To comply with GDPR, is it enough for our 3rd party data processors to have terms of service which comply with GDPR. Or do we need to get updated signed contracts for all processors?
Directive 95/46/EC
Kindly ask you to answer why the documents keep within the Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995?
Dropbox
I have a question regarding Dropbox. We currently store all of our company document here. I wouldn't say there was personal data stored here but sensitive data we store in order to work with our clients. With regards to deleting and getting rid of this data, is this something you need to do in order to be GDPR compliant? Dropbox is currently GDPR compliant, so do we need to do anything further?
Terms and conditions
1) Do we have to get reconsent from each user we have on our platform? Or is it enough to notify all users that requirements and privacy notice have changed and provide an opt out option?
Privacy notice template
Is the privacy notice in the templates designed for a website? Or should I have a different notice for that?
Required GDPR documentation
We have a corporate client base, which includes individuals names, telephone numbers and email addresses. We also have staff and keep records of their personal details ie age, name, address, tel no, national insurance number. With regards to GDPR, do we have to submit a compliance form or do we have to keep the relevant keep records in case we get a 'visit'. Also, do you provide any templates from which we can work?
GDPR - Encrypted e-mails
I am wondering if/when/how we should use encrypted e-mails at my company? In which cases could it be a necessary means to ensure some extra compliance in relation with the GDPR. Are there any general guidelines? Which information should entail encryption?
Mandatory EU GDPR documents
I saw your ‘List of mandatory documents required by EU GDPR. It is quite helpful. You have 9 forms listed as non-mandatory documents. I thought that these forms are indeed mandatory?
Data transfer
I'm working on a marketing freelance basis for a small business involved in small regional UK trade shows for the print industry .The data they collect on visitors to the shows is shared with the exhibitors. I'm trying to find out some info on how to approach this 'data transfer' to our associated UK exhibitors and the implications of this from a GDPR point of view please.
Employee security awareness training
We had an employee security awareness training on GDPR and the whole issue of security related to users' personal data. Unfortunately, I do not find a document in which I can sign the employees on the issues related to GDPR and their responsibilities. I would be very grateful if you could send me such a document.