Expert Advice Community

Guest

PII role identification

  Quote
Guest
Guest user Created:   Sep 17, 2016 Last commented:   Sep 17, 2016

PII role identification

A small company using cloud services to store and process its customers data, without offering any cloud service, can be considered a PII processor or just a cloud service customer?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 17, 2016

Answer:

Its a relative question, depending upon if it has its own data on this cloud service it uses, because:

- When you talk about your own data on the cloud service you use, you are the PII principal. You define by your own how the data can be used.
- When you deal with your customer data on the cloud service you use, you are the PII controller. You receive personal data from customers (the PII principals) and use a third party (the PII processor) to perform operations previously agreed with customers.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 17, 2016

Sep 17, 2016