{"id":4020,"date":"2022-04-05T16:34:09","date_gmt":"2022-04-05T14:34:09","guid":{"rendered":"https:\/\/foyen.dev.kodeks.no\/?post_type=expertise&#038;p=4020"},"modified":"2022-04-25T08:13:33","modified_gmt":"2022-04-25T06:13:33","slug":"privacy-and-cyber-security","status":"publish","type":"expertise","link":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/","title":{"rendered":"Privacy and cyber security"},"content":{"rendered":"\n\n<section class=\"expertise-header  blue\">\n\n    <div class=\"grid cg-0 padding\">\n\n        <div class=\"grid-2 grid-s-1 grid-m-1 cg-0\">\n\n            <div class=\"grid rg-30 left ass\">\n                <div class=\"breadcrumb grid as col ac cg-10\">\n                    <a href=\"\">Expertise<\/a>\n\n                    <span class=\"arrow grid ac\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"38.511\" height=\"18.499\" viewBox=\"0 0 38.511 18.499\">\n                            <path id=\"Path_151\" data-name=\"Path 151\" d=\"M253.974,221.04h-3.652v.977l7.122,6.892h-33.7v2.759h33.7l-7.12,6.893v.977h3.652s7.429-6.77,8.276-7.87h0v-2.76C261.4,227.81,253.974,221.04,253.974,221.04Z\" transform=\"translate(-223.739 -221.04)\" fill=\"#010101\" \/>\n                        <\/svg><\/span>\n\n                    <span class=\"title\">Privacy and cyber security<\/span>\n\n                <\/div>\n                <div class=\"img-wrapper\">\n                    <img loading=\"lazy\" decoding=\"async\" width=\"887\" height=\"710\" src=\"https:\/\/foyen.no\/wp-content\/uploads\/m-10.png\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"\" srcset=\"https:\/\/foyen.no\/wp-content\/uploads\/m-10.png 887w, https:\/\/foyen.no\/wp-content\/uploads\/m-10-720x576.png 720w, https:\/\/foyen.no\/wp-content\/uploads\/m-10-768x615.png 768w, https:\/\/foyen.no\/wp-content\/uploads\/m-10-534x427.png 534w, https:\/\/foyen.no\/wp-content\/uploads\/m-10-339x271.png 339w, https:\/\/foyen.no\/wp-content\/uploads\/m-10-445x356.png 445w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/>                <\/div>\n                <h1>Privacy and cyber security<\/h1>\n                <p>Data protection encompasses the individual\u2019s right to privacy and the right to protection of personal data. In a digitalized world, all businesses process personal data, and the applicable laws and regulations are both wide and complicated. Both large and small businesses are affected and must carry out their activities in compliance with the laws and regulations, and we know how. Due to constant updates and developments from case law and practice from European and national authorities, privacy law is also difficult to approach and get a full overview of. <\/p>\n            <\/div>\n\n            <div class=\"accordion-wrapper\">\n\n                \n                    <div class=\"people-list grid js \">\n\n                        <h3>Contact person<\/h3>\n                        <div class=\"list grid-2 cg-20\">\n\n                            \n                                <a href=\"https:\/\/foyen.no\/en\/people\/jostein-ramse\/\" class=\"grid rg-10\">\n                                    <div class=\"img-wrapper\">\n                                        <img loading=\"lazy\" decoding=\"async\" width=\"1367\" height=\"2048\" src=\"https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-scaled.jpg\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image\" alt=\"\" srcset=\"https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-scaled.jpg 1367w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-481x720.jpg 481w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-854x1280.jpg 854w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-768x1151.jpg 768w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-1025x1536.jpg 1025w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-534x800.jpg 534w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-339x508.jpg 339w, https:\/\/foyen.no\/wp-content\/uploads\/NIC_1113-238x356.jpg 238w\" sizes=\"auto, (max-width: 1367px) 100vw, 1367px\" \/>                                    <\/div>\n                                    <div class=\"grid rg-0\">\n                                        <h2>Jostein Ramse<\/h2>\n                                        <span>Lawyer<\/span>\n                                    <\/div>\n                                <\/a>\n\n                            \n                        <\/div>\n\n                        <a class=\"btn\" href=\"\/en\/people\/#privacy-and-cyber-security\" data-text=\"Our team\" data-text-hide=\"Hide\">Our team<\/a>                    <\/div>\n\n                \n                \n\n\n                <!--  -->\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n<section class=\"accordion\">\n\n    <div class=\"grid padding\">\n        <ul class=\"accordion\">                <li>\n                    <div class=\"title\">\n                        <span>General<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>F\u00f8yen has for many years been an important part of the privacy law community in Norway. After the transposition of the EU General Data Protection Regulation (GDPR) in 2018, the need and scope of our advice on privacy law is bigger than ever before. We help with the implementation of robust internal control systems and with carrying out risk assessments. We assist in dialogues with the Data Protection Authority and make assessments in relation to transfer of personal data to countries outside EU\/EEA, use of new technologies, crisis management (security beach), and drafting of DPIA, BCR, and PBCR. F\u00f8yen is also an important adviser for actors within different business sectors that go through a digitalization process.<\/p>\n<p>We have experience with privacy issues within a wide range of business sectors such as technology, media, health, public bodies, trade of goods, transport, industry, energy, etc. The scope of our experience enables us to quickly understand the questions that arise within privacy law, and to use our expertise to solve new challenges. Our customers thus get effective advice, no matter how complex the matter is.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Systems for internal control<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Any businesses that process personal data must have a system for internal control, which documents the processing and that it complies with the GDPR. We can assist with the mapping of processing activities within the business and with the establishment of required routines. We also assist with the implementation of routines for deletion of personal data. We have a thoroughly prepared set of standard documents which we use when assisting with the above-mentioned issues.