We have collected some information which describes our road towards GDPR compliance and also some general information about GDPR.
- How does GDPR affect our company
- What is GDPR
- Our Roadmap towards GDPR compliance
- Cookies we set
- Request data we store or Remove cookies
How does GDPR affect our company
Gislen Software Private Limited is not located inside the European Union. However, we work mostly with clients in the European Union, in some cases via one of our wholly-owned subsidiaries located in the European Union. GDPR, therefore, applies to us as to how we handle personal data about European subjects and we are fully committed to achieving full compliance. We intend to be compliant ahead of the 25 May 2018 deadline.
We have identified the areas in which GDPR affects our work:
- Our website, which stores visitor personal information and provides forms for visitors to use to contact us or comment on posts. We also use service providers to support the site which, according to GDPR, act as processors for analysing visitor data.
- In our back-office systems in India where we store data about client contacts in emails, in documents and other ways.
- We are processors for our European clients who handle personal data of European subjects. Mostly this is done remotely from our office and the data itself remains on European servers. In most cases, our role is to support the systems and not process personal data. But, to support the systems, we will in many cases need to have access to the personal data itself. We will sign relevant agreements with all clients where this is required to ensure that we and our clients are compliant with the GDPR.
The right to privacy of our clients, their employees and customers are our priority. We intend to achieve full GDPR compliance and ensure that individual privacy is maintained in every way.
What is GDPR?
GDPR stands for the General Data Protection Act, legislation which provides comprehensive pan-European data protection. GDPR will be introduced in the European Union and the European Economic Area (EE/EEA) replacing the 1995 Data Protection Directive. The Data Protection Directive was implemented in different ways across different countries while GDPR will be the same (with certain minimum differences/additions for membership countries).
GDPR regulates authorities and organisations as to how they are allowed to process data (called ‘personal data’) about individuals in the EU (called ‘data subjects’) including collecting, storing, transferring or use.
GDPR gives individuals free of charge rights to control their data. Individuals have the right to know what data an organisation stores about them and to request correction, deletion or even transfer to another organisation when that is applicable. GDPR requires organisations to report breaches within 72 hours of discovery. The regulatory bodies in each country are getting significantly more ability to enforce compliance and impose high fines for non-compliance and breaches.
For more information about the GDPR please read the official web page.
Roadmap for our GDPR compliance
Here’s our high-level roadmap for GDPR compliance, with our current status mentioned:
- Research which areas of our business and services are impacted by GDPR – COMPLETED
- Assess our need for compliance with our website – COMPLETED
- Prepare a draft Data Protection Agreement based on the EU General Clauses for our clients – COMPLETED
- Assess which of our clients we work with where we have access to personal data of EU subjects and get processor agreements with them – COMPLETED
- Assess all security aspects, required for compliance with the GDPR – IN PROGRESS
- Sign agreements with processors handling personal data or tracking cookies collected from our website and ensure compliance – IN PROGRESS
- Assess our need for compliance in how we handle personal data such as client contacts and marketing data in our company in India – IN PROGRESS
- Develop a strategy and requirements for how to address the areas of our services are impacted by GDPR – IN PROGRESS
- Implement the required changes to our internal processes and procedures required to achieve and maintain compliance with GDPR – IN PROGRESS
- Sign new Work Agreements/NDA’s with all employees – IN PROGRESS
- Finalise and communicate our full compliance – TO BE ANNOUNCED