Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
ISO 14001 has no additional legal requirements. Companies with an environmental management system in accordance with ISO 14001 are not required to perform better than legally required. In addition, an environmental management system can be used to reduce costs by reducing waste. Finally, an environmental management system can be designed to minimize bureaucracy. So, I cannot subscribe to the idea that implementing an environmental management system is an expensive project.
Please check this information below with more detailed answers:
I cannot give you a straight answer, that will depend on your organization’s internal procedures. When a material has a defect, it is a product nonconformity. ISO 9001:2015 does not mandates a corrective action for each product nonconformity. ISO 9001:2015 requires deciding what to do with that product nonconformity. So, if you want to do that you have to update your procedure accordingly.
The following material will provide you more information:
Article 4 paragraph 7 GDPR defines ‘controller’ as the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
It means that who collects data is the controller. If you are developing an App that will collect personal data, you (or your company) will be the data controller. You need to declare who the data controller is and inform your data subjects clearly in the privacy notice. Most likely it will be the company and not the person.
The controller will need to comply with GDPR requirements for data processing.
Article 4 paragraph 8 GDPR defines the processor as “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”.
Therefore, the data processor is someone who acts on behalf of the controller. Let’s make an example with your app. You are the developer of the app and you collect users’ personal data. Maybe you are going to share these data with third parties like Google Analytics, which provide you some services to implement the functionalities of your app. Third parties will act as the data processors.
It can also be a web agency that sends on your behalf customized emails to your customers. They will process email addresses (which are personal data) on your behalf.
The data processor needs to be appointed by the data controller who will instruct on how to process data, what principles follow, what data retention period, and so on. The data controller has also the power to control and verify if the processor complies with the data processing principles set.
The responsibilities for not complying with GDPR requirements are liabilities towards data subjects for any damage caused by the data processing and also fines from the Data Protection Authorities. The fines are severe. Infringements are divided into two classes: infringements of data controller and data processor duties have fines up to 10 000 000 EUR or 2% annual turnover (whichever is higher), while the infringements of basic GDPR principles (like lawfulness of processing) has fines of 20 000 000 EUR or 4% annual turnover (whichever is higher).
Here you can find more information about data transfers, controller and processor:
You can consider enrolling in this EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
Can I replace a CAR/NCR with a material reject form? The form calls out the issue and then allows quality and production to come together in a meet to resolve the issue at hand and further prevent it
Implementing a lean quality management system for a consulting firm implies being very pragmatic and knowledgeable about ISO 9001:2015. Now the standard is less and less bureaucratic, it is up to each organization the task to develop and implement a lean quality management system.
Setup a project sponsor, a project manager and a project team. Ensure top management support, get training and as a first step perform a Gap analysis, to determine the amount of work to be done - comparing what your organization already has in place versus ISO 9001:2015 requirements. From that GAP Analysis you can develop your Project Plan, listing what needs to be done, by whom, until when.
Then, an important step is to design a model of how your organization work as a set of interrelated processes. For example:
Decide how to describe and monitor those processes.
From there it is implementation in order to close the gaps found. Then, perform an internal audit and the management review. There you can decide if your organization is ready for a certification audit.
This is a very short description of the journey but below you can find more detailed information:
Yes, it is. According to the contract signed between your company and the certification body, after the certification audit your organization will have yearly surveillance audits.
The following material will provide you more information:
Internal and external issues are relevant topics that can influence the future of an organization. For example, governments can issue legislation that will affect the activity of a recycling company. Socials trends can influence how consumers and households react to recycling practices. About internal issues you can have, for example, experienced workforce, inflexible machinery or lack of capacity.
You can find more examples in this free webinar on demand - ISO 9001:2015 clause 4 - Context of the organization, interested parties, and scope - https://advisera.com/9001academy/webinar/iso-90012015-clause-4-context-of-the-organization-interested-parties-and-scope-free-webinar-on-demand/ (it is about ISO 9001 but I think it may be useful)
The following material will provide you more information:
Providing a safety culture is critical to implementing ISO 45001, and the crucial step is in the example of top management. There is a saying that “management leads whether they mean to or not”, and this is equally important to a safety culture. If there is a rule that safety glasses need to be worn, but the president of the company never wears them in the area, then this tells people that the safety rules are not important; if top management tries to say safety is important in words, but not in actions, they the culture of safety will not happen. A culture of safety will only occur when the rules are known, understood, and equally applied to everyone; then you can work on maintaining and improving safety.
You can find out more about convincing top management about the OHSMS that are still applicable to ISO 45001 in the article: 4 crucial techniques for convincing your top management to implement OHSAS 18001, https://advisera.com/45001academy/blog/2017/08/30/4-crucial-techniques-for-convincing-your-top-management-to-implement-ohsas-18001/
Considering ISO 13485:2016, in requirement 4.2.5 Control of records is stated that organization will keep records for at least the lifetime of the medical device, or as specified by applicable regulatory requirements, but not less than two years. It means that if a lifetime of your medical device is six months or one year, you need to keep records for at least two years.
For more information, please read the following article:
You can also check out our book for more information:
Data Transfer Agreement template (Referenced in Cross Border Transfer Procedure):
DTA for Controller -> Controller
DTA for Controller -> Processor
When to use which one?