Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Yes, you need to share your third-party list with the processor. The chain of data processors must be clear and transparent to the controller. The controller can authorize the processor to engage a sub-processor with a specific authorization or with a general authorization. In case of general written authorization, the Article 28 GDPR requires the processor informing the controller “of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.”
Here you can find more information:
It depends on the privacy policy and the data you shared with the app. In privacy notice, the data controller will tell you what kind of data the app will have access to and ask for your consent.The data subject can withdraw the consent at any time and for any reason.
According to Article 15 GDPR you can demand access to data stored by the data controller (right of access ) and of course you can demand that data based on consent shall be erased under Article 17 GDPR unless there is another legitimate ground of processing. I.e., if the app required your consent to access your image gallery and some photos of you had been processed (i.e., stored in the cloud), you can demand the cancellation of images stored but you may not be able to demand the cancellation of some information related to your account if they are processed under another legitimate grounds. I.e. billing information can be stored for longer periods because of tax laws provisions.
The data controller shall erase your data without undue delay. In your request, you can refer to the data minimization principle demanding to cancel all the information that is no longer necessary to be processed. Of course, this is a general answer, based on your statement that the data processing is based on consent. You should check in the privacy notice which is the legitimate ground and what information is stored before demanding to proceed under Article 17 GDPR.
Here you can find more information:
You can also consider enrolling in this free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
ISO 9001 is defined as the international standard that specifies requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements.
Broadly speaking, I can suggest these main topics to consider:
OPEX:
CAPEX:
Regarding ISMS maintenance costs, the above-mentioned costs also have to be considered, but at different levels, and you have to add the surveillance audit costs for certification maintenance.
These articles can provide you more information:
For additional examples of the combination of assets, threats, and vulnerabilities, please see these materials:
In case of an address change, you need to communicate that to your certification body, so you both can evaluate the degree of impact this will bring to your ISMS and the certification validity, to identify if any immediate change is required, or if related changes can be assessed during the next scheduled audit.
With ISO 9001 an organization implements a set of practices, written or not, they represent a standard way of doing things internally. The same ISO 9001 requires determining indicators to monitor and measure performance.
So, your organization must have some indicators about logistics performance. When your organization decides to improve performance, it may use six sigma as a methodology for improvement.
You can find more information below:
The need to consider Information security in project management separately will depend on the results of risk assessment and applicable legal requirements (e.g., laws, regulations, and contracts).
For example, some projects may require the implementation of technologies not used in your organization at large, so it would not make sense to write a corporate policy. Other projects, by force of contracts, may require that all information security is under project context. In case these situations do not occur, then you can make projects refer to the corporate documents
For additional information, see: