The controller has 30 days to respond to the data subject. However, if a processor is the one receiving a request form a data subject the processor has to notify the data controller as soon as possible and is only the controller that needs to send a reply to the data subject.
Nothing has changed as regards to company related information. However, things may change as of 2019 when a new ePrivacy Regulation may be coming into force.
I just need to confirm, can I use ISO 27001 policy tool kit to develop PCI DSS policies?
Answer: We're not experts in PCI DSS, but generally we recommend ISO 27001 documentation toolkit as a way to contribute to achieve PCI compliance, because PCI-DSS has some requirements that can be fulfilled by ISO 27001 controls from Annex A, such as access control policy, back up policy, etc.
These materials will also help you regarding ISO 27001 implementation:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.c om/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Toolkit content
Answer: If you want to fulfil only ISO 27001 requirements regarding information security continuity, then you should consider using the Disaster Recovery Plan template, located on folder 08 Annex A A.17 Business Continuity 04 Business Continuity Plan, instead of the Business Continuity Plan template.
This template alone will be enough to cover all the requirements of ISO 27001.
Example: I am Swedish so automatically I am a citizen, I'm not living in any EU country so from that perspective I am not an EU resident. So what is the correct term as the targeted audience is very different.
Answer:
The EU GDPR will apply to the processing of personal data of EU data subjects, regardless of whether the processing activities take place in the EU or not. The EU GDPR is also applicable to entities established outside the EU if they offer goods or services to individuals in the Union, or if they monitor the behavior of individuals in the Union (i.e., profiling activities, tracking individuals’ activities on the internet, etc.).
The key to understanding when EU GDPR is applicable is understanding the meaning of “in the Union.” The EU GDPR will only apply to personal data regarding individuals within the Union, whil e the nationality or habitual residence of those individuals is irrelevant. For example, a company based in the EU which is processing the data of Japanese individuals located in Japan will still need to comply with the EU GDPR. Consequently, the Japanese individuals will be benefiting from all rights according to the EU GDPR, even if these rights do not exist in their own nation’s laws.
Answer:
You want to be a lead auditor, for that purpose you should have some work experience, particularly useful will be some experience in the quality area. You should have a course as lead auditor, start performing internal audits and keeping a log of those audits. Then, I advise you to contact certification bodies and ask them what are their requirements to be a certification body lead auditor.
The following material will provide you information about being a lead auditor: