Expert Advice Community

Guest

GDPR compliance

  Quote
Guest
Guest user Created:   Dec 12, 2018 Last commented:   Dec 12, 2018

GDPR compliance

We are ISO27001 certified and I am looking at BS:10012:2017 to further our compliance with GDPR. I understand the 2017 version aligns itself with GDPR and may be seen as a "certificate of GDPR compliance". If I understand it correctly, a successful audit for BS:10012 means that it can be appended to the 27001 certificate indicating we are securing personal data. Personal data for our company is the customer data we collect on behalf of clients and our own employee data. We are both a data processor and a data controller. The alternative is ISO 270018, for protecting data in the cloud. And we are a cloud based company. I am leaning towards 10012 as the next step and would appreciate your view.
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Dec 12, 2018

Answer:

Let me start by saying that compliance with ISO standards and compliance with a legal requirement are somewhat different. ISO standards are not mandatory and you don't get fined if you do not comply with their provisions nor can they be enforced by governmental bodies. In terms of ISO or any other standard, you get some kind of certificat ion stating you are compliant while for GDPR this is not applicable.

And finally, nor ISO nor any other standard can be used to prove compliance with a legal requirement such as the EU GDPR. What BS:10012 does is give you a framework that you could use in terms of data protection without guaranteeing anything in terms of legal compliance.

Coming back to your original question, I personally think that BS:10012 or ISO 270018 are not required to be compliant with the EU GDPR so unless you need those standards for something else, then you can get certified. ISO 27001 is, however, a good way to prove that you are keeping your information assets including personal data secure which helps in terms of compliance with Article 32 of the EU GDPR.

If you want to find out more about ISO and GDPR compliance, check out this EU GDPR & ISO 27001 Integrated Documentation Toolkit (https://advisera.com/eugdpracademy/eu-gdpr-iso-27001-integrated-documentation-toolkit/).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 12, 2018

Dec 12, 2018

Suggested Topics

Guest user Created:   Jun 24, 2021 EU GDPR
Replies: 1
0 0

GDPR Compliance questions