42Gears Commitment to General Data Protection Regulation (GDPR)

42Gears Commitment to General Data Protection Regulation (GDPR)
By 42Gears Team
General Data Protection Regulation (GDPR
  • A controller is the one who “determines the purposes and means of the processing of personal data” (that’s you, and maybe us).
  • A processor is one who “processes personal data on behalf of the controller” (that’s us when you use our applications, products or services).

42Gears essential steps towards GDPR Compliance:

1. Accountability and Governance:

We have designed comprehensive but proportionate measures to minimize the risk of breaches and uphold the protection of personal data.

2. Data Protection by Design and Default:

42Gears has adopted appropriate technical and organizational measures to consider and integrate data protection into its processing activities.

3. Lawful basis of processing:

We aim to ensure lawful basis for processing of personal data. We have a Privacy Policy setting out our purpose of collecting and processing of personal data.

4. Security:

GDPR requires personal data to be processed in a manner that ensures its security. We have defined and implemented adequate systems to maintain effective and proportionate security that includes protection against unauthorized or unlawful processing and against accidental loss, destruction or damage.

5. Contracts:

We determine appropriate means to validate the contractual obligations in relation to data processing with the third parties to avoid the risk posed by processing.

6. International Transfer:

Personal data collected by us including any and all the personal information of the EU Customers may, therefore be processed by our service providers in the United States. We take appropriate contractual or other measures to protect the personal information in accordance with the applicable laws pertaining to Data Protection.

7. Data Breach:

A personal data breach means a breach of security leading to the destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. We have trained our employees to report and escalate breaches. Under GDPR, we are subject to a direct obligation to notify controllers of a data breach without undue delay after becoming aware of it. Therefore, we ensure that we engage appropriately with our controllers in the event we become aware of a data breach.

8. Individual Rights:

Disclaimer: 42Gears does not claim that the organisations using our products/services will be HIPAA/GDPR/CCPA or any applicable regulations compliant or exempt from any legal or regulatory provision applicable thereto. Using the products/services will only assist customers in achieving certain mandates devised for the companies handling personal information of the end users.

“Written with expertise and passion to help you understand the topic better.”

4
42Gears Team – Content Author
Published on: May 23, 2018

Subscribe to our newsletter

Stay updated with the latest news, articles, and resources on enterprise mobility.

Weekly articles
Actionable insights delivered once a week. No noise.
No spam
Your privacy matters. Unsubscribe anytime.