Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
Are pixels and cookie IDs regarded as personal data?
I am assuming you are referring to Facebook pixels ID which is considered as an analytic cookie. If so, yes, analytic cookies are considered personal data, and they are ruled by the e-privacy directive (a new e-privacy regulation is under approval procedure between the EU Commission and the EU Parliament).
How can we cope with a deletion request if we cannot correlate a cookie ID with a specific person?
Usually, cookies deletion is managed by users’ browser and it is the user who can manage cookie deletion by its own browser.
Do we have to delete the cookie IDs after a specific period of time?
Yes, you should establish the data retention period in your data policy. Some cookies last one session, others 24 hours, and some last one year. On the market, there is plenty of tools that can help you to determine the period.
Do we require consent to place cookies?
It depends on the cookies. The e-privacy directive states that you need consent, except for strictly necessary cookies which are essential to browse the website and use its features, such as accessing secure areas of the site. You should, however, explain their existence and use, in the privacy notice.
Here you can find more information:
You can consider enrolling in our free EU GDPR Foundations Course
EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
Please check this article about mandatory documentation - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/ these are the documents and records that all organizations must have. Each organization will have a particular organizational structure where these mandatory documents will fit. For example, design and development will be done by different departments in different organizations.
You can find more information about documents and records below:
ISO 9001:2015 does not mention the existence of a quality manual. So, it is not mandatory to have a quality manual, neither is forbidden to have one. I recommend organizations to have a quality manual, but it is just a recommendation. Please check this article about mandatory documentation - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/
The following material will provide you information about the quality manual:
Based on ISO 14004 guidance we can categorize interested parties this way:
Your organization exists to serve some interested parties. That service is constrained, helped or hindered by other interested parties. Considering the life cycle approach to your organization’s environmental aspects interested parties are of paramount importance.
You can find more information about interested parties below:
Unfortunately, I have no personal experience of working with hospitals. According to what I read many hospitals decide to start by certifying just a service. For example, blood services, and then, year after year they enlarge the scope of the system including further services like imaging services or outpatient consultation.
The following material will provide you information:
If you are looking for guidance for Quality Policy and Quality Manual, but you are not a manufacturer of medical devices, then you should look for the ISO 9001. ISO 9001:2015 is a standard that is applicable to all businesses.
Following articles can help you to understand the ISO 9001:2015:
You can even look at our Quality manual template and Quality Policy template from our ISO 9001:2015 Documentation toolkit:
ISO 9001:2015 does not require a Quality Manual. So, you can design your Quality Manual as best fits your organization’s purpose. For example, you can include the internal and external issues as a topic to be reviewed during management review or while updating quality objectives. Internal and external issues will affect the ability of an organization to perform.
You can find more information below:
No, ISO 9001:2015 does not require a quality manual as a mandatory document. However, I recommend organizations to develop their own quality manual as a document presenting the quality system.
The following material will provide you information about the quality manual:
First, please check this article - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/ where you can find a list of mandatory records required by the standard.
Second, please check clause 7.5.2 a) of ISO 9001:2015 about identification and control of documents. Title, date, author or reference number are just examples. Your organization does not need to use all of them at the same time.
You can find more information about records below:
Organizations are not closed systems. External issues are relevant topics that can influence the future of an organization. For example, governments can issue legislation that will affect the activity of an organization. Socials trends can influence consumers or clients’ priorities. You can use the PESTLE analysis to determine external issues (PESTLE stands for Political, Economic, Social, Technology, Legislation and Environment).
You can find more examples of external issues in this free webinar on demand - ISO 9001:2015 clause 4 - Context of the organization, interested parties, and scope - https://advisera.com/9001academy/webinar/iso-90012015-clause-4-context-of-the-organization-interested-parties-and-scope-free-webinar-on-demand/
You can find more information below: