Answer: To define which documents you need to develop and how to make them useful, you should consider issues such as:
- regulation or contractual requirements that demands a certain document
- the organization size and the number of people involved
- the importance and complexity of the process or activity
Answer: Many of our clients are companies that provide SaaS and are using large hosting providers like AWS, Azure and similar - so yes, this toolkit is applicable for such companies, especially if they are small or medium-sized (up to 500 employees).
Answer:
I would say that neither Incident/Problem/Change Management is fully implemented without Configuration Management (Service Asset and Configuration Management in ITIL). That means that mentioned processes are depending on information from Configuration Management.
Following articles provide more details:
2. Data processor agreement – Our client requested us to sign a Data Processing Agreement, which defines our client as data controller and us as the data processor. However, under certain situation, in delivering the service to clients, we play the data controller role and our client is the data processor. Does this means we need another Data Processing Agreement for these exchanged roles?
Answer:
1. I strongly advise you to define a maximum retention policy for candidates CV considering that anyway the data in the CV would be most likely outdated in a few years.
2. Not necessarily. When you are acting as an independent controller it is not necessary to have a DPA with another controller.
Answer: Indeed, this is one reason and the other is that in order to fulfill all of its obligations as regards to the EU GDPR any company needs to get the support from the top management. Thus, the top management needs to be informed and it also needs to endorse the compliance effort together with the Personal Data Protection Policy as well.
In the case of policies and procedures you won´t need much effort since our templates are already written and they are fully editable, you just need to enter the specific information about your company. Although the forms are not pre-filled, so you will need to input all the information.
Also, it is important to highlight that our documentation not only deals with all the technicalities but also guides you on what to fill out with several comments.
We do not have any detailed procedure for a Lessons Learnt Program. Your organization monitors performance, identifies improvement opportunities, develops improvement projects and after evaluating their effectiveness, intends to capture the know-how acquired.
A procedure for a Lessons Learnt Program should define how that know-how is acquired and transmitted to others in the organization.
Flujogramas en los procedimientos
Mi respuesta:
No es necesario¡realizar flujogramas para los procedimientos. Tenga en cuenta que en esta nueva versión de la norma, ISO 9001: 2015, no es obligatorio escribir ningún procedimiento, por lo que puede optar por tener un procedimiento o no, y también cómo será el mismo. Sin embargo, la creación de flujogramas puede ayudar a una organización a explicar mejor un proceso, comunicarse e incluso a mejorar ese proceso.
Para obtener más información sobre la documentación de ISO 9001: 2015, consulte estos artículos:
Privacy Policy vs. Privacy Notice and Data breaches
1. So the first one, should the company have both: privacy policy and privacy notice? Cause I see the differences between these two, but it is really hard to find a web were both of them are there... So I messed up...
2. next one, can I write about data breaches in my risk policy? Cause there are written all information about several breaches, so it seems to me legit to write this one as well...
Answer:
1. The Privacy Policy in the EU GDPR Documentation Toolkit is meant to be an overall Policy to describe what is a company doing to be compliant with the provisions of the EU GDPR. The Privacy Notice on the other hand is a document meant to explain to the data subjects what is a data controller doing with their data. So, as you can easily see the two documents are meant to serve different purposes. To learn more about privacy notices check out our webinar “Privacy Notices Under the EU GDPR” (https://advisera.com/eugdpracademy/webinar/privacy-notices-under-the-eu-gdpr-free-webinar-on-demand/)
Puede justificar la ausencia del manual de calidad ya que el manual de calidad ya no es un requisito obligatorio según ISO 9001: 2015. Sin embargo, su organización puede decidir escribir un manual de calidad si lo considera útil.
Para obtener más información sobre el manual de calidad en ISO 9001, consulte estos artículos: