SaaS Agreements – GDPR – EU-US Privacy Shield now Invalid

On the 16th of July 2020 the EU-US Privacy Shield was ruled invalid with immediate effect by the European Court of (“CJEU”). The steps that SaaS suppliers now need to take depend on the scale and type of international data flows and the transfer mechanisms used. If you rely solely upon the EU-US Privacy Shield for transfers to the US, you must replace the Privacy Shield with the EU Commission’s Standard Contractual Clauses (“SCCs”).

Continue reading

SaaS Agreements – Brexit – Transition Period

Brexit has now taken place and the UK has left the EU. However until the end of the transition period the UK is still treated as being part of the EU to enable an EU trade deal to be negotiated. This means that although SaaS suppliers and SaaS customers can continue to lawfully process and transfer personal data between the EU and the UK until the expiry of the transition period on the 31st of December 2020, SaaS suppliers and SaaS customers still need to take action now to amend existing documents to reflect that fact that the UK is no longer part of the EU.

Continue reading

SaaS Agreements – Brexit – Need for an EU Representative

A “no deal Brexit” is looking likely for the 31st of October 2019. SaaS suppliers and SaaS customers need to take steps now to ensure that they comply with the requirement to appoint an EU Representative under the GDPR, where they will no longer have any establishment in the EU after Brexit.

Continue reading

SaaS Agreements – FAQs – Data Processor

It is important for a SaaS supplier to understand the legal obligations imposed upon them as a data processor when negotiating a SaaS agreement and a data processing agreement (“DPA“) as the duties of a data processor are not the same as the duties of a data controller. In a

Continue reading

SaaS Agreements – FAQs – Personal Data

It is essential for SaaS providers and SaaS customers to understand what consitutes personal data to ensure that they comply with their respective legal obligations when acting as data controllers and/or data processors. What is Personal Data? Articles 4(1) of the General Data Protection Regulation (“GDPR“) defines personal data as:

Continue reading

SaaS Agreements – GDPR – Personal Data Breaches and How to Avoid them

Recently there have been a number of high profile cases involving the UK’s data protection authority (the “ICO”), imposing very large fines on Marriott and British Airways for serious data breaches. SaaS customers and SaaS suppliers should be reviewing the appropriateness of their technical and organisational measures to avoid the

Continue reading

SaaS Agreements – Preparing for a No Deal Brexit

Currently a “no deal Brexit” is looking likely for the 31st of October 2019. It is therefore essential that SaaS suppliers and SaaS customers take steps now to ensure that they can continue to lawfully process and transfer personal data between the EU and the UK following a no deal Brexit.

Continue reading

SaaS Agreements – Data Protection – Brexit Update

UK SaaS Agreements: In light of the various leaving scenarios of which a “no deal Brexit” is looking likely, it is highly advisable that SaaS suppliers and SaaS customers now take steps to ensure that they can continue to lawfully process and transfer personal data between the EU and the UK following Brexit.

Continue reading

SaaS Agreements – Brexit – Prepare Now

As a SaaS Supplier or SaaS customer you will be aware that the UK plans to leave the EU on the 29th of March 2019 – Brexit. In light of the various leaving scenarios currently being discussed of which a “no deal Brexit” is looking likely, it is essentail that SaaS suppliers and SaaS customers take steps now to ensure that they can continue to lawfully process and transfer personal data between the EU and the UK following Brexit.

Continue reading

SaaS Agreements – GDPR – Local Derogations

The General Data Protection Regulation (“GDPR”) now applies to all SaaS customers and SaaS companies collecting or processing the personal data of individuals located within the EU. SaaS suppliers and SaaS customers must comply with the terms the GDPR. SaaS suppliers and SaaS customers should be aware that the GDPR does not however fully harmonise data protection law throughout the EU, as each EU country may introduce their own requirements in certain instances (“derogations”) under their own local data protection laws.

Continue reading
Bodle Law