Transfer of personal data to the US deemed illegal - key steps that your organisation can take after Schrems II

Aug 6, 2020 2:54:24 PM / by PrivacyPerfect posted in Privacy Shield, US, Standard Contractual Clauses

Many European organisations share data with organisations outside the EU, or rather the EEA, with data often being transferred to the US. Most of these organisations, 60% of them, relied on the Privacy Shield as a data transfer mechanism to the US. However, on July 16, 2020, the Court of Justice of the European Union invalidated the Privacy Shield, making the transfer of personal data to more than 5,500 US organisations (including the most used software tools) be in violation of the EU privacy law, the GDPR. The reason for invalidation: the law and practice of access to personal data by US intelligence services means that the protection of personal data by EU standards does not have an adequate level of protection.

Read More

Doorgifte persoonsgegevens naar VS onwettig - belangrijke stappen die uw organisatie kan nemen na Schrems II

Aug 6, 2020 2:51:55 PM / by PrivacyPerfect posted in Privacy Shield, US

Veel Europese organisaties delen gegevens met organisaties in landen buiten de EU (of eigenlijk de EER: EU en Noorwegen, Liechtenstein en IJsland). Vaak is dit naar de VS. Op 16 juli 2020 zette het Hof van Justitie van de Europese Unie een streep door het PrivacyShield, waarop 60% van de organisaties die gegevens delen buiten de EU vertrouwt voor wettige doorgifte naar de VS. Dit maakt de doorgifte van persoonsgegevens aan meer dan 5.500 Amerikaanse organisaties (waaronder de meest gebruikte softwaretools) in een klap in strijd met de Europese privacywet AVG. De reden: het recht en de praktijk omtrent toegang tot persoonsgegevens door Amerikaanse inlichtingendiensten betekent dat de bescherming van persoonsgegevens naar EU-maatstaven niet een passend beschermingsniveau geniet.

Read More

PrivacyPerfect introduceert nieuwe DSR-module voor eenvoudig afhandelen informatieverzoeken

Jul 30, 2020 12:48:36 PM / by PrivacyPerfect posted in Data Subject Requests, DSR

Verwerking ‘verzoeken van betrokkenen’ conform de AVG niet langer een zeer kostbaar en tijdrovend proces 

30 juli 2020 - De Algemene Verordening Gegevensbescherming (AVG) verleent personen rechten om controle te houden over de verwerking van hun persoonsgegevens. Via een ‘verzoek van betrokkene’ kan ieder individu gebruik maken van deze rechten. Het kan onder andere gaan om het recht op inzage, het recht op vergetelheid, het recht op rectificatie en het recht op overdraagbaarheid van gegevens. Het reageren op deze verzoeken is een kostbaar en tijdrovend proces met veel handmatige taken en een strakke deadline van een maand. Om de afhandeling van verzoeken eenvoudiger en sneller te maken, introduceert PrivacyPerfect, leverancier van privacy compliance-oplossingen, de DSR-module. 

Read More

Remote working & Data security

Jul 23, 2020 10:22:00 AM / by The Trust Bridge posted in Data Security, remote work

Given the strange situation we all find ourselves in at the moment, with so many people suddenly
working from home for the first time, organizations have little time to prepare for the consequences that may arise from increased risk of cyber attacks and data breaches. All the data they have is not where it perhaps should be or protected to the same extent as it is normally. It is likely that many employees will continue to work from home for many months, if not forever.

Read More

Overcoming the challenges of conducting a DPIA

Jul 22, 2020 1:20:58 PM / by PrivacyPerfect posted in DPIA, Data Protection Impact Assessments

Carrying out a Data Protection Impact Assessment (DPIA) is often considered a challenging task by data protection professionals due to the complexity of the process, which often involves big and detailed projects, and relies on the involvement and support of other stakeholders within an organisation. Fortunately, there are several methods that can help make the performing of DPIAs easier, simpler, and more efficient. In this blog post, our privacy experts highlight the key steps that may help make the process painless.

Read More

PrivacyPerfect behaalt ISO 27001-certificering voor databeveiliging

Jul 17, 2020 10:28:03 AM / by PrivacyPerfect posted in ISO certification, ISO

PrivacyPerfect, leverancier van privacy compliance-oplossingen, heeft de ISO 27001-certificering voor informatiebeveiliging behaald. Hiermee toont PrivacyPerfect aan dat het beschikt over een solide managementsysteem voor databeveiliging en dat ook de software-oplossingen voldoen aan de strengste normen voor databeveiliging en de privacywetgeving. 

