GDPR. Sage X3 People

Size: px
Start display at page:

Download "GDPR. Sage X3 People"

Transcription

1 GDPR Sage X3 People

2 This how to guide presents tools available in Sage X3 People for version 9 helping companies to fulfil some of their obligations regarding the European General Data Protection Regulation (GDPR). Please read the Sage Legal Disclaimer set out at the end of this guide. Audience This document is aimed at highlighting some Sage X3 People features that can be used when adhering to certain GDPR duties. This document is not intended to cover all the GDPR requirements. For this, please refer to some useful links in the Find out More section below. GDPR is a European law and it applies to all companies that operate in the EU and companies outside the EU who process the personal data of individuals in the EU. What s new The version 9 for Sage X3 People is GDPR ready. The tools delivered are especially for GDPR, to further assist customers. Find out More You can find appropriate supplementary documentation. Know Your GDPR Functional documentation for Enterprise Management - Online Help Centre (Access from the Enterprise Management pages) GDPR * Page 2 of 20

3 Contents Audience 2 What s new 2 Find out More 2 OVERVIEW 4 Features 4 Documentation 6 FEATURES THAT HELP YOU WITH GDPR 7 Ease of access to the right information and process 7 Data Protection Officer (DPO) management 7 Attachments 8 Auditing tools 9 Requester 9 Purge process 10 Search engine 12 Import/export data 13 Access security and data filtering 13 DOCUMENTATION 16 Personal data List, content and location 16 Specifically, for the HR and payroll modules, the standard data types associated to personal data main records are the following: 16 Security principles 17 SAGE LEGAL DISCLAIMER 19 GDPR * Page 3 of 20

4 Overview How Sage X3 People helps customers Definitions GDPR General Data Protection Regulation DATA PROTECTION OFFICER Under the GDPR companies and any third-parties that process personal data on their behalf will need to appoint a Data Protection Officer ( DPO ) if: (i) they are a public body; (ii) if the core activities of the business or third-parties involve monitoring of individuals on a large scale; or if the core activities consist of processing on a large scale of special categories of personal data, including data relating to criminal convictions and offences. The DPO needs to have expert knowledge of data protection law, although doesn t necessarily need to be an employee and could instead be employed on a service contact to fulfil the role. Details of the DPO will need to be communicated to the supervisory authority, such as the ICO in the UK. Features Feature How this feature can help you Comments Visual process dedicated to GDPR Data Protection Officer (DPO) management Attachment of documents, forms Auditing tool Requester You can design a dedicated home page for GDPR with all links and direct accesses to the functions you need You can create and allocate roles to users. You can attach to a master record any type of document needed for the GDPR, for example forms expressing the consent of people. You can track all activities, including connection, execution of a function, update/creation/deletion of records You can create your own extraction and reporting tools related to GDPR, for example, search/list/extract records linked to an individual For version 9 of X3 People a ready-to-use home page is designed and provided by Sage. You can personalise it. For version 9, the users can associate to a company, and to a role code defined as DPO. GDPR * Page 4 of 20

5 Feature How this feature can help you Comments Purging rules You can set-up rules to purge data that is no longer required, Note that this should be both from a business and a legal perspective (You must ensure that you adhere to all local data retention regulations). Personal data analysis Search engine Reference to a master record Import / Export templates Before v7.1, you can leverage the capabilities of the requester or extractions using import/export templates to identify records related to an individual, on demand. All business intelligence tools (Sage Enterprise Intelligence, BusinessObjects, Sage Data Management & Analytics ), if you installed one, can help you in this task. Sage X3 People is meta-data driven. The data is associated to a data type. See in the documentation section the list of data types that can rely to personal data. All data may be extracted or integrated using the import/export templates. Note that in the case of an import, the consistency of the data must be ensured. Please look at the list of the templates available in the solution, either standard or specific (You have set up or personalized). From v7.1, a full text search engine is delivered into the solution that can help you find the right information, as soon as the data is indexed. For more information, see in the section Search engine. To version 9* of X3 People the platform delivers a dedicated reporting tool enabling users to find the transactions linked to an individual, with the date of the first and last use. This provides you a powerful tool helping you to analyse the personal data, the content and the location, and decide whether this data may be obfuscated or purged (depending on the legal retention rules). *For Version 9, this tool will be delivered in Patch 10. GDPR * Page 5 of 20

6 Feature How this feature can help you Comments Data breach warning To limit the risk of a data breach and related penalties, you must make sure to implement best practices in terms of security and access right management, including your network, database and application. In case of breach, you can extract personal data stored into the database to contact relevant people impacted by the breach *For Version 9, this tool will be delivered in Patch 10. Documentation Topic Content Comments Data types This documentation lists the data types considered as personal data and detailing the content and location of this data. Local data retention rules Some examples of retention rules that apply for countries. Sage doesn t warrant the validity or the relevance of these rules, that are provided just as example. GDPR * Page 6 of 20

7 Features that help you with GDPR Ease of access to the right information and process If you have a person responsible for GDPR in your business, they are most probably not experts in the use of Sage X3 People, or its numerous tools for manipulating and storing personal data. As such, Sage X3 People provides you with the ability to design and allocate dedicated home pages for such people. Allowing you to group the information they might need on a dashboard and designing visual processes for them to easily access the relevant functions. For version 9, a new standard visual process dedicated to GDPR is delivered, with all relevant links to the Sage X3 People features. Intended to provide a base from which you can easily adapt to your own processes and organization as required. The following screenshot shows you the process delivered for X3 People: Data Protection Officer (DPO) management If you need to identify a DPO or want to record the individual(s) with responsibility for data protection you can do this within Sage X3 People by following these steps. You can use the following features: GDPR * Page 7 of 20

8 For version 9, you can use the responsibility code that can be freely defined to identify the DPO. To access this field: Setup -> Organizational structure -> Companies: A patch is delivered with the miscellaneous table 906 containing this new code for DPO purposes. However, it is possible to create the record in this table manually. Attachments If you would like to keep track of administrative events linked to data protection such as consents, data access rights and alteration. You can use Sage X3 People which provides you with the ability to attach documents to any record. From the master record, an attachment link gives access to a page where you can create links associated to keywords that can be freely defined; for example, consents linked to employees. Commenté [GC1]: Is it true in V9? Commenté [MJ2R1]: Yes, this is the example in V9. GDPR * Page 8 of 20

9 Auditing tools To manage the security linked to personal data it is advisable to put in place security and audit parameters regardless of the Sage X3 People technology used. One of the tools provided by X3 People makes available, is a set-up of an audit that can be triggered on access to any functions and any modification done. This can be done on creation, updates, deletion, and stores in the audit trail fields the values (before and after modification). The audit can also be focused and conditioned. For example, below the creation, modification and deletion of customers are tracked as soon as the first contact date is greater than a given date: This feature automatically creates database triggers that ensure the traceability of modifications, regardless of the way the updates were performed. With X3 People one can set an audit of any record, to track all changes, or only a deletion or only a value change. This parameter can be set-up at the user level and is managed by an Enterprise Management supervisor function. Requester If you would like to extract data for search and auditing purposes X3 People integrates various reporting tools including an ad-hoc requester. GDPR * Page 9 of 20

10 The result of such a request can generate PDF files, Excel spreadsheets, csv files, and many other formats. At execution, the requester performs a strict filtering on data based on the rights given to the user. The recommendation is to use requests that are not shared if they are authorised to several users, except if all these users have the same rights. Purge process Purging rules are described in a meta data dictionary. Every set of data (representing a document such as a payslip) are described by a rule that includes the conditions that must be fulfilled to allow the purging of such data. These descriptions are supplied as standard but can be personalized to take into account additional rules. For example, you could define that a dedicated status prevents you to purge automatically some data. Commenté [GC3]: We can here add the menu entry, at least the name of the function. GESAHI? Commenté [MJ4R3]: The link to the function is already present in the process. An example of purging rule is given below: GDPR * Page 10 of 20

11 The purge parameters define the minimum duration for storing these documents: The purge process can be launched per company or globally, in interactive or in batch mode. No automatic purging process exists for main records such as employees or contacts. The purging of these records may be processed manually. An alternative of purging master records is to obfuscate or blank personal data as soon as there is no legal or business / contractual reason to keep it. Basic actions like removing s, phone numbers, bank Ids or names is a simple and effective method that may also be considered. A manual suppression is also possible as long as no document references the master record. An additional feature described in the next paragraph gives you information about the document dates associated to a master record, so you can identify if, you can delete the master record after purging such documents. GDPR * Page 11 of 20

12 Search engine You may receive a request from an individual without limited detail, which might make it difficult to identify this individual in your database. For this, you can leverage all capabilities of Sage X3 People regarding data extraction, inquiries, requester, including additional business intelligence tools connected to Enterprise Management. For version 9, X3 People includes a search engine, and all personal data could be defined as searchable to allow you to quickly find the right record to answer the request. Starting from a name, you will immediately find the associated records. For example, if you search for Martin, you might find a lot of results that you can filter depending on what you are searching, an employee, a user or any other master record. Commenté [GC5]: When I search POUSSE in SEED Folder, the result displays data in common function. It seems to not display information in other function like in GESEML. Perhaps I am wrong! Commenté [MJ6R5]: The tables and records must be flagged with searchable in order to work. You have to define the data as searchable to have results. A search on an address would probably have given only one result: Once the master record is found, you can use all the other tools to process the action needed. Note: You have to make sure the classes, representations and fields are flagged as searchable within the system. Commenté [GC7]: So I understand better why my search is not concluding. In V9 we have very few syracused function. So probably it is not applicable for X3P V9 Commenté [MJ8R7]: No, I did this in V9 and it works. GDPR * Page 12 of 20

13 Import/export data Sage X3 People provides you with standard import/export templates associated to the different master records and documents. This allows you to extract data to answer any data access request you have received. The set-up can be changed to allow additional fields. The set-up is shown below. Note that the output format can be ascii with various separators (covering csv), but also XML and other various formats. Most of the templates but not all of them can be used not only for export, but also for import. Note that consistency constraints of X3 People version 9 will need to be fulfilled. This in part allows you to integrate data supplied by an individual (data portability). Access security and data filtering You may want to manage user access to personal and sensitive personal data in Sage X3 People. It is advisable to set-up the security of your system according to best practices to limit the risk of data breaches and related penalties, but also to set-up the security filters on data so that every user of the system has only the required access needed for performing their tasks. Sage X3 People allows you to restrict each user s access by function and also to assign filtering rules to the corresponding data per company, site, access codes or row level permissions. Note that an access code is a code that can be assigned to an individual record and globally restricts either the ability to read, to create, and to trigger complex operations on the record. The access security is closely related to the audit features, and allows you to manage access to sensitive or personal data. Some examples of the corresponding pages are given below: Access filtering per site and companies for a given profile and function GDPR * Page 13 of 20

14 GDPR * Page 14 of 20

15 Access code set-up for a given profile code Filtering rules per main record data function for given fields GDPR * Page 15 of 20

16 Documentation Personal data List, content and location Specifically, for the HR and payroll modules, the standard data types associated to personal data main records are the following: Data type EML Description Employee Id Commenté [GC9]: As I have understood the objective was to provide the list of data types, which allow to identify a person. I am not sure to understand how to use this list of fields. And fields, contents and location: Table Description Field Description Data Type REFNUM Employee ID EML SRN First name A NAM Name A CIV Title C PSD Known as NAM DATBRN Date of birth D EMPPIC Photo ABB Image file SEX Gender M NTT Nationality Code CRY CRYNAM Country name NCY CTYBRN Municipality A EMPLOID Civil status ADD1/ADD2/ADD3 Address ADL CTY City CTY CODPOS Postal Code POS TEL Telephone TEL MOB Mobile phone TEL FAX Fax TEL EML A NAMCNT Person of contact: Name NAM SRNCNT Person of contact: First name NAM TELCNT Person of contact: Telephone TEL MOBCNT Person of contact: Mobile phone TEL EMLCNT Person of contact: A CHDNAM Name A EMPLOCHD Children CHDSRN First Name A CHDSEX Gender M DATCHDBRN Date of Birth D SSITFAM Marital Status C SJNTREFNUM Spouse's registration number MAT EMPLOJNT Spouses (>1) SJNTNAM Spouse's name A SJNTSRN First name A SJNTDATBRN Date of birth D SJNTTEL Telephone TEL EMPLOAD Administrative information FLGHDC Disabled worker M HDC Handicap rate DCB EMPLORIB Bank ID statement BIDNUM Bank ID number BID EMPLOMED Medical examinations MEDDCT Doctor A Commenté [MJ10R9]: This is only used for the data search function that is not available yet, however I don t think it should be removed from the document. GDPR * Page 16 of 20

17 Fields for France legislation only: Table Description Field Description CTYBRNSEE Federal ID code DEPBRN Department EMPLOID Civil status NUMSSC Social Security no. CODUE EU coding CODSEE Federal ID code EMPLOCHD Children NUMSSEBNF1 NIR Fields for Portuguese legislation only: Table Description Field Description EMPLOID Civil status NUMSSC Social Security no. EMPTAXNBR Tax identification FORTAXNBR Foreign tax ID EMPLOIDPOR Civil status IDNBR Identification no. PLCRGT Registration EXPDAT Expiration date Security principles To minimise the risk of data breaches and related penalties some elementary security principles are advisable. For version 9 please refer to the documentation available for more details: o o Technology and Architecture Overview document for this version; The Online help for more details for Security, Security Best Practices and Data Security on the platform module. Main principles Security was a strong focus in the design and development of Sage X3. The solution was audited and certified by a third-party for safe operation in the Cloud. Sage X3 supports external identity providers like LDAP, Oauth2 (Google and Microsoft Live accounts) and Sage ID. This improves security by offloading the management of user credentials, and also improves the user experience by providing a Single Sign-On (SSO) experience. User credentials do not transit through the ERP when integrated with Oauth2 identity providers or with Sage ID. In addition, communications with the various client components can be GDPR * Page 17 of 20

18 secured with HTTPS, and communications between server-side components are authenticated with certificates. GDPR * Page 18 of 20

19 Information on every page load. As the URL can contain data (customer ID, order number for example), sanitization rules based on regular expressions are defined in the configuration file. This ensures that no personal data is sent to pendo even if activated. By default, the rules used perform the following sanitization: Sage Legal Disclaimer o Host and port are removed from URL The information contained in this guide is for general guidance purposes only. It should not o Function, classes and representations segments are sent to identify the use case be taken for, nor is it intended as, legal advice. We would like to stress that there is no substitute o for Report customers codes, making statistical their codes, own detailed landing investigations page names or are seeking not sent their but own replaced legal by advice if they STAT, are unsure QUERY, about home. the implications of the GDPR on their businesses. While we have made o every No data effort segment to ensure is sent that the information provided in this guide is correct and up to date, Sage makes no promises as to completeness or accuracy and the information is delivered on an as is basis without any warranties, express or implied. Sage will not accept any liability for errors or omissions and will not be liable for any damage (including, without limitation, damage for loss of business or loss of profits) arising in contract, tort or otherwise from the use of or reliance on this information or from any action or decisions taken as a result of using this information. GDPR * Page 19 of 20

20 The Sage Group plc or its licensors. All rights reserved. Sage, Sage logos, and Sage product and service names mentioned herein are the trademarks of The Sage Group plc or its licensors. All other trademarks are the property of their respective owners.

SCHOOL SUPPLIERS. What schools should be asking!

SCHOOL SUPPLIERS. What schools should be asking! SCHOOL SUPPLIERS What schools should be asking! Page:1 School supplier compliance The General Data Protection Regulation (GDPR) comes into force on 25 May 2018 and will be applied into UK law via the updated

More information

GDPR Workflow White Paper

GDPR Workflow White Paper White Paper The European Union is implementing new legislation with the objective of protecting personal data of citizens within the EU and giving them more control over how their data is used. Hefty fines

More information

GDPR: A QUICK OVERVIEW

GDPR: A QUICK OVERVIEW GDPR: A QUICK OVERVIEW 2018 Get ready now. 29 June 2017 Presenters Charles Barley Director, Risk Advisory Services Charles Barley, Jr. is responsible for the delivery of governance, risk and compliance

More information

WEBSITE PRIVACY POLICY

WEBSITE PRIVACY POLICY WEBSITE PRIVACY POLICY INTRODUCTION Welcome to the Octopus Group s privacy policy ( Privacy Policy ) Octopus Group respects your privacy and is committed doing the right thing when it comes to protecting

More information

2. Who we collect information (data) from & why we collect it

2. Who we collect information (data) from & why we collect it 1. Introduction Our Privacy Policy applies to the personal data that Ambrey collects and uses. References in this Privacy Policy to Ambrey, we, us or our mean Ambrey Limited and the Ambrey Group of companies:

