supplier complies with the above rules they should not be liable for online comments. However, if the SaaS supplier fails to comply with the above, they could be sued as publisher of the content or comment along with the anonymous author – who may not be identifiable.</p>
<p style="text-align: justify;">Regardless of whether or not the proposed changes are implemented, SaaS suppliers should always include a clause in their <a href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements">SaaS agreement</a> permitting them to remove content from customer websites they are hosting in order to enable them to minimise the risks of being pursued for a defamation claim.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong title="SaaS Agreement - <a href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent">Distributor</a> or <a href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent">Agent</a>?">Other related articles:</strong></span></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SaaS Agreements - Jurisdiction - Info made Available on Internet" href="http://www.bodlelaw.com/saas/saas-agreements-jurisidiction-infromation-made-available-on-internet" target="_blank">SaaS Agreements &#8211; Jurisdiction &#8211; Info made Available on Internet</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Safe Harbor Issues with German Customers" href="../saas/data-protection-german-saas-problems-if-using-a-us-data-centre" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Safe Harbor, German Customers</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-liability-online-comments/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements &#8211; Software &#8211; Copyright Protection</title>
		<link>http://www.bodlelaw.com/saas/saas-agreements-software-copyright-protection</link>
		<comments>http://www.bodlelaw.com/saas/saas-agreements-software-copyright-protection#comments</comments>
		<pubDate>Fri, 10 Feb 2012 10:00:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IPR]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[breach of copyright]]></category>
		<category><![CDATA[computer programme]]></category>
		<category><![CDATA[copyright]]></category>
		<category><![CDATA[English lawyer]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS contract]]></category>
		<category><![CDATA[SaaS expert]]></category>
		<category><![CDATA[SaaS legal expert]]></category>
		<category><![CDATA[SAS institute and world programming]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[software functionality]]></category>
		<category><![CDATA[software on demand]]></category>
		<category><![CDATA[software subscription]]></category>
		<category><![CDATA[subscription agreement]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2223</guid>
		<description><![CDATA[The Advocate General ruled that the functionalities of software are simply “the service which the user expects” from the computer programme. For example, when using software to book an airline ticket the functionalities of the booking process will be the same regardless of which company’s software you use. Such services cannot be protected by copyright. However, what can be protected by copyright, is the means by which the functionalities are achieved as this reflects the author’s own intellectual creation. Protection will depend upon the degree of originality in the writing of the software.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-software-copyright-protection"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-agreements-software-copyright-protection&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;"><a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS</a> Software with the same functionality can co-exist without there being an infringement of copyright, following the recent opinion of the Advocate General in SAS Institute and World Programming Ltd. The Advocate General advised that it is the methods used to create the means for the software to carry out its functions, not the functions of the software and the programming language which can be protected by copyright.</p>
<h3 style="text-align: justify;">What is Copyright?</h3>
<p style="text-align: justify;">Copyright is the right to stop others from copying works without permission. Copyright in SaaS software derives from the software being an original literary work. Copyright protects the expressions of ideas in the SaaS software NOT the ideas themselves.</p>
<h3 style="text-align: justify;">SAS Institute and World Programming Ltd</h3>
<p style="text-align: justify;">The High court referred this case to the European Court of Justice (ECJ). World Programming Ltd was accused of infringing copyrights in SAS Institute software as a result of using information contained in the SAS Institute manuals (not the <a href="http://www.bodlelaw.com/saas/source-code-and-object-code">source code</a>) to develop rival software. SAS Institute argued that the functions of its software were copyright protected pursuant to the Computer Programs Directive. This Directive protects copyright in the expression in any form of a computer programme. It does not however cover ideas and principles which underlie any element of a computer programme, including those which underlie a computer programme interfaces.</p>
<h3 style="text-align: justify;">Are Software Functionalities Protected by Copyright?</h3>
<p style="text-align: justify;">The Advocate General ruled that the functionalities of software are simply “the service which the user expects” from the computer programme. For example, when using software to book an airline ticket the functionalities of the booking process will be the same regardless of which company’s software you use. Such services cannot be protected by copyright. However, what can be protected by copyright, is the means by which the functionalities are achieved as this reflects the author’s own intellectual creation. Protection will depend upon the degree of originality in the writing of the software.</p>
<p style="text-align: justify;">This is not the end of the matter, as the ECJ still has to make a ruling on this case. However the ECJ usually follows the opinion of the Advocate General. In which case, the ability of SaaS software suppliers to prevent the functionality of their software being replicated in the future will be limited, if it is not the SaaS software source code that is replicated.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong title="<a href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements">SaaS Agreement</a> - <a href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent">Distributor</a> or <a href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent">Agent</a>?">Other related articles:</strong></span></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="SaaS Agreements - Jurisdiction - Info made Available on Internet" href="http://www.bodlelaw.com/saas/saas-agreements-jurisidiction-infromation-made-available-on-internet" target="_blank">SaaS Agreements &#8211; Jurisdiction &#8211; Info made Available on Internet</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Safe Harbor Issues with German Customers" href="../saas/data-protection-german-saas-problems-if-using-a-us-data-centre" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Safe Harbor, German Customers</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-agreements-software-copyright-protection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SaaS Agreements – Data Protection – Data Stored in the USA</title>
		<link>http://www.bodlelaw.com/saas/saas-data-protection-data-stored-in-the-usa</link>
		<comments>http://www.bodlelaw.com/saas/saas-data-protection-data-stored-in-the-usa#comments</comments>
		<pubDate>Wed, 01 Feb 2012 09:50:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[SAAS]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Bodle Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[ECPA]]></category>
		<category><![CDATA[Electronic Communications Privacy Act]]></category>
		<category><![CDATA[emails]]></category>
		<category><![CDATA[Irene Bodle]]></category>
		<category><![CDATA[SaaS agreement]]></category>
		<category><![CDATA[SaaS supplier]]></category>
		<category><![CDATA[software as a service]]></category>
		<category><![CDATA[subscription agreement]]></category>
		<category><![CDATA[Suzlon Energy Ltd]]></category>
		<category><![CDATA[US citizens]]></category>

		<guid isPermaLink="false">http://www.bodlelaw.com/?p=2208</guid>
		<description><![CDATA[SaaS suppliers who use data centres physically located in the USA to store or process data should be aware of a recent US Court of Appeals ruling that the Electronic Communications Privacy Act (ECPA) - an American law - protects the data of non-USA citizens when their data is stored on servers in the USA.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-data-protection-data-stored-in-the-usa"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.bodlelaw.com%2Fsaas%2Fsaas-data-protection-data-stored-in-the-usa&amp;source=bodlelawcom&amp;style=compact&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;"><a title="SaaS Agreements - Essential Elements" href="http://www.bodlelaw.com/slas/saas-asp-agreements-essential-elements" target="_blank">SaaS</a> suppliers who use data centres physically located in the USA to store or process data should be aware of a recent US Court of Appeals ruling that the Electronic Communications Privacy Act (ECPA) &#8211; an American law &#8211; protects the data of non-USA citizens when their data is stored on servers in the USA.</p>
<h3>Suzlon Energy Ltd</h3>
<p style="text-align: justify;">A Korean firm, Suzlon Energy Ltd, applied for a court order for Microsoft to disclose email documents belonging to an Indian citizen which were stored on a server used by Microsoft which was located in the USA. Suzlon argued that the emails should be disclosed as part of a litigation process because the privacy protections of the ECPA only applied to the data of US citizens.</p>
<p style="text-align: justify;">The US court determined that the ECPA covered “any person” and not just a US citizen. Part of the reason for this was the impracticality of expecting Microsoft to assess whether or not its account holders were US citizens, when receiving a disclosure request. The court decided that the ECPA applied to any data stored in the USA, regardless of the citizenship of the owner of the data.</p>
<h3>Increased Protection for EU Customer Data?</h3>
<p style="text-align: justify;">Following this decision any SaaS customer data stored in the USA will be protected by the provisions of the ECPA, regardless of the citizenship of the data owner and must not be disclosed as part of a US litigation process. This decision may help to alleviate some of the concerns being raised by SaaS customers in Europe about the inadequacy of <a href="http://www.bodlelaw.com/saas/data-protection">data protection</a> provisions in the USA. However, if the server on which the SaaS customer’s data is stored is physically located outside of the USA the data will not be protected by the ECPA.</p>
<p style="text-align: justify;">On a practical level, SaaS suppliers will need to know exactly where each customer’s data is geographically stored in order to correctly respond to disclosure requests and to determine whether or not such a request can be rejected under the provisions of the ECPA.</p>
<h3>Help</h3>
<p style="text-align: justify;">Irene Bodle is an IT lawyer specialising in SaaS agreements with over 10 years experience in the IT sector. If you require assistance with any SaaS, ASP, software on demand contracts or any other IT legal issues contact me:</p>
<p><strong>irene.bodle@bodlelaw.com</strong><br />
<span style="color: #800000;"> <strong>www.bodlelaw.com</strong></span></p>
<p><strong>To register for my newsletter <a title="subscribe to my newsletter" href="../subscribe-4" target="_blank">click here</a></strong></p>
<p><span style="color: #800000;"><strong>______________________________________________________</strong></span></p>
<p><span style="color: #800000;"><strong>Other related articles:</strong></span></p>
<ul>
<li><a title="SAAS, ASP Agreements - Essential Elements" href="../slas/saas-asp-agreements-essential-elements" target="_blank">SaaS Agreements – Essential Elements</a></li>
<li><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank">SaaS Agreements – Essential Elements</a><a title="SLAs Explained - Essential Elements" href="../slas/slas" target="_blank"> &#8211; SLAs Explained</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Security" href="../slas/security" target="_blank">SaaS Agreements – FAQs – Security</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Software Licence" href="../category/saas/software-licence-saas" target="_blank">SaaS Agreements – FAQs – Software Licence</a></li>
<li><a title="sourcehttp://www.bodlelaw.com/saas/source-code-and-object-code " href="../saas/source-code-and-object-code" target="_blank">SaaS Agreements – FAQs – Source Code and Object Code</a></li>
<li><a title="SaaS, ASP Agreements - FAQs - Escrow" href="../category/saas/escrow-saas" target="_blank">SaaS Agreements – FAQs – Escrow</a></li>
<li><a title="SaaS, ASP Agreement - FAQs - Confidential Information" href="../saas/confidential-information" target="_blank">SaaS Agreements – FAQs – Confidential Information</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection Issues" href="../saas/data-protection" target="_blank">SaaS Agreements – FAQs – Data Protection</a></li>
<li><a title="Data Protection - New Proposed Rules Part 2" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-2" target="_blank">SaaS Agreements &#8211; Data Protection -New Proposed EU Rules Part 2</a></li>
<li><a title="Data Protection - New Proposed EU Rules Part 1" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-new-proposed-eu-rules-part-1" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; New Proposed EU Rules Part 1</a></li>
<li><a title="Google Analytics in Germany" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-google-analytics-in-germany" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Google Analytics in Germany</a></li>
<li><a title="SaaS Agreements - Data Protection - The Patriot Act" href="http://www.bodlelaw.com/saas/saas-agreements-data-protection-patriot-act" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; The Patriot Act</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Data Commissioner &#8211; UK Fines</a></li>
<li><a title="SaaS, ASP Agreements - Data Protection - Subcontractors and Model Clauses" href="../saas/saas-asp-agreements-sub-contractors-data-protection-and-model-clauses" target="_blank">SaaS Agreements &#8211; Data Protection -  Sub-Contractors,  Model Clauses</a></li>
<li><a title="Liability for Loss of Backup Tapes" href="../saas/saas-agreements-%E2%80%93-data-protection-%E2%80%93-liability-for-loss-of-backup-tapes" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Liability for Loss of Backup Tapes</a></li>
<li><a title="Safe Harbor Issues with German Customers" href="../saas/data-protection-german-saas-problems-if-using-a-us-data-centre" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Safe Harbor, German Customers</a></li>
<li><a title="Data Transfer Outside of EEA" href="../saas/transfer-of-personal-data-outside-of-the-eu" target="_blank">SaaS Agreements &#8211; Data Protection &#8211; Transfer of Data Outside the EEA</a></li>
<li><a title="Need for an NDA prior to signing a SaaS Agreement" href="../saas/saas-agreements-%E2%80%93-contract-negotiations-need-for-an-nda-prior-to-signing-a-saas-agreement" target="_blank">SaaS Agreements &#8211; Need for an NDA Prior to Signing a SaaS Agreement</a></li>
<li><a title="SaaS Agreement - Distributor or Agent?" href="http://www.bodlelaw.com/saas/saas-agreement-distributor-or-agent" target="_blank">SaaS Agreements &#8211; Distributor or Agent &#8211; Is There a Difference?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">SaaS Agreements, Software on Demand – Confused?</a></li>
<li><a title="Cloud Computing and the Legal Cloud" href="../saas/cloud-computing-and-the-legal-cloud" target="_blank">Cloud Computing and the Legal Cloud</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.bodlelaw.com/saas/saas-data-protection-data-stored-in-the-usa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

