1. Are Legitimate Interest & Legal Basis the same? If not, how are they different?
GDPR Controllers and Processors of personal data records
Are there different documents & records for Controllers and Processors of personal data?
EU GDPR and Data Processing
We provide a service to our customers whereby we provide a technical support service for certain software applications that they run. If a customer employee experiences a problem with the software application, they will log a ticket with us and we will diagnose and fix the problem. In certain circumstances, we may transfer the ticket to our partner in XXX to help diagnose and fix the problem. The ticket has details of the technical problem but includes the customer employees’ name and e-mail address. We (or our XXX partner) may use the e-mail address to reply to the employee and keep them informed on progress or request follow-up information. Would this data be classed as “personal data” and if so would we be classed as processing this personal data? If yes to both, what steps would we be required to take to meet our obligations under the GDPR regulations?
GDPR Readiness Assessment and DPIA
1. What are the differences between an EU GDPR Readiness Assessment, and a Data Protection Impact Assessment (DPIA)?
GDPR Data Consent and Storage
1. Can visitors see information about earlier visitors when they sign in? This is a data privacy breach. Standard signing-in books do not comply with GDPR.
GDPR Questions
1. What exactly is a (and/or where can I obtain more information on) “Supplier” Privacy Notice?
GDPR standard contractual clauses
What exactly is meant by:
Personal data breach and DPO
Our main concern regarding the DPO is that when the time comes to report a breach... what are the specific tasks that the DPO has to fulfill. is there a Checklist we could use to establish a guideline?
Transfer personal data outside the EU
There are 2 companies in 2 different countries in the EU. One of them is a parent company, another one is a subsidiary company. Is it legal for the subsidiary company to share all the employment contracts (which contain employees' personal information e.g. salary, phone number, home address, etc.) with the parent company since these contracts were concluded between the employees and the subsidiary company?
GDPR Data Controller or Data Processor
Can my controller ask me to conduct DPIA for the processing activities that involve me as a data processor?