More information

About Mark Bullock & Company Chartered Surveyors

About Mark Bullock & Company Chartered Surveyors Privacy Policy Updated 28th November, 2018 By continuing to use this site you a) agree to us providing to you the information you have requested and b) confirm that you have read and agree to the use of

More information

GDPR RECRUITMENT POLICY

GDPR RECRUITMENT POLICY > General characteristics Company Credendo Export Credit Agency Date 12/12/2018 Version 1.2 Classification Public Status Final Document reference GDPR Recruitment Policy Revision frequency Ad hoc Document

More information

Security Information for SAP Asset Strategy and Performance Management

Security Information for SAP Asset Strategy and Performance Management Master Guide SAP Asset Strategy and Performance Management Document Version: 1.0 2017-11-30 Security Information for SAP Asset Strategy and Performance Management Typographic Conventions Type Style Example

More information

Sage Construction Central Setup Guide (Version 18.1)

Sage Construction Central Setup Guide (Version 18.1) Sage 300 Construction and Real Estate Sage Construction Central Setup Guide (Version 18.1) Certified course curriculum Important Notice The course materials provided are the product of Sage. Please do

More information

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES Forum financier du Brabant wallon 14.12.2017 Data Protection should be part of every company s or organisation s DNA Do you process

More information

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready? European Union (EU) General Data Protection Regulation (GDPR) Do you handle EU residents personal data? The GDPR update is coming May 25, 2018. Are you ready? What do you need to do? Governance and Accountability

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) a. General Data Protection... 2 b. IT systems compliance... 2 c. Employee awareness... 2 d. Information we hold... 3 e. Data flow & Data sharing... 4 f. Data Accuracies

More information

Website privacy policy

Website privacy policy Website privacy policy Introduction Welcome to the Octopus Group s privacy policy ( Privacy Policy ) Octopus Group respects your privacy and is committed doing the right thing when it comes to protecting

More information

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk CURTIS BANKS LIMITED Privacy Information Notice curtisbanks.co.uk Contents Section Page 1 Who we are 3 2 Why we need to collect, use and process personal information 3 3 The information we may collect,

More information

Oracle Risk Management Cloud

Oracle Risk Management Cloud Oracle Risk Management Cloud Release 12 New Feature Summary December 2016 TABLE OF CONTENTS REVISION HISTORY... 3 COMMON TECHNOLOGIES... 4 APPLICATIONS SECURITY... 4 User Account Management... 5 Administrator

More information

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions General Data Protection Regulation Frequently Asked Questions (FAQ) This document addresses some of the frequently asked questions regarding the General Data Protection Regulation (GDPR), which goes into

More information

PRIVACY NOTICE (TIER 4)

PRIVACY NOTICE (TIER 4) Page: 1 of 6 1. Scope All data subjects whose personal data is collected, in line with the requirements of the GDPR. 2. Responsibilities 2.1 The Data Protection Officer / GDPR Owner is responsible for

More information

GDPR Compliance. Clauses

GDPR Compliance. Clauses 1 Clauses GDPR The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a privacy and data protection regulation in the European Union (EU). It became enforceable from May 25 2018. The

More information

Data Protection and GDPR

Data Protection and GDPR Data Protection and GDPR At DPDgroup UK Ltd (DPD & DPD Local) we take data protection seriously and have updated all our relevant policies and documents to ensure we meet the requirements of GDPR. We have

More information

PS Mailing Services Ltd Data Protection Policy May 2018

PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Ltd Data Protection Policy May 2018 PS Mailing Services Limited is a registered data controller: ICO registration no. Z9106387 (www.ico.org.uk 1. Introduction 1.1. Background We collect

More information

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe Respecting Privacy, Securing Data and Enabling Trust a view from Europe Robert Bond, Partner & Notary Public Robert Bond Robert Bond has nearly 40 years' experience in advising national and international

More information

Please let us know if you have any questions regarding this Policy either by to or by telephone

Please let us know if you have any questions regarding this Policy either by  to or by telephone Our Privacy Policy At Torbay Fishing we are committed to protecting and preserving the privacy of our customers when visiting us, visiting our website or communicating (electronically or verbally) with

More information

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings:

PRIVACY POLICY. 1. Definitions and Interpretation In this Policy the following terms shall have the following meanings: PRIVACY POLICY BACKGROUND: Leaman Mattei Limited (LM) understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone

More information

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to Suzanne Dibble 2018. Copyright in this document belongs to Suzanne Dibble. You may not copy or use it for any purpose unless you have purchased this template document from Suzanne Dibble. You may not allow

More information

GDPR compliance: some basics & practical to do list

GDPR compliance: some basics & practical to do list GDPR compliance: some basics & practical to do list Philippe LAURENT independent full service business law firm located in Brussels May 2017 Personal data processing = any operation or set of operations

More information

General Data Protection Regulation for ecommerce. Reach Digital - 18 december 2017

General Data Protection Regulation for ecommerce. Reach Digital - 18 december 2017 General Data Protection Regulation for ecommerce Reach Digital - 18 december 2017 GDPR for ecommerce This document is intended to determine the recommendations and responsibilities for an ecommerce merchant

More information

Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR )

Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR ) Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR ) May 2018 Document Classification Public Q&A for Citco Fund Services clients in relation to The General Data Protection

More information

Subject Access Request Form

Subject Access Request Form Subject Access Request Form The General Data Protection Regulations (GDPR) provides you, the data subject, with a right to receive a copy of the data /information we hold about you or to authorise someone

More information

Accelerate GDPR compliance with the Microsoft Cloud

Accelerate GDPR compliance with the Microsoft Cloud Regional Forum on Cybersecurity in the Era of Emerging Technologies & the Second Meeting of the Successful Administrative Practices -2017 Cairo, Egypt 28-29 November 2017 Accelerate GDPR compliance with

