SaaS Agreements – Data Protection – TalkTalk Fine

SaaS customers and SaaS Suppliers should be aware that in October 2016 the Information Commissioner’s Office (ICO) issued a £400,000 fine against TalkTalk for serious breaches of the Data Protection Act 1998 (DPA). The fine was issued in relation to the hacking of personal data stored in a database that was accessible via the Internet.

Continue reading

SaaS Agreements – Hosting – Encryption of Stored Data

Under the Data Protection Act (DPA), SaaS customers are required to take “appropriate technical and organisational measures” to prevent the unauthorised or unlawful processing of personal data and accidental loss or destruction of, or damage to, personal data. SaaS providers who process personal data on behalf of SaaS customers are required to include such obligations in their SaaS agreement (or SLA).

Continue reading
Bodle Law