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Consent and other legal basis for processing of personal data<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>In the GDPR, consent is an important legal basis for processing of personal data. F\u00f8yen assists with the assessment whether a consent is considered sufficient, or whether there is an alternative basis for the processing such as legitimate interest. In many business sectors, there are also specific laws that may serve as legal basis for the processing. F\u00f8yen\u2019s lawyers are experienced with the assessment of such specific legal basis and have also assessed the need for and set forth proposals for such laws.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Privacy notices and privacy policies<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>In order to be in compliance with the privacy laws and regulations, the data subjects must be informed about the processing in accordance with the requirements of the GDPR. F\u00f8yen has extensive experience with the drafting of privacy notices and other ways of providing the required information. It is also important that employees are aware of their obligations when processing personal data. F\u00f8yen thus regularly assists with the drafting of privacy policies and training of employees.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Risk assessments<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Risk assessments must be made in relation to all processing of personal data. In certain situations, a data processing impact assessment (DPIA) must also be carried out in accordance with article 35 of the GDPR.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Data processing agreements<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Both the controller and the processor are required to enter into a data processing agreement if the processor shall process data on behalf of the controller. The data processing agreement must fulfil the requirements set out in article 28 of the GDPR and often raises questions of liability and claims for compensation. A data processing agreement shall not be entered into in situations where there is a transfer of personal data between two independent controllers or where there are joint controllers. It is thus important to be aware of the different roles related to the processing of personal data.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Transfer of data to third countries<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Businesses are required to identify all transfers of personal data to third countries outside the EU \/EEA. There is also a transfer if a person outside the EU\/EEA has access to the personal data, even if the personal data is stored within the EU\/EEA. The general rule is that all transfers are prohibited unless there is a specific and sufficient legal basis for the transfer. The assessment of whether there is such a basis, is usually made in the form of a Transfer Impact Assessment (TIA). This is typically relevant when entering into agreements with international cloud service providers, in relation to agreements where cloud services form part of the value chain, or in relation to more traditional outsourcing. In these situations, it is vital to have knowledge of the various service models and to know what to do to comply with privacy laws and regulations in each specific situation.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Data protection officer<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Many businesses are obliged to have a data protection officer in accordance with the GDPR. The GDPR sets out requirements for when such data protection officer shall be appointed, which role the data protection officer shall have within the company, and which tasks the data protection officer shall perform. F\u00f8yen\u2019s lawyers are experienced with and can offer to take on the role as data protection officer, or alternatively support internally employed data protection officers in their role.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Fines for breach of the GDPR<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>The data protection authorities can impose fines for breach of the GDPR. The fines imposed on larger businesses have been very high, but we see that the fines imposed on regular Norwegian businesses are rising as well. However, by using the right tools and arguments, there are considerable leeway for arguing that there is no breach at all, or that the fine must be reduced. It is not uncommon for the authorities to reduce the fines after hearing the arguments submitted after notice of a potential fine.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>BCR and PBCR<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>BCR and PBCR are internally binding rules, agreements, and instructions within a group of companies which allow for the transfer of personal data between the affiliated companies even if this involves a transfer to third countries outside the EU\/EEA. BCR apply where the companies are controllers, while PBCR apply where the companies are processors. The data protection authority must approve BCR and PBCR. This can be a long process which also involves the data protection authorities in other countries within the EU\/EEA, but it ensures an approval from the data protection authorities. If BCR or PBCR are complied with after the approval, the likelihood of inspections and fines from the data protection authorities are reduced.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Personal data breach \u2013 cyber security<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>A personal data breach is defined in the GDPR as a \u201cbreach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed\u201d. Such breach must be handled correctly within the business and in accordance with the GDPR. A protocol documenting the processing must be established. It must be assessed whether there is a need to notify the data protection authority and potentially also data subjects affected by the breach. Cybersecurity is key when assessing which security requirements that must be made to the processing of personal data, especially in relation to a specific breach and how such incidents must be handled.