Register of Processings Manual Version: Mei 2018

Similar documents
Magento GDPR Frequently Asked Questions

Accelerate GDPR compliance with the Microsoft Cloud

EU GDPR & ISO Integrated Documentation Toolkit integrated-documentation-toolkit

Data Processing Agreement

General Data Protection Regulation (GDPR) Key Facts & FAQ s

SCHOOL SUPPLIERS. What schools should be asking!

Getting ready for GDPR. Philipp Hobler EMEA Field CTO Global Technology Office Dell EMC Data Protection Solutions

UWTSD Group Data Protection Policy

Google Cloud & the General Data Protection Regulation (GDPR)

EU Data Protection Triple Threat for May of 2018 What Inside Counsel Needs to Know

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

General Data Protection Regulation (GDPR) and the Implications for IT Service Management

PRIVACY POLICY OF THE WEB SITE

EU GDPR and . The complete text of the EU GDPR can be found at What is GDPR?

Creative Funding Solutions Limited Data Protection Policy

COMPUTAMATRIX LIMITED T/A MATRICA Data Protection Policy September Table of Contents. 1. Scope, Purpose and Application to Employees 2

1. Right of access. Last Approval Date: May 2018

Element Finance Solutions Ltd Data Protection Policy

The Role of the Data Protection Officer

Privacy Policy. You may exercise your rights by sending a registered mail to the Privacy Data Controller.

Technical Requirements of the GDPR

Cybersecurity Considerations for GDPR

Data Protection Policy

DATA PROTECTION POLICY THE HOLST GROUP

General Data Protection Regulation (GDPR) The impact of doing business in Asia

You will see lots of references in the Checklist to the GDPR Pack if you would like to purchase this, go to

EU GDPR: The General Data Protection Regulation

ACCOUNTING TECHNICIANS IRELAND DATA PROTECTION POLICY GENERAL DATA PROTECTION REGULATION

PRIVACY POLICY Last Updated May, 2018

Knowing and Implementing the GDPR Part 3

PRIVACY POLICY QUICK GUIDE TO CONTENTS

Changing times in Swiss Data Privacy: new opportunities? Microsoft Security Day 27 April 2017 Clara-Ann Gordon

GDPR: A GUIDE TO READINESS

BIOEVENTS PRIVACY POLICY

Embedding GDPR into the SDLC. Sebastien Deleersnyder Siebe De Roovere

AMCs and. Does the new law apply to my organization?

PS Mailing Services Ltd Data Protection Policy May 2018

GDPR and the Privacy Shield

What options NETIM offers, including those related to gaining of access to and updating of information.

Embedding GDPR into the SDLC

EU General Data Protection Regulation (GDPR) Achieving compliance

Smart Software Licensing tools and Smart Account Management Privacy DataSheet

Fluid Metering, Inc. Privacy Policy

Our Data Protection Officer is Andrew Garrett, Operations Manager

General Data Protection Regulation (GDPR)

Blue Alligator Company Privacy Notice (Last updated 21 May 2018)

The Apple Store, Coombe Lodge, Blagdon BS40 7RG,

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

Privacy Policy of

GDPR compliance: some basics & practical to do list

PREPARING FOR THE GDPR AT THE UNIVERSITY OF HELSINKI

Fishers Green Sailing Club Privacy Policy

Legal basis of processing. Place MODE AND PLACE OF PROCESSING THE DATA

The GDPR Are you ready?

Nexus Education Schools Trust. Subject Access Request Procedures

BHBIA New Data Protection Rules. Pharma Company Perspective. Guy Murray Director, Market Research & Analytics, GC&BI MR Operations and Compliance, MSD

Privacy policy SIdP website EU 2016/679

Haaga-Helia University of Applied Sciences Privacy Notice for JUSTUS publication data storage service

GDPR: A QUICK OVERVIEW

Please let us know if you have any questions regarding this Policy either by to or by telephone

General Data Protection Regulation (GDPR)

EY s data privacy service offering. How to transform your data privacy capabilities for an EU General Data Protection Regulation (GDPR) world

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

GDPR Compliance. Clauses

EXAM PREPARATION GUIDE

General Data Protection Regulation (GDPR) NEW RULES

Vistra International Expansion Limited PRIVACY NOTICE

To make that choice, please click under privacy policy the checkbox (

PRIVACY POLICY BACKGROUND:

User Manual - Contractors

Sarri Gilman Privacy Policy

GENERAL DATA PROTECTION REGULATION (GDPR) CLIENT INFORMATION GENERAL DATA PROTECTION REGULATION CLIENT INFORMATION

VERSION 1.3 MAY 1, 2018 SNOWFLY PRIVACY POLICY SNOWFLY PERFORMANCE INC. P.O. BOX 95254, SOUTH JORDAN, UT

DEPARTMENT OF JUSTICE AND EQUALITY. Data Protection Policy

THE NEW GENERAL DATA PROTECTION REGULATION IMPLICATIONS FOR ENTERPRISES. Forum financier du Brabant wallon

Priv ac y Policy. Last upda ted:

GRANTS AND CONTRIBUTIONS ONLINE SERVICES USER GUIDE: CANADA SUMMER JOBS

AUTOTASK ENDPOINT BACKUP (AEB) SECURITY ARCHITECTURE GUIDE

PRIVACY POLICY. What personal data we collect and why we collect it IN ORDER TO: (Date of last update: 1 st January 2019)

PRIVACY STATEMENT +41 (0) Rue du Rhone , Martigny, Switzerland.

