Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
You can move to another notified body, but most important here is that findings that were raised against MDD are applicable for MDR as well. So you definitively need to solve those findings. Your CE mark will be under suspension until you comply with the MDR.
If you a legal manufacturer and want to put a medical device under your name, then you are also obliged to be certified according to ISO 13485. The contract manufacturer is your outsourced process and you need to have a proper quality agreement with them in accordance with the requirement 4.1.5 from the ISO 13485.2016. This quality agreement is supposed to cover mutual responsibilities, but also what kind of control you will have over them. Usually, the following are control measures:
Supplier's audit – you will perform supplier audit over them in a periodicity which will be risk-based the need for the outsourced company to notify you if it receives any complaint about similar products mutual communication in resolving complaints and inconsistencies - defined time required to respond to inquiries and clarifications
Considering the MDR /CE mark, again if you are a legal manufacturer and want to put a medical device under your name, then it is your responsibility to prepare the technical file in accordance with the Annex II and Annex III of MDR. Be prepared that when the notified body will come for your MDR audit they will also go to the audit of the outsourced certified company.
For more information, see:
You need consent to process a special category of personal data (the so-called sensitive data) and when your data processing goes beyond the fulfillment of a contractual obligation. In your case, when making a contract with a client for your software, the client agrees to data processing for the purposes of the contract: receiving the software, issuing invoices, store the IP, Wi-fi password, location, etc. This set of data you are collecting must be contained in the privacy notice and have as a legal basis the performing of contractual obligation.
However, if you want to process your client’s data for marketing purposes you need to ask a specific consent on it because the client when downloading the software reasonably expected that personal data would be processed to fulfill the obligation.The consent must be specific and given freely so you need to ask your client something like “Do you agree to receive information, promotions, from us?” or “Do you want that your data are shared with our partners for promotional advertisement?” The Client must be aware of the reasons you are asking him consent.
Here you can find more information on the legal basis to process personal data according to the GDPR and what to consider about the GDPR privacy notice:
If you want to learn how personal data are processed under the EU GDPR you may consider enrolling in our free training EU GDPR Foundations course: https://advisera.com/training/eu-gdpr-foundations-course//
How to integrate ISO 9K with ISO 14K
Answer:
Organizations exist to serve clients. So, I recommend starting with modeling how the organizations serve clients based on the process approach and ISO 9001.
Then, I consider other interested parties:
Based on ISO 14001 and interested parties' requirements I recommend organizations to determine environmental aspects and impacts, compliance obligations, and risks.
From here, it is possible to determine what needs to be done to improve the interaction with the environment while serving clients. And what needs to be done can be translated to things like:
Of course, you will have several activities that can be immediately integrated like training, management review, internal audits, document control, monitoring, and measurement.
You can find more information below:
what are the basic requirements for certification?
Answer:
I don’t know if I’m understanding correctly your question. To be certified an organization has to comply with management system standards (both at the design of the system level and at the conformity of practices level) and has to comply with compliance obligations.
what are the best practices followed by organisations seeking for ISO 14k certification?
Answer:
Setup a project sponsor, a project manager, and a project team. Determine the scope of the EMS. Ensure top management support, get training. Designing and implementing an environmental management system (EMS) implies being knowledgeable about ISO 14001:2015.
As a first step perform a Gap analysis, to determine the amount of work to be done - comparing what your organization already has in place versus ISO 14001:2015 requirements. From that GAP Analysis, you can develop your Project Plan, listing what needs to be done, by whom, until when.
From there it is implementation in order to close the gaps found. Then, perform an internal audit and the management review. There you can decide if your organization is ready for a certification audit.
Perhaps the following links can be useful:
Only auditors working for certification bodies (certification auditors) can certify a business as ISO 27001 compliant.
The choice of the certification body is an organization's decision, based on its strategies and business objectives and alignment with certification body practices.
These articles can provide you further information:
Please note that the provision of Business Impact Analysis / Business Continuity Risk Assessment needs to be considered in the contract or service agreement you have with this supplier because this way in case they do not provide the documents you can have legal means to enforce compliance. Anything out of the contract or service agreement must be negotiated with the supplier.
Considering that, to see a material with examples of applicable legal clauses to contracts that you can use as a basis to make your questionnaire for performance review, please access this template demo (although it is about ISO 27001, it also can be applied to business continuity): https://advisera.com/27001academy/documentation/security-clauses-for-suppliers-and-partners/
These articles will provide you a further explanation about supplier management:
These materials will also help you regarding supplier management:
1 - The scope cannot be a server or a product, because it is a management standard right? Does this then mean that it can’t be an environment, like a cloud environment? Would you set the scope as the software engineering department for example instead?
Your assumption is correct. The ISMS scope cannot be defined in terms of products, assets, or technologies. It needs to be defined in terms of information, location or processes to be protected, so the definition of the scope as a software engineering department is more appropriated.
This article will provide you a further explanation about scope definition:
These materials will also help you regarding scope definition:
2 - And you mentioned the scope cannot be drawn between people who share the same office? Does this mean they would also need to be segregated in terms of network or email environment?
I’d really appreciate your opinion as I think the delivery time will be quite different if we chose the smaller scope rather than the whole company, although maybe more detailed in segregating them.
Please note that, for small environments, it is better to define all its elements as the ISMS scope because the effort and costs to segregate them may not be worthy, compared to managing all elements as part of the ISMS scope.
This article will provide you a further explanation about scope definition:
If you are a distributor of medical devices and may have to register products in the future, you have to have implemented ISO 13485:2016.
For more information about ISO 13485, please see following articles:
This choice will depend on the business objectives and complexity of measurement, but in most cases, organizations consider only critical services for such KPI (measuring noncritical services only adds effort without bigger benefits).
Regarding calculation, in general, it is considered the total sum of interruption times in a given period (e.g., day, week, month, etc.), where the downtime periods are monitored either by monitoring systems or by reports sent by users. Both approaches have their advantages and disadvantages, which should be evaluated considering the business context.
This article will provide you a further explanation about monitoring:
These materials will also help you regarding monitoring: