Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • GDPR Documentation and PII

    Please advise regarding the below:

    1. What is data processor obligations in details regarding data subject rights

    • The right to be informed.
    • The right of access.
    • The right to rectification.
    • The right to erasure.
    • The right to restrict processing.
    • The right to data portability.
    • The right to object.
    • Rights in relation to automated decision making and profiling.

    Is there any procedure to be taken as example

    2. When providing outsourcing call center services , what is the legal basis to process the data noting that consent is taken by the data controller (is it legitimate interest : be able to fulfill our contractual obligation with the controller ?)

    3. What is the list of documentations required by the data processor

  • Filling templates

    "Thank you for your detailed responses! Our company is in the US but we have a representative in Austria (Prighter). I assume I use this address for the supervisory authority address? Can you confirm if this is correct?"

    Yes, you should refer to the Austrian Supervisory Authority.

  • Documenting mandatory documents for ISMS

    When writing mandatory documents you need to take into account all the elements that are prescribed in the standard - e.g. in Statement of Applicability you need to include all 114 controls from Annex A, and for each one if it is applicable, the justification, and the status of the implementation. 

    This white paper will give you an overview of mandatory documents, and how to structure them: Checklist of Mandatory Documentation Required by ISO 27001 https://info.advisera.com/27001academy/free-download/checklist-of-mandatory-documentation-required-by-iso-27001 

    This free online training will teach you the basics of the ISMS and what are the steps in the implementation: ISO 27001 Foundations Course: https://advisera.com/training/iso-27001-foundations-course/ 

  • What to exclude from Procedures and/or Quality Manual?

    If you will not design any new products, it means that you are manufacturing already known products, that you can exclude requirement 7.3 Design and development. In our documentation toolkit, you do not need to use folder 09_Procedure_for_Design_and_Development.

    If your medical device is not sterile, it means that requirement 7.5.5 Particular requirement for sterile medical devices and 7.5.7 Particular requirements for validation of processes for sterilization and sterile barrier systems. In our documentation toolkit, you do not need to use 12_Procedures_for_Sterile_Medical_Devices. 

    Each exclusion must be stated and explained in the Quality manual. For example, requirements 7.5.5 and 7.5.7 are not applicable because our medical devices are not sterile.

    On the following link you can find tips on how to write a short quality manual for ISO 13485:

Page 236-vs-13485 of 1128 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +