Data Protection - Services
Data Protection Home Page
Data Protection Services
Data Protection Team more>>
Data Protection Registration Form more>>
Data Protection Team Published Articles more>>
Data Protection Full Article List

Articles

Register here for regular Data Protection updates

020 7203 5291
Charles Russell
8-10 New Fetter Lane
London
EC4A 1RS

Data Protection Services

Data Protection Audits
Website Audits
Employment Advice
General Data Protection Advice

Data Protection Audits:
We have extensive experience of carrying out data protection audits and preparing the necessary reports. We carry out audits by interviewing the local database managers for each type of data processing to establish current working practices of the business being audited. This usually involves briefings with the IT manager, a member from personnel/human resources, a member of staff familiar with customer databases (or membership subscriptions) and associated matters, and a member of staff dealing with direct marketing (including campaigning and fund raising, if appropriate). Our principal fee earners carry out a review of a small sample of the data records identified as typical of the business databases. This small scale review identifies the key data protection issues that each type of database raises and highlights whether additional analysis is required. Reviews normally survey the data handling procedures adopted by the business’s personnel/human resources department, to include any standard forms used for applications, references, appraisals and other employment related matters.

Our standard audit practice and reports normally include a detailed list of recommendations for changes to existing practice. We are therefore able to incorporate all our recommendations, subject to the comments of the relevant business data controllers, into standard operating procedures. Where requested, we undertake training of key client personnel in data protection issues, tailoring the training to the individual client requirements.

Website Audits
Many UK-based websites. An initial study has concluded that 75% of UK-based websites are not data protection compliant. The Information Commissioner is becoming more interested in websites as website operators increasingly use them to provide online goods and services, with the gathering of necessary and sometimes excessive personal data and in summer 2006, following its first enforcement action against a website operator for breach of the data protection legislation, announced it would be investigating other websites to ensure compliance.
As a result, Charles Russell provides a fixed fee website data protection audit service, with a lower level of fixed fee for simple information-only websites than for e-commerce sites selling goods and/or providing services. In either case, the fixed fee covers a review of a website and report by letter on its compliance with UK data protection laws, including suggested steps to make the site compliant. The fee does not cover the redrafting of any website terms and conditions of use or privacy statements to make these data protection compliant.

Employment Advice
We have extensive experience in providing employment law services to human resources clients, which incorporate data protection advice in so far as it relates to employers' handling of employees records and personal data, and the drafting of employment law policies tailored to clients' requirements. In particular, we are able to provide assistance with employers in the preparation of email and workplace monitoring policies and procedures.

General Data Protection Advice
We provide general assistance to clients and our colleagues within the firm whenever data protection issues are involved. For example, whenever our corporate or commercial colleagues are instructed in transactions involving mergers and acquisitions, outsourcing agreements or other transfer of undertakings, we will provide data protection advice on the transfer of personal data and data protection due diligence of target undertakings. As Charles Russell has a particular emphasis on IT/telecommunications and charities sectors, we are often called upon to advise on particular issues affecting these clients such as data retention and email marketing issues telecommunications clients and the handling of sensitive personal data by charities clients.