More information

Getting ready for GDPR. Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions

Getting ready for GDPR. Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions Getting ready for GDPR Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions GDPR Background Single EU-wide Regulation Harmonizes Global User Data Protection across

More information

Eco Web Hosting Security and Data Processing Agreement

Eco Web Hosting Security and Data Processing Agreement 1 of 7 24-May-18, 11:50 AM Eco Web Hosting Security and Data Processing Agreement Updated 19th May 2018 1. Introduction 1.1 The customer agreeing to these terms ( The Customer ), and Eco Web Hosting, have

More information

TIA. Privacy Policy and Cookie Policy 5/25/18

TIA. Privacy Policy and Cookie Policy 5/25/18 TIA Privacy Policy and Cookie Policy 5/25/18 Background: TIA understands that your privacy is important to you and that you care about how your information is used and shared online. We respect and value

More information

Google Cloud & the General Data Protection Regulation (GDPR)

Google Cloud & the General Data Protection Regulation (GDPR) Google Cloud & the General Data Protection Regulation (GDPR) INTRODUCTION General Data Protection Regulation (GDPR) On 25 May 2018, the most significant piece of European data protection legislation to

More information

1. Muscat & Co Mortgage Solutions Ltd - Privacy Notice

1. Muscat & Co Mortgage Solutions Ltd - Privacy Notice 1. This Muscat & Co Mortgage Solutions Ltd privacy notice provides information on how we and any of our subsidiaries, and any 3 rd party providers collect, use, secure, transfer and share your information.

More information

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH

Project Better Energy Limited s registered office is Witan Gate House, Witan Gate West, Milton Keynes, Buckinghamshire, MK9 1SH PRIVACY NOTICE Curv360 is a part of the Project Better Energy Limited group of companies and is a controller of any personal data you provide. We respect your data and your privacy is important to us.

More information

UWC International Data Protection Policy

UWC International Data Protection Policy UWC International Data Protection Policy 1. Introduction This policy sets out UWC International s organisational approach to data protection. UWC International is committed to protecting the privacy of

More information

MiContact Center Business Important Product Information for Customer GDPR Compliance Initiatives

MiContact Center Business Important Product Information for Customer GDPR Compliance Initiatives MiContact Center Business Important Product Information for Customer GDPR Compliance Initiatives MITEL SOLUTIONS ENGINEERING MiContact Center Business Release 9.0 Version 1 May 2018 NOTICE The information

More information

Sparta Systems TrackWise Digital Solution

Sparta Systems TrackWise Digital Solution Systems TrackWise Digital Solution 21 CFR Part 11 and Annex 11 Assessment February 2018 Systems TrackWise Digital Solution Introduction The purpose of this document is to outline the roles and responsibilities

More information

GDPR Policy WECare Worldwide

GDPR Policy WECare Worldwide GDPR Policy WECare Worldwide MAY 2018 GDPR policy, WECare Worldwide WECare 1 WECare Worldwide s commitment to GDPR WECare Worldwide ( WECare ) is both a UK registered charity (1162386) and a Sri Lankan

More information

Privacy Policy GENERAL

Privacy Policy GENERAL Privacy Policy GENERAL This document sets out what information Springhill Care Group Ltd collects from visitors, how it uses the information, how it protects the information and your rights. Springhill

More information

GETTING STARTED GUIDE. Mobile Admin. Version 8.2

GETTING STARTED GUIDE. Mobile Admin. Version 8.2 GETTING STARTED GUIDE Mobile Admin Version 8.2 Last Updated: April 24, 2018 GETTING STARTED GUIDE: MOBILE ADMIN 2018 SolarWinds Worldwide, LLC. All rights reserved. This document may not be reproduced

More information

In this Policy the following terms shall have the following meanings:

In this Policy the following terms shall have the following meanings: NJR TRADING LTD understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of everyone who visits this website, https://bar-tonic.

More information

What's New in P6 Professional Release 8.2 December 2011 Copyright Oracle Primavera What's New in P6 Professional Copyright 1999, 2011, Oracle and/or its affiliates. All rights reserved. Oracle and Java

More information

M T BUCKLEY & Co Chartered Accountants

M T BUCKLEY & Co Chartered Accountants M T BUCKLEY & Co Chartered Accountants 2 Beulah Walk, Woldingham, Caterham, Surrey CR3 7LL Telephone: 01883 650420 Mobile: 07876 030622 1. PURPOSE OF THIS POLICY PRIVACY POLICY This policy describes how

More information

Arkadin Data protection & privacy white paper. Version May 2018

Arkadin Data protection & privacy white paper. Version May 2018 Arkadin Data protection & privacy white paper Version May 2018 Table of Contents 1- About Arkadin 4 2- Objectives 6 3- What does the GDPR cover? 8 4- What does the GDPR require? 10 5- Who are the data

More information

GDPR Processor Security Controls. GDPR Toolkit Version 1 Datagator Ltd

GDPR Processor Security Controls. GDPR Toolkit Version 1 Datagator Ltd GDPR Processor Security Controls GDPR Toolkit Version 1 Datagator Ltd Implementation Guidance (The header page and this section must be removed from final version of the document) Purpose of this document

More information

General Data Protection Regulation (GDPR) and the Implications for IT Service Management

General Data Protection Regulation (GDPR) and the Implications for IT Service Management General Data Protection Regulation (GDPR) and the Implications for IT Service Management August 2018 WHITE PAPER GDPR: What is it? The EU General Data Protection Regulation (GDPR) replaces the Data Protection

More information

About the P6 EPPM Importing and Exporting Guide

About the P6 EPPM Importing and Exporting Guide P6 EPPM Importing and Exporting Guide October 2018 Contents About the P6 EPPM Importing and Exporting Guide Scope This guide contains information about import and export formats and the process of importing

