My question is, Is there any requirement in ISO 9001:2015 standard that QMS manager reporting should be to the top management neither to any specific department head?”
Answer:
There is no requirement in ISO 9001:2015 about responsibilities and roles in the implementation phase. ISO 9001:2015 requires that management system leadership is a top management responsibility. If top management is not involved in the implementation phase it may be difficult, not impossible, to evidence knowing and leading the management system.
The following material will provide you information about top management responsibility:
No hay plantillas relacionadas con la cláusula 4.4 porque la norma no requiere ninguna documentación obligatoria para esta cláusula.
La cláusula 4.4 incluye requisitos generales para el SGC que están relacionados con cada parte del SGC. Esto significa que en realidad está cumpliendo de forma indirecta con esta cláusula 4.4 con todos los procedimientos, políticas y registros documentados necesarios para cada parte del SGC.
The MPIs and OPIs are 2 types of Environmental Performance indicators.
- MPIs include policies, people/employees, activities, practices, procedures, decisions and actions in the organization. Examples of MPIs are: Hazardous waste generated per unit of product (kg/unit); Wastewater discharged per unit of product (1000 L/unit).
- OPIs include the inputs, the supply of those inputs, i nstallations, faclities and equipment operation, design, outputs and delivery of those outputs. Examples of OPIs are: Percetage of environmental targets achieved; Environmental budget (%/year).
When I start implementing an ISO 9001 project I start with the team: Who is the Project Sponsor, someone that can influence top management, who is the Project Manager, who is included in the Project Team.
Then, training about ISO 9001 and what is a management system.
After that we can design a Project Plan (what will be done, by whom, until when with what resources). Normally, I divide the Project in two parallel work fronts: one strategic (about strategic orientation, policy, context, interested parties, strategic risks and and oppotunities, objectives with action plans) and another much operational (mapping processes and designing its risk management with procedures, instructions, control plans). My book, linked bellow, descrives this approach.
Then, implementing is following the Project Plan and making verifications, performing audits and having management meeting to make decisions and improving.
The following material will provide you information about ISO 9001 implementation:
Things are not so simple as you would imagine, among the responsibilities for processors under the EU GDPR the most important are:
To appoint a representative if based outside of the Union;
- ensure certain minimum provisions in contracts with controllers (see Mandatory obligations for data processor contracts);
- Not appoint sub-processors without specific or general authorisation of the controller and to ensure there is a contract with the sub-processor containing certain minimum provisions;
- process personal data on the instructions of the controller unless required to process for other purposes by Union or Member State law ;
- keep a record of processing carried out on behalf of a controller );
- co-operate with the supervisory authorities;
- implement appropriate security measures;
- notify the controller o f any personal data breach without undue delay;
- appoint a data protection officer in certain cases;
- comply with the rules on transfers of personal data outside of the Union (see Transfers outside the Union).
2. The main changes to the standard and the implications for corporates that are ISO14001:2004 certified
Answer:
1. All ISO standards are reviewed every five years in order to keep it current and relevant for the marketplace. ISO 14001:2015 was designed to respond to latest trends and ensure it is compatible with other management system standards.
2. These are the main changes to the standard:
Increased prominence of environmental management within the organization's strategic planning processes
Greater focus on leadership
Addition of proactive initiatives to protect the environment from harm and degradation, such as sustainable resource use and climate change mitigation
Improving environmental performance added
Lifecycle thinking when considering environmental aspects
Addition of a communications strategy
Los objetivos de calidad están orientados a establecer las pautas y acciones para gestionar la organización en relación con la calidad, mientras que los objetivos estratégicos están orientados a gestionar la organización en general.
Aunque la calidad y los objetivos estratégicos no son los mismos, deben estar alineados. Puede decidir en su empresa que la calidad es un factor estratégico, por lo tanto, los objetivos de calidad serán parte de su plan estratégico.
Un ejemplo de un objetivo de calidad puede ser aumentar la satisfacción del cliente al 5%, y un ejemplo de un objetivo estratégico puede ser aumentar el 3% de las ventas.
Para obtener más información sobre los objetivos de calidad, consulte estos artículos:
If you send the newsletters to existing of former customers, you provide a means for the user to unsubscribe and the content of the newsletter refers to similar services of products they purchased from you the answer would be yes.
Cross Border Data Transfers
Answer:
If the data of your employees are being processed outside the EEA then you need to have specific safeguards in place such as Standard Contractual Clauses. Ideally you would have one singed with all suppliers processing your personal data outside the EEA. However, when dealing with SaaS suppliers they usually tend to have documents that would cover all range of customers. For starters, you could ask them to inform you about the safeguards that they are using when sending data outside the EEA.