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Cookies<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>Use of cookies is a specific area of law with a huge practical impact. Today, the laws and regulations relating to cookies are divided between two supervisory authorities, which leads to uncertainty and misunderstandings amongst those who own and set up web pages. However, we know how to arrange for compliance with the laws and regulations.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n                        <li>\n                    <div class=\"title\">\n                        <span>Seminars etc.<\/span>\n                    <\/div>\n\n                    <div class=\"content\">\n                        <p><p>F\u00f8yen\u2019s lawyers frequently hold seminars and give speeches on various topics within privacy law. We have established a dedicated forum for data protection officers and others with responsibilities for privacy within businesses. This forum is arranged four times a year, where relevant topics are presented and discussed. We also give lectures for businesses who would like a presentation of or training sessions within specific topics.<\/p>\n<\/p>\n                    <\/div>\n                <\/li>\n        <\/ul>\n    <\/div>\n\n<\/section>","protected":false},"excerpt":{"rendered":"<p>Data protection encompasses the individual\u2019s right to privacy and the right to protection of personal data. In a digitalized world, all businesses process personal data, and the applicable laws and regulations are both wide and complicated. Both large and small businesses are affected and must carry out their activities in compliance with the laws and regulations, and we know how. Due to constant updates and developments from case law and practice from European and national authorities, privacy law is also difficult to approach and get a full overview of. <\/p>\n","protected":false},"featured_media":944,"template":"","class_list":["post-4020","expertise","type-expertise","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy and cyber security - F\u00f8yen<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy and cyber security - F\u00f8yen\" \/>\n<meta property=\"og:description\" content=\"Data protection encompasses the individual\u2019s right to privacy and the right to protection of personal data. In a digitalized world, all businesses process personal data, and the applicable laws and regulations are both wide and complicated. Both large and small businesses are affected and must carry out their activities in compliance with the laws and regulations, and we know how. Due to constant updates and developments from case law and practice from European and national authorities, privacy law is also difficult to approach and get a full overview of.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/\" \/>\n<meta property=\"og:site_name\" content=\"F\u00f8yen\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-25T06:13:33+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/foyen.no\/wp-content\/uploads\/m-10.png\" \/>\n\t<meta property=\"og:image:width\" content=\"887\" \/>\n\t<meta property=\"og:image:height\" content=\"710\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy and cyber security - F\u00f8yen","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/","og_locale":"en_US","og_type":"article","og_title":"Privacy and cyber security - F\u00f8yen","og_description":"Data protection encompasses the individual\u2019s right to privacy and the right to protection of personal data. In a digitalized world, all businesses process personal data, and the applicable laws and regulations are both wide and complicated. Both large and small businesses are affected and must carry out their activities in compliance with the laws and regulations, and we know how. Due to constant updates and developments from case law and practice from European and national authorities, privacy law is also difficult to approach and get a full overview of.","og_url":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/","og_site_name":"F\u00f8yen","article_modified_time":"2022-04-25T06:13:33+00:00","og_image":[{"width":887,"height":710,"url":"http:\/\/foyen.no\/wp-content\/uploads\/m-10.png","type":"image\/png"}],"twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/","url":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/","name":"Privacy and cyber security - F\u00f8yen","isPartOf":{"@id":"https:\/\/foyen.no\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/#primaryimage"},"image":{"@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/#primaryimage"},"thumbnailUrl":"https:\/\/foyen.no\/wp-content\/uploads\/m-10.png","datePublished":"2022-04-05T14:34:09+00:00","dateModified":"2022-04-25T06:13:33+00:00","breadcrumb":{"@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/#primaryimage","url":"https:\/\/foyen.no\/wp-content\/uploads\/m-10.png","contentUrl":"https:\/\/foyen.no\/wp-content\/uploads\/m-10.png","width":887,"height":710},{"@type":"BreadcrumbList","@id":"https:\/\/foyen.no\/en\/expertise\/privacy-and-cyber-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Hjem","item":"https:\/\/foyen.no\/en\/"},{"@type":"ListItem","position":2,"name":"Privacy and cyber security"}]},{"@type":"WebSite","@id":"https:\/\/foyen.no\/en\/#website","url":"https:\/\/foyen.no\/en\/","name":"F\u00f8yen","description":"","publisher":{"@id":"https:\/\/foyen.no\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/foyen.no\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/foyen.no\/en\/#organization","name":"F\u00f8yen","url":"https:\/\/foyen.no\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/foyen.no\/en\/#\/schema\/logo\/image\/","url":"https:\/\/foyen.no\/wp-content\/uploads\/Foyen_svart.svg","contentUrl":"https:\/\/foyen.no\/wp-content\/uploads\/Foyen_svart.svg","width":1,"height":1,"caption":"F\u00f8yen"},"image":{"@id":"https:\/\/foyen.no\/en\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/foyen.no\/en\/wp-json\/wp\/v2\/expertise\/4020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/foyen.no\/en\/wp-json\/wp\/v2\/expertise"}],"about":[{"href":"https:\/\/foyen.no\/en\/wp-json\/wp\/v2\/types\/expertise"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/foyen.no\/en\/wp-json\/wp\/v2\/media\/944"}],"wp:attachment":[{"href":"https:\/\/foyen.no\/en\/wp-json\/wp\/v2\/media?parent=4020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}