More information

Data Subject Access Request Form (GDPR)

Data Subject Access Request Form (GDPR) Data Subject Access Request Form (GDPR) Data Subject Access Request Form Article 15 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) grants you the right to access your personal

More information

Personal Data collected for the following purposes and using the following services:

Personal Data collected for the following purposes and using the following services: PRIVACY POLICY www.marquise-tech.com This Website collects some Personal Data from its Users. POLICY SUMMARY Personal Data collected for the following purposes and using the following services: Contacting

More information

Care Recruitment Matters Limited Privacy Notice

Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited Privacy Notice Care Recruitment Matters Limited (CRM) is a specialist recruitment agency, sourcing permanent candidates for companies focused in the Health and Social Care

More information

Data Processing Agreement DPA

Data Processing Agreement DPA Data Processing Agreement DPA between Clinic Org. no. «Controller». and Calpro AS Org. nr. 966 291 281. «Processor» If the parties have executed a Data Management Agreement, the Date Management Agreement

More information

VERSION 1.3 MAY 1, 2018 SNOWFLY PRIVACY POLICY SNOWFLY PERFORMANCE INC. P.O. BOX 95254, SOUTH JORDAN, UT

VERSION 1.3 MAY 1, 2018 SNOWFLY PRIVACY POLICY SNOWFLY PERFORMANCE INC. P.O. BOX 95254, SOUTH JORDAN, UT VERSION 1.3 MAY 1, 2018 SNOWFLY PRIVACY POLICY SNOWFLY PERFORMANCE INC. P.O. BOX 95254, SOUTH JORDAN, UT 84095-9998 SNOWFLY PRIVACY POLICY This Privacy Policy describes Snowfly s practices regarding the

More information

Mobile Admin GETTING STARTED GUIDE. Version 8.2. Last Updated: Thursday, May 25, 2017

Mobile Admin GETTING STARTED GUIDE. Version 8.2. Last Updated: Thursday, May 25, 2017 GETTING STARTED GUIDE Mobile Admin Version 8.2 Last Updated: Thursday, May 25, 2017 Retrieve the latest version from: https://support.solarwinds.com/success_center/mobile_admin/mobile_admin_documentation

More information

DCU Guide to Subject Access Requests. Under Irish Data Protection Legislation

DCU Guide to Subject Access Requests. Under Irish Data Protection Legislation DCU Guide to Subject Access Requests Under Irish Data Protection Legislation Context Under section 4 of the Irish Data Protection Acts 1988 & 2003 an individual, on making a written request to DCU, may

More information

Sage Hibernia Limited Copyright Statement

Sage Hibernia Limited Copyright Statement Sage Hibernia Limited Copyright Statement Sage Hibernia Limited, 2010. All rights reserved If this documentation includes advice or information relating to any matter other than using Sage software, such

More information

Meeting GDPR requirements in your S2 Security environment

Meeting GDPR requirements in your S2 Security environment white paper Meeting GDPR requirements in your S2 Security environment May 2018 What is GDPR? The European Union s General Data Protection Regulation (GDPR) takes effect May 25, 2018 and applies to all

More information

Introductory guide to data sharing. lewissilkin.com

Introductory guide to data sharing. lewissilkin.com Introductory guide to data sharing lewissilkin.com Executive Summary Most organisations carry out some form of data sharing, whether it be data sharing between organisations within the group or with external

More information

Data Subject Data Portability Request Form

Data Subject Data Portability Request Form Data Subject Data Portability Request Form Article 20 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) grants you the right to receive a copy of certain personal data held

More information

GDPR compliance. GDPR preparedness with OpenText InfoArchive. White paper

GDPR compliance. GDPR preparedness with OpenText InfoArchive. White paper White paper GDPR preparedness with OpenText InfoArchive The new EU privacy law, GDPR, will be in effect in less than a year. OpenText has the solutions to help you prepare and comply to this new law. Contents

More information

The Role of the Data Protection Officer

The Role of the Data Protection Officer The Role of the Data Protection Officer Adrian Ross LLB (Hons), MBA GRC Consultant IT Governance Ltd 28 July 2016 www.itgovernance.co.uk Introduction Adrian Ross GRC consultant Infrastructure services

More information

Data protection declaration

Data protection declaration Data protection declaration The following information describes the service provider's data processing and data usage guidelines for entertainment products by the Aeria Games GmbH, henceforth to be referred

More information

Oracle Financial Consolidation and Close Cloud. What s New in the November Update (16.11)

Oracle Financial Consolidation and Close Cloud. What s New in the November Update (16.11) Oracle Financial Consolidation and Close Cloud What s New in the November Update (16.11) November 2016 TABLE OF CONTENTS REVISION HISTORY... 3 ORACLE FINANCIAL CONSOLIDATION AND CLOSE CLOUD, NOVEMBER UPDATE...

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) BCD Travel s Response to the EU General Data Protection Regulation (GDPR) November 2017 Page 1 Response to the EU GDPR Copyright 2017 by BCD Travel N.V. All rights reserved. November 2017 Copyright 2017

More information

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR) Michael Eva, London Grid for Learning What is GDPR? General Data Protection Regulation (GDPR) protects the personal data of EU citizens regardless of where the

More information

FIRSTBEAT TECHNOLOGIES OY DESCRIPTION OF PERSONAL DATA PROCESSING FOR PARTNERS - FIRSTBEAT LIFESTYLE ASSESSMENT

FIRSTBEAT TECHNOLOGIES OY DESCRIPTION OF PERSONAL DATA PROCESSING FOR PARTNERS - FIRSTBEAT LIFESTYLE ASSESSMENT FIRSTBEAT TECHNOLOGIES OY DESCRIPTION OF PERSONAL DATA PROCESSING FOR PARTNERS - FIRSTBEAT LIFESTYLE ASSESSMENT Description of personal data processing in the Firstbeat Lifestyle Assessment service of

More information

Online Statements Disclosure

Online Statements Disclosure Online Statements Disclosure Rev. 04/30/13 DEFINITIONS "We", "Our", "Us" or "The Bank" mean Central Pacific Bank. "You" and "your" mean the account owner(s) authorized by the Bank to receive account statements

More information

Just-Property Ltd GDPR Client Data Register

Just-Property Ltd GDPR Client Data Register GDPR Client Data Register Company Name Contact Justin Coughlan Role Managing Director Email jcoughlan@just-property.ie Contact number 01 631 52 51 1. Point of Contact with responsibility for Data Protection

More information

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018

ma recycle GDPR Privacy Policy .com Rely and Comply... Policy Date: 24 May 2018 ma recycle.com Rely and Comply... GDPR Privacy Policy Policy Date: 24 May 2018 Max Recycle Hawthorne House Blackthorn Way Sedgeletch Industrial Estate Fencehouses Tyne & Wear DH4 6JN T: 0845 026 0026 F:

More information

Data Processing Agreement

Data Processing Agreement In accordance with the European Parliament- and Council s Directive (EU) 2016/679 of 27th April 2016 (hereinafter GDPR) on the protection of physical persons in connection with the processing of personal

More information

Made In Hackney Data Protection Policy Last Updated:

Made In Hackney Data Protection Policy Last Updated: Made In Hackney Data Protection Policy Last Updated: 16.05.2018 Definitions Charity GDPR Responsible Person Register of Systems Made In Hackney (MIH), a registered charity. means the General Data Protection

More information

PRIVACY POLICY. What personal data we collect and why we collect it IN ORDER TO: (Date of last update: 1 st January 2019)

PRIVACY POLICY. What personal data we collect and why we collect it IN ORDER TO: (Date of last update: 1 st January 2019) PRIVACY POLICY (Date of last update: 1 st January 2019) For the purpose of the Data Protection Act 1998 (the Act) and from the 25 May 2018, the EU General Data Protection Regulation 2016/679 (the GDPR),

More information

Disruptive Technologies Legal and Regulatory Aspects. 16 May 2017 Investment Summit - Swiss Gobal Enterprise

Disruptive Technologies Legal and Regulatory Aspects. 16 May 2017 Investment Summit - Swiss Gobal Enterprise Disruptive Technologies Legal and Regulatory Aspects 16 May 2017 Investment Summit - Swiss Gobal Enterprise Legal and Regulatory Framework in Switzerland Legal and regulatory Framework: no laws or provisions

More information

Archive Legislation: archiving in the United Kingdom. The key laws that affect your business

Archive Legislation:  archiving in the United Kingdom. The key laws that affect your business Archive Legislation: Email archiving in the United Kingdom The key laws that affect your business Contents Laws regulating archiving, who they apply to and the penalties 3 Who is affected? 3 All private

More information

Wonde may collect personal information directly from You when You:

Wonde may collect personal information directly from You when You: Privacy Policy Updated: 17th April 2018 1. Scope At Wonde, we take privacy very seriously. We ve updated our privacy policy ( Policy ) to ensure that we communicate to You, in the clearest way possible,

More information

Depending on the Services or information you request from us, we may ask you to provide the following personal information:

Depending on the Services or information you request from us, we may ask you to provide the following personal information: LINK HUNGARY PRIVACY POLICY PROTECTING YOUR DATA 1. Who are Link Asset Services and Link Hungary? Link Asset Services ( Link ) is a trading name of companies which offer a range of services, principally

More information

Migration Best Practices for Oracle Access Manager 10gR3 deployments O R A C L E W H I T E P A P E R M A R C H 2015

Migration Best Practices for Oracle Access Manager 10gR3 deployments O R A C L E W H I T E P A P E R M A R C H 2015 Migration Best Practices for Oracle Access Manager 10gR3 deployments O R A C L E W H I T E P A P E R M A R C H 2015 Disclaimer The following is intended to outline our general product direction. It is

More information

Vistra International Expansion Limited PRIVACY NOTICE

Vistra International Expansion Limited PRIVACY NOTICE Effective Date: from 25 May 2018 Vistra International Expansion Limited PRIVACY NOTICE This Privacy Notice explains how particular companies in the Vistra Group collect, use and disclose your personal

More information

Data Controller and Owner. Types of Data collected. Mode and place of processing the Data. Privacy Policy of aimedis.com. Methods of processing

Data Controller and Owner. Types of Data collected. Mode and place of processing the Data. Privacy Policy of aimedis.com. Methods of processing Privacy Policy of aimedis.com This Application collects some Personal Data from its Users. Data Controller and Owner Aimedis B.V., Sint Michaëlstraat 4, 5935 BL Steyl, Netherlands Owner contact email:

More information

Element Finance Solutions Ltd Data Protection Policy

Element Finance Solutions Ltd Data Protection Policy Element Finance Solutions Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

Motorola Mobility Binding Corporate Rules (BCRs)

Motorola Mobility Binding Corporate Rules (BCRs) Motorola Mobility Binding Corporate Rules (BCRs) Introduction These Binding Privacy Rules ( Rules ) explain how the Motorola Mobility group ( Motorola Mobility ) respects the privacy rights of its customers,

More information

April Understanding Federated Single Sign-On (SSO) Process

April Understanding Federated Single Sign-On (SSO) Process April 2013 Understanding Federated Single Sign-On (SSO) Process Understanding Federated Single Sign-On Process (SSO) Disclaimer The following is intended to outline our general product direction. It is

