Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
"Can you think of anything that could easily be overlooked when preparing for GDPR?"
The main issue is to insert privacy sensibility into organization processes and make GDPR a living thing into every-day activities.
In fact, many organizations can easily comply with the document-side of GDPR by drafting good privacy notices and policies or updating their devices with security measures but all the work done is frustrated if employees keep password under the keyboard, or forget to comply with data subjects request or do not update privacy notices and ask consent when required.
Most of the fines issued from Data Protection Authorities (DPAs) concern non-compliance with general data processing principles as indicated in Article 5 GDPR (almost 44% of fines in 2019 according to European statistics on DPA decisions), security measures, and respect of data subjects rights.
Here you can find more information:
Article 5 GDPR: https://advisera.com/gdpr/principles-relating-to-processing-of-personal-data/
Is consent needed? Six legal bases to process data according to GDPR: https://advisera.com/eugdpracademy/knowledgebase/is-consent-needed-six-legal-bases-to-process-data-according-to-gdpr/
Four main questions for obtaining and managing data subjects’ consent under GDPR: https://advisera.com/eugdpracademy/knowledgebase/four-main-questions-for-obtaining-and-managing-data-subjects-consent-under-gdpr/
You can also consider enrolling in this free online training EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
Thank you, @Rhand Leal
I have bought the documentation toolkit with extended support.
1 - Frankly, I'm not quite sure to whom should I send my queries via email.
I have received detailed email explaining these things at the time of purchase, but I can't find it now.
You can post your questions on our community at this site: https://community.advisera.com/
In case you want to make a more sensitive question, you can send it to our support contact: support@advisera.com
2 - I'm planning to implement the ISO 22301 for our bank, which is a leading bank with more than 30 branches, and for now we are planning to certify only IT department operations.
my question is, do we need to include the branches in our scope or it's just our HQ office and our DR Site?
In each branch, we have some switches, firewalls that is used to connect to our centralized systems. All the equipment in the branches are managed centrally from the head office.
You can define your ISO 22301 scope only as your HQ office and DR Site. You can treat your branches as external locations that your scope interacts with.
These articles will provide you a further explanation about scope definition (it is focused on ISO 27001, but the concepts also apply to ISO 22301):
Since it seems all IT elements in the branches are managed from the HQ, there is no need to include the branches in the scope. You only need to inform how these elements are separated from other elements controlled by the branches.
These articles will provide you a further explanation about scope definition (it is focused on ISO 27001, but the concepts also apply to ISO 22301):
Previous versions of ISO 14001 used the words “legal requirements”. ISO 14001:2015 uses instead the words “compliance obligations”. Compliance obligations include legal requirements and other requirements like customer requirements.
Any organization operating in a certain region will have to comply with a set of laws and regulations – the legal requirements. For example, in my country any organization has to comply with legislation about:
You can find more information below:
First, that is a great example of what can become a quality management system owned by many people in an organization. Normally, there is great resistance to participate in this way.
What I would recommend is that before starting to create procedures people should have some basic training in ISO 9001 requirements associated with each department. Now, you cannot go back in time. So, I recommend performing departmental internal audits where internal auditors can check implementation and also conformance according to ISO 9001 requirements.
The following material can provide more information:
First is important to note that Document control and confidentiality levels (i.e., information classification) are different things.
Control of documents and records is a requirement of the standard (one that does not require to be documented), while information classification is one of the information security controls from ISO 27001 Annex A.
Considering that, the use of the information classification control to identify confidentiality levels is needed only if your organization has relevant risks, or legal requirements (e.g., laws, regulations, or contracts) demanding the implementation of this control. If no such situations occur, you do not need to implement information classification.
This article will provide you a further explanation about information classification:
Configuration management in AS9100 (clause 8.1.2) is all about ensuring that the end product meets the requirements fully as per the design, with any design changes noted. For a company that is creating designs as their deliverable, the most important thing is traceability for the design to the design requirements to show they are met. This is very much like a design verification activity.
As for FOD, which is an example given in clause 8.5.4 on preservation, this would not really be applicable to a company delivering a design. You will not that the list in this clause is listed as “when applicable”
You can learn more on configuration management in AS9100 in the article: Understanding configuration management in AS9100 Rev D, https://advisera.com/9100academy/blog/2017/05/08/understanding-configuration-management-in-as9100-rev-d/
Operational risk management in AS9100 (clause 8.1.1) is all about identifying and tracking the risks that are in place during the creation and delivery of the product or service. In an organization that delivers designs you still have risks for completing and delivering the design (e.g. incomplete requirements, tight timeline for delivery, etc.). These risks need to be identified for the project, assessed and communicated, and mitigation actions assigned when necessary, with the understanding that some risks will have no action other than tracking until they are gone (e.g. time-critical delivery from a supplier)
You can learn more on operational risk management in AS9100 in the article: 5 key elements of risk management in AS9100 Rev D, https://advisera.com/9100academy/blog/2017/05/15/5-key-elements-of-risk-management-in-as9100-rev-d/
Clause 6.4.2 states that When the laboratory uses equipment outside its permanent control, it shall ensure that the requirements for equipment of this document are met.
Firstly it is important to note that "Equipment" is considered as any item used to generate a result, so this also applies, for example, to software, reference materials, chemicals and reagents.
This clause can cover a number of scenarios, for example
1) When equipment is shared within the laboratory facility or another department of the organisation,
2) When items are stored in a storeroom not managed directly by the laboratory,
3) When equipment is calibrated offsite by a service provider or another department and returned for use by the laboratory, and 4) If a service provider performs a service on an item, even if onsite.
In all these cases the activity must comply with ISO 17025 requirements for equipment. This includes facilities and environment, handling, storage, use, verification, performance checks, and appropriate records.
For more information see