PrivacyPerfect wil een bijdrage leveren aan een digitale wereld waarin mensen erop kunnen vertrouwen dat bedrijven en overheden hun persoonsgegevens op een veilige manier verwerken. Daarom helpt het organisaties met software-modules en advies om onder meer de Algemene verordening gegevensbescherming (AVG) na te leven. Met het behalen van de ISO 27001-certificering bewijst PrivacyPerfect dat databeveiliging een integraal onderdeel is van zijn bedrijfsvoering, producten en dienstverlening.

“Als leverancier van privacy compliance-oplossingen is een gedegen bescherming van persoonsgegevens de basis van de belofte die wij doen aan onze klanten. We zijn dan ook trots dat we deze certificering hebben behaald en hiermee kunnen aantonen dat we als organisatie volledig compliant zijn met de AVG”, zegt Nicoline Matser, CEO van PrivacyPerfect.

Onder de AVG hebben organisaties meer verantwoordelijkheid gekregen om aan te tonen dat zij de juiste organisatorische en technische maatregelen hebben genomen om aan de privacywetgeving te voldoen. Om deze zogenaamde verantwoordingsplicht goed in te vullen, is een organisatiebrede strategie voor gegevensbescherming onmisbaar. De oplossingen die PrivacyPerfect hiervoor biedt worden inmiddels door meer dan 2000 gebruikers wereldwijd ingezet. 

Kans om reputatie te versterken

Read More

Healthcare institutions and GDPR compliance in a digital world

Jul 16, 2020 9:45:00 AM / by PrivacyPerfect posted in healthcare

Digital transformation is and has been the focus of many organisations in the last couple of years, including those of the healthcare sector. This shift brings with it new, additional aspects for all areas, a major one being data protection. In the healthcare sector, where a huge amount of sensitive personal data is being processed on a daily basis, protection of this data has to be of top priority, with strict procedures, access controls, and guidelines on privacy. As such, compliance with the GDPR, within digitized care and cure organisations, is crucial. Let’s take a look at how you can ensure compliance for your healthcare organisation without disrupting the efficiency of your work.

Read More

What the outcome of the upcoming ruling in Facebook Ireland vs Schrems can mean for your organisation and how to prepare for the 16th of July

Jul 8, 2020 8:30:00 AM / by PrivacyPerfect posted in Privacy Shield, International Data Transfer, Standard Contractual Clauses

In exactly one week, on the 16th of July, one of the most anticipated cases in data protection, case C-311/18 — Facebook Ireland versus Schrems — will be delivered by the EU Court of Justice (ECJ). What’s at stake is if international flows of personal data to and from the EEA can continue as is now, or if major changes will be required. The verdict in the groundbreaking "Schrems 2.0" case will dictate whether the widely used Standard Contractual Clauses (SCCs) and the EU/USA Privacy Shield will remain a valid means of transferring personal data to countries outside the EEA under the EU’s GDPR. As these mechanisms are used for a large majority of international data transfers, this may in turn have a large impact on organisations around the globe. In preparation for the case, we analyse the road so far, and what the possible outcomes could mean for your organisation in regard to data privacy.

Read More

All you need to know about Data Processing Agreements

Jul 2, 2020 10:15:12 AM / by PrivacyPerfect posted in Data Processing Agreements, Third-party

 One way or another, almost all organisations rely on third parties for processing personal data in today’s digital world, creating a direct need for data processing agreements (DPA). Even the tools that are considered to be the basic necessities in business, such as email clients, CMS systems, data storage servers, or website analytics, all process personal data on behalf of organisations. With the introduction of the GDPR, there are strict requirements and guidelines on how this can be done in a compliant manner, through signed DPAs between the organisation (the data controller) and any party that acts as a data processor on their behalf. But what are Data Processing Agreements (DPAs), are they really necessary for you, what do they look like, and who needs to be involved from within your organisation? 
Read More

Data Subject Requests under GDPR vs CCPA

Jun 25, 2020 5:15:46 PM / by PrivacyPerfect posted in ccpa, Data Subject Requests

Responding to Data Subject Requests has been an ongoing challenge for organisations worldwide due to the complexity and tight deadlines of the process. July 1st 2020, California will become the first US state with an enforced comprehensive consumer privacy law, the California Consumer Privacy Act (CCPA), creating new, broad privacy rights that impose significant obligations as well. The new law, which we can see as a Californian counterpart of the General Data Protection Regulation (GDPR), might have a significant impact on entities that collect and share and sell personal data. While both the GDPR and CCPA provide rights to individuals in regard to managing their personal information , there are several overlaps and differences between them. Let’s take a look. 

Read More

    Lists by Topic

    see all
    harmas_Rajztábla 1-1
    Keep informed!
    Sign up to the Weekly GDPR Digest now.