DISCLOSURE PURSUANT TO ART. 13 EU REGULATION No. 2016/679 (GDPR) Customers and prospects

VISTRA (CYPRUS) LTD. PRIVACY NOTICE

RVC DATA PROTECTION POLICY

Nexus Education Schools Trust. Subject Access Request Procedures

GDPR- the new General Data Protection Regulations. Staff PDM- 2 nd May 2018

Martijn Loderus. Merritt Maxim. Principal Analyst Forrester. Director & Global Practice Partner for Advisory Consulting Janrain

Privacy Policy: itsme APP

General Data Protection Regulation Frequently Asked Questions (FAQ) General Questions

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

THE GDPR PCLOUD'S ROAD TO FULL COMPLIANCE

Privacy Policy. In this data protection declaration, we use, inter alia, the following terms:

General Data Protection Regulation (GDPR)

Privacy by Design and the GDPR

IMPACT OF INTERNATIONAL PRIVACY REGULATIONS. Michelle Caswell, Coalfire Julia Jacobson, K&L Gates

Haaga-Helia University of Applied Sciences Privacy Notice for Urkund Plagiarism Detection Software

VISTRA NETHERLANDS PRIVACY NOTICE

Privacy Policy May 2018

Using My Personal Data

Emsi Privacy Shield Policy

Transcription:

Register of Processings Manual Version: 1.0 28 Mei 2018 This manual should help you register your processing. By law the University has to have a register of all personal data processing. This tool provides the DPO-team the necessary overview. 1. Data Controller Most of the processings for research are carried out under the responsibility of the UT. If you collect and process the personal data yourself or use the results for your own purposes, choose Yes. If another party decides your purposes and tells you how to process the data, choose No and enter the Name of the organization. 2. Contact Information Who should be contacted when the DPO has questions? This is most likely your own information or maybe your supervisors information. The contact person is always an employee of the UT. 3. Processor If there is a 3 rd party involved, handling on behalf of the UT, then this 3 rd party is a processor. This 3 rd party can be a person (often Self-employed without employees) or another organization. A processor is not a person or organization working with the data, so do not enter all project members here or all people that have access! Example of processors are hosting providers, external (cloud) tools that are used in your project (for example surveys), etc. This is often misunderstood, contact your PCP for more information when in doubt. Most research projects don t have a processor! Partners in your project (or their personnel) are most likely (co-)- controller and not processor.

If there is no processor click the Remove button (default number of processors = 1, removing the first (empty) entry sets the number of processors to 0). If you don t remove the processor the tool will warn you about mandatory fields when you save the information. At that moment it is still possible to remove the processor. 4 Description and lawfulness of processing For the name of the processing the name of your project is sufficient. Give it a clear name that is easily recognizable and distinct, so research for my promotion is not a useful name. For research the legal base is often Consent of the person concerned. If asking consent is a problem, contact your Privacy Contact Person.

5 Purpose of the personal data processing State here what the purpose of the processing is and be concise. It should be clear from the purpose why you need the specific personal data that you process. If there is no relation between the purpose and the data you collect, the processing is unlawful. The data collected can only be used for the detailed purpose you state here. So Research is too broad and by law not acceptable as a purpose. 6 Which personal data are included in the processing? See the text in the application.

7 Transfer of personal data Here you can enter the parties that use the data under your control. This is the processor (question 3) or any other party (for example the partners in the project) that uses the personal data. Statistical and anonymized data is outside the scope of the GDPR. The transfer of that kind of data should not be mentioned here. 8 Security of personal data The security of personal data is very important. You should address this in your Data Management Plan in detail (More information: https://www.utwente.nl/en/lisa/researchsupport/). To prevent you describing the security in detail twice, only some superficial questions are asked here.

For High-risk projects (with respect to personal data) the PCP can help you with the Data Management Plan. 9 Transfers of personal data to third countries outside the European Union The GDPR applies to the countries of the European Union. So transfers outside the European Union need extra safeguards (for example Privacy shield regulation for the United States). If you answer yes here you will probable need help from the Privacy Contact Person. 10 Preliminary Investigation (DPIA) There are three criteria under which you will have to do a DPIA (data protection impact assessment). A systematical and extended judgement of personal aspects of a living person Large-scale processing of special personal data Systematic and large-scale monitoring of public space In practice, this means that a formal privacy impact assessment won t be often needed. When a DPIA is necessary, or when you are in doubt about the necessity, contact the Privacy Contact Person of your faculty. However, even if you don't have to do a DPIA, we advise you to do an inventory of risks, since this will bring to light which measures you can take to secure the personal data.

Statement of approval When you are done, declare that you have provided correct information and click save. Your application will be forwarded to the DPO-team. When it is accepted by them you should receive an automated e-mail. Thank you for registering your processing. If you have any suggestions or questions, contact your Privacy Contact Person. See https://www.utwente.nl/privacy for more information.