More information

PRIVACY POLICY OF THE WEB SITE

PRIVACY POLICY OF THE WEB SITE PRIVACY POLICY OF THE ERANOS FOUNDATION Introductory remarks The Eranos Foundation respects your privacy! Privacy policy EU Norm 2016-769 GDPR 1 We do not sell or distribute any information that we acquire

More information

A practical guide to using ScheduleOnce in a GDPR compliant manner

A practical guide to using ScheduleOnce in a GDPR compliant manner A practical guide to using ScheduleOnce in a GDPR compliant manner Table of Contents Glossary 2 Background What does the GDPR mean for ScheduleOnce users? Lawful basis for processing Inbound scheduling

More information

MicroStrategy Desktop Quick Start Guide

MicroStrategy Desktop Quick Start Guide MicroStrategy Desktop Quick Start Guide Version: 10.4 10.4, June 2017 Copyright 2017 by MicroStrategy Incorporated. All rights reserved. If you have not executed a written or electronic agreement with

More information

Adaptive Risk Manager Challenge Question Cleanup 10g ( ) December 2007

Adaptive Risk Manager Challenge Question Cleanup 10g ( ) December 2007 Adaptive Risk Manager Challenge Question Cleanup 10g (10.1.4.3.0) December 2007 Adaptive Risk Manager Challenge Question Cleanup, 10g (10.1.4.3.0) Copyright 2007, Oracle. All rights reserved. The Programs

More information

PRIVACY POLICY Last Updated May, 2018

PRIVACY POLICY Last Updated May, 2018 PRIVACY POLICY Last Updated May, 2018 PRIVACY POLICY OVERVIEW This Privacy Policy establishes rules to govern the collection, use and disclosure of personal information collected by Banff & Lake Louise

More information

QNB Bank-ONLINE AGREEMENT

QNB Bank-ONLINE AGREEMENT This is an Agreement between you and QNB Bank ("QNB"). It explains the rules of your electronic access to your accounts through QNB Online. By using QNB-Online, you accept all the terms and conditions

More information

Fabrizio Patriarca. Come creare valore dalla GDPR

Fabrizio Patriarca. Come creare valore dalla GDPR Fabrizio Patriarca Come creare valore dalla GDPR Disclaimer Notice: Clients are responsible for ensuring their own compliance with various laws and regulations, including the European Union General Data

More information

PRIVACY NOTICE. Who we are:

PRIVACY NOTICE. Who we are: PRIVACY NOTICE This privacy notice is effective 22 nd May 2018. Please read the following information carefully as it contains information about what data we collect and store about you and the reason

More information

South Hams Motor Club Our Privacy Policy. How do we collect information from you? What type of information is collected from you?

South Hams Motor Club Our Privacy Policy. How do we collect information from you? What type of information is collected from you? South Hams Motor Club Our Privacy Policy At South Hams Motor Club (SHMC) we are committed to protecting and preserving the privacy of our customers when attending our events, visiting our website or communicating

More information

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY

VIACOM INC. PRIVACY SHIELD PRIVACY POLICY VIACOM INC. PRIVACY SHIELD PRIVACY POLICY Last Modified and Effective as of October 23, 2017 Viacom respects individuals privacy, and strives to collect, use and disclose personal information in a manner

More information

An Oracle White Paper November Primavera Unifier Integration Overview: A Web Services Integration Approach

An Oracle White Paper November Primavera Unifier Integration Overview: A Web Services Integration Approach An Oracle White Paper November 2012 Primavera Unifier Integration Overview: A Web Services Integration Approach Introduction Oracle s Primavera Unifier offers an extensible interface platform based on

More information

What is cloud computing? The enterprise is liable as data controller. Various forms of cloud computing. Data controller

What is cloud computing? The enterprise is liable as data controller. Various forms of cloud computing. Data controller A guide to CLOUD COMPUTING 2014 Cloud computing Businesses that make use of cloud computing are legally liable, and must ensure that personal data is processed in accordance with the relevant legislation

More information

Chronos Fitness, Inc. dba Chronos Wearables, 1347 Green St. San Francisco CA 94109,

Chronos Fitness, Inc. dba Chronos Wearables, 1347 Green St. San Francisco CA 94109, Privacy Policy Of Chronos Wearables This Application collects some Personal Data from its Users. Data Controller and Owner Chronos Fitness, Inc. dba Chronos Wearables, 1347 Green St. San Francisco CA 94109,

More information

Oracle Cloud. Using the Google Calendar Adapter Release 16.3 E

Oracle Cloud. Using the Google Calendar Adapter Release 16.3 E Oracle Cloud Using the Google Calendar Adapter Release 16.3 E68599-05 September 2016 Oracle Cloud Using the Google Calendar Adapter, Release 16.3 E68599-05 Copyright 2015, 2016, Oracle and/or its affiliates.

More information

Deutsche Bank Corporate Banking & Securities. TradeMatch. User Guide.

Deutsche Bank Corporate Banking & Securities. TradeMatch. User Guide. Deutsche Bank Corporate Banking & Securities TradeMatch User Guide http://autobahn.db.com 1 TradeMatch Autobahn is Deutsche Bank s award-winning electronic distribution service. Since 1996, Autobahn has

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Addressing the General Data Protection Regulation (GDPR) 2018 [EU] and the Data Protection Act (DPA) 2018 [UK] For information on this Policy or to request Subject Access please

More information

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th Cisco Spark and GDPR Thomas Flambeaux Collaboration Consulting Solution Engineer, Security and Compliance Cisco Connect 2018 Copenhagen April 12th 2015 Cisco and/or its affiliates. All rights reserved.

More information

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary Aon Client Data Privacy Summary Table of Contents Our Commitment to Data Privacy 3 Our Data Privacy Principles 4 Aon Client Data Privacy Summary 2 Our Commitment to Data Privacy Data Privacy Backdrop As

More information