Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
"I have been through the forwarded material around GDPR compliance and I have the following questions:
1. International personal data transfers – Binding Corporate rules (BCR) under GDPR – and Cross border documentationHow do we secure compliance? Is it by fill in and sign the Cross Border document or do we need another agreement?
I assume you are referring to the documentation in the EU GDPR Documentation Toolkit. As you may know, Binding corporate rules (BCR) under Article 47 GDPR apply to group companies for transfers inside the same group, and to be compliant must be approved by the competent Data Protection Authority (DPA) following the procedure in Article 63 GDPR which is quite complex.
BCR must
BCR are quite complex and not suitable for small-medium companies, with a long and complex adoption procedure. Maybe, your question referred to the Standard Contractual Clauses, which are used for assuring the transfer of data between companies that do not belong to the same group.
These are contained in Folder 7 of the EU GDPR Documentation Toolbox that you bought. If so, you need to attach the Data Transfer Agreement to the original Agreement with the other Party selecting the right template depending if you are transferring to a data processor or to a data controller.
2. When we have “employed” sellers and consultants with their own companies which invoices their “salary” to Digizuite, do we then need specific Data processing agreements with each of them?
Do your sellers and consultants process personal data on your behalf in their job? If they do, you need to sign a specific data processing agreement with each of them independently from the use of Digizuite. Maybe sellers relate with customer's personal data and you need to assure the process data being compliant with GDPR requirements as data processors.
3. I can’t find a Data Processor agreement in your material. Why isn’t it part of the toolkit?"
In the EUGDPR Documentation Toolkit, you can find 2 templates of Data Processor Agreement in Folder 8 - Third Party Compliance.
Here you can find some useful material about data transfer:
You can consider enrolling in this EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//
Setup a project sponsor, a project manager and a project team. Ensure top management support, get training and as a first step perform a Gap analysis, to determine the amount of work to be done - comparing what your organization already has in place versus ISO 9001:2015 requirements. From that GAP Analysis you can develop your Project Plan, listing what needs to be done, by whom, until when.
Then, an important step is to design a model of how your organization work as a set of interrelated processes. For example:
Decide how to describe and monitor those processes.
From there it is implementation in order to close the gaps found. Then, perform an internal audit and the management review. There you can decide if your organization is ready for a certification audit.
This is a very short description of the journey but below you can find more detailed information:
One general advise: avoid generic lists of risks. Each organization is a particular case.
According to ISO 9001:2015 organizations can determine three types of risks:
The following material will provide you more information about risks:
After ISO 9001:2015 the requirement for the independence of internal auditors has been removed from the internal auditor definition but not from the audit definition. Now, in addition to meeting your organization's competence criteria, internal auditors only have to ensure objectivity and impartiality. Thus, the manager could audit his own subordinates during an internal audit if, and only if he/she can ensure that it will be carried as a systematic, independent and documented process for obtaining objective evidence. This requirement is lost when the auditor (the manager) is a person who could be affected by the audit. For example, as manager he/she who would need to deal with the corrective actions that were found. So, avoid having managers auditing their own subordinates during an internal audit.
The following material will provide you more information:
1- Implementation process flow
Answer:
The following links provide information that can help you develop your own implementation process flow. The first article is about using the Gap Analysis as the first step in gathering information to develop an implementation plan:
2- Basic required procedures"
Answer:
This may come as a surprise to you but ISO 9001:2015 does not requires any procedure. It is up to each organization to decide what procedures, if any, are needed (please check clause 4.4.2). Not being mandatory is not the same as being forbidden. So, I recommend organizations to develop relevant procedures. The more complex an organization is and the bigger the staff rotation, the more are procedures useful. Please check this article - List of mandatory documents required by ISO 9001:2015 - https://advisera.com/9001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-90012015/
Please check the beginning of clause 9.3.1. It states that top management shall review to ensure a set of things about the quality management system. The conclusions and decisions of the management review are about that set of things. If top management does not approve those outputs, it cannot evidence that that set of things is being ensured.
The following material will provide you more information:
I can only provide a general answer about project sponsors. Normally, a project sponsor is someone who does not actively participate in the project. The project sponsor must be regularly briefed by the project manager about the project status and intervene if the project is halted. A project sponsor can be very useful for unlocking resources and reconciling conflicting priorities and escalated issues.
The following material will provide you more information about design and development:
I have a question in regards to the document in section 8, Third Party Compliance. Supplier Data Processing Agreement. We use a third party like Google Analytics, does it fall under this category?
According to the ISO 13485:2016 requirement 4.2.3 Medical device file, here are the elements that you need to have:
For more information, please see the following article:
Hi, I need to know whether there have been any changes to the EU GDPR policies recently in relation to e-privacy. Can you advise?