Expert Advice Community

Guest

GDPR tips

  Quote
Guest
Guest user Created:   Jul 09, 2018 Last commented:   Jul 09, 2018

GDPR tips

Hello, I'm in my small business (about 30 employees) proportionate information security officer and proportionately engaged in project management outside of this issue. Due to staff shortages and time pressure in the project with me in recent months, the employment with the GDPR hardly came about. But now the time has come and I have the task, quasi as Head of GDPR (without being named officially DPO) to fulfill the implementation. Because in our view ISMS and GDPR go hand in hand. I have been given the stipulation to do the GDPR regulations by the end of the year by the end of the year.
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Jul 09, 2018

Now my question, whether this makes sense and whether this approach could be fatal to us. Unfortunately, it is not possible for us, e.g. 100% free for 1 month only for GDPR activities. Since you certainly have experience, also in terms of the scope, I am very curious about your tips and hints.

Answer:

First I would like to start by mentioning that a DPO is not necessary to be appointed unless (a) the processing is carried out by a public authority or b ody, except for courts acting in their judicial capacity; or (b) the core activities of the legal entity consist of processing operations which, by their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the legal entity of processing on a large scale of special categories of data pursuant to Article 9 of the EU GDPR and personal data relating to criminal convictions and offences referred to in Article 10 of the EU GDPR. If you could link the implementation of ISMS together with GDPR it won’t constitute an issue.

To learn more about ISMS and GDPR check out our articel “Does ISO 27001 implementation satisfy EU GDPR requirements?” (https://advisera.com/27001academy/blog/2016/10/17/does-iso-27001-implementation-satisfy-eu-gdpr-requirements/).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 09, 2018

Jul 09, 2018

Suggested Topics

Guest user Created:   Apr 17, 2018 EU GDPR
Replies: 1
0 0

GDPR in tourism