What is the scope of the IT Security Policy (Doc 8.1) included in the EU GDPR Documentation Toolkit?
EU GDPR questions
1. What should be the agreement between us (xxx) and the content providers (sub-processors)?
EU GDPR toolkit
The toolkit is made for both data controllers and data processors, right?
Sub-processors
Our software stores personal data on our infrastructure on behalf of our clients, so we are a Processor. We use Zendesk, a ticketing system, where users can report issues. This system is hosted in the US. In this system we will have email addresses from users, mostly only from our contact persons at clients. So not from all users. Should we regard Zendesk as a Sub-Processor with respect to personal data?
Cross reference between 27001 and GDPR
Is there a cross reference between 27001 and GDPR?
Legitimate Interest Assessments template
Is there any template around Legitimate Interest Assessments?
The Data Processing Agreement
Many of our customers, whom we process data are asking for this DPA. It is my understanding that this DPA is a document that we send to OUR suppliers who process data on our behalf, not for our customers whom we process data for. Can you please advise?
B2B company
We are a B2B company, which doesn't directly process the data of the end user. Do the same rules apply here for B2B and B2c companies?
GDPR data
Does data belong to the controller or the subject?
Privacy Shield
In your GDPR training video you outline that "as of the time that the video was created, the United States and Canada was still not recognized as having adequate data protection" Has this change or is this still the case?