Guest
I am not sure you can help me with this but I will ask. Are we required to physically host in the EU data centers for our products and processing or can we host in the US if we follow all of the GDPR rules and cross border transfer guidance. If this is not the type of question I can ask, I totally understand and will pursue other avenues for guidance. Thanks again for your help and great product. Let me know if you have any questions or concerns.
We have an inquiry regarding the GDPR implementation , we are a software company that develops a software solutions to a customer X at Europe ; the software solutions are carrying personal information for X’s employees so we are a processor.
Internal systems developed and maintained by my company for other customers that have EU citizen employees should be GDPR compliant and in this case it should be secure by design and data should be secured at rest considering there is no agreement between the client and ourselves for applying GDPR requirements on the system ..please confirm?
Regarding personal rights, are these rights applied on employees as they are EU citizens in the way that is compliant with business rules and data retention policies, for example if the employee left the company and wants his data to be deleted, in this case the company should reply within 1 month that according to the business needs and regulations, his data will be retained for 5 years for example and after these 5 years ha may ask for a data deletion confirmation, is that right? We need to know what are the employee rights here and what to be applied at our systems?
Hi there - I'm *** from ***, a US-based company that acts as a data processor. We used your excellent GDPR toolkit to be compliant when GDPR first came out (May 2018). Recently, as I'm sure you know, Privacy Shield was invalidated. What advice can you provide on how to retain GDPR compliance going forward?
"I have a doubt, in the company which I work, we have clients of LATAM and all of their employees aren´t European people but our hosting is in Spain. If I understand very well GDPR applies just for European people, this is right?
What are the key technical security safeguards that are mandatory to achieve compliance?
Our company established in Australia is planning to run a global online classifieds website. We will also be servicing to data subjects in EEA in addition to data subjects outside EEA.
We have no representatives or establishments in EEA. The data will be stored in Ireland and all of our servers will be in Ireland. We use a cloud hosting provider. We will never transfer data from Ireland to any third country.
Will we still be compliant? If not, what should we do to be compliant?
1) What is the prime difference between ROPA & PIA?
2) While assessing a vendor, once I am done with Information Risk Assessment Questionnaire, how would I be able to identify if i have to proceed with ROPA or PIA?
3) I have created ROPA and PIa questionnaires and added below sections; do these makes sense or am I missing out on something?
ROPA
Contact Information
Basic information on processing and responsibility
Data Collection
Purpose and legal basis of data processing
Data transfers and recipients
Standard period for data erasure
Means of processing
Groups with access authorization (simplified authorization concept)
Technical and organizational measures (Art. 32 GDPR)
Data portability
PIA
Business / Project Information
General Information
Attributes of the Data (use and accuracy)
Sharing Practices
Notice to Individuals to Decline/Consent Use
Data sharing
Access to Data (administrative and technological controls)
Privacy Analysis
Retention and Deletion
We are a German technology startup company approaching 20 employees spread over the world (Europe, Asia, Australia).
Actually, I have three questions:
1) I hear that if you have 20 employees with regular data processing activities, in Germany you are obliged to have a data protection officer. Is that right?
2) To have an employee considered having regular data processing activities, it is sufficient to have access and work with MS Outlook, is that right?
3) Following the ruling regarding the invalidation of Decision 2016/1250, I am very much confused with the requirements. Reading some of the publication of the edpb, it seems to me hardly feasible anymore to manage GDPR across a small multinational company. Any suggestions?
What recommendations would you suggest for a small / Medium sized business in light of the recent decision by the ECJ regarding the EU-US Privacy Shield?
I am to develop Data Protection Matrix for my organization. How do I go about it?