Loader
 

Heuckie & GDPR


Heuckie is committed to protecting the data that our customers entrust to us. The General Data Protection Regulation (GDPR) introduces specific requirements that apply to companies established in the EU, or located anywhere in the world when processing personal data in connection with offering their goods or services to persons in the EU.

What is the GDPR?


On May 25, 2018, the General Data Protection Regulation (GDPR) will take effect in the European Union. GDPR governs how both "Data Controllers" and "Data Processors" collect and process "Personal Data" in the EU. Based on well recognized privacy principles of accountability, fairness and transparency, GDPR brings long awaited consistency to data protection in the EU by harmonizing the existing patchwork of national data protection legislation across all EU member countries.

What type of information does the GDPR apply to?


The GDPR applies to all personal data. Personal data means data that can be used to identify an individual.

What rights will individuals have under GDPR?


The GDPR gives expanded protection to individuals and new rights to manage personal data collected about them, including:

  • The right to be informed - Organizations must be transparent in how they are using personal data.
  • The right of access - Individuals have the right to request what information is collected about them and how it is processed.
  • The right of rectification - Individuals have the right to request that their personal data be rectified, or corrected, if it is inaccurate or incomplete.
  • The right to erasure - Also known as 'the right to be forgotten', this right refers to an individual's ability to request deletion or removal of their personal data in certain circumstances.
  • The right to restrict processing - Individuals have a right to request that their data be blocked or suppressed from processing.
  • The right to data portability - Individuals have the right to receive a copy of their personal data for their own use.
  • The right to object - In certain circumstances, individuals are entitled to object to their personal data being used. Such circumstances include use of personal data for direct marketing, historical research or statistical purposes.

Who does the GDPR apply to?


The GDPR applies to all organizations established in the EU and to organizations, whether or not established in the EU, that process personal data of individuals in the EU in connection with either the offering of goods or services or the monitoring of behavior in the EU. Citizenship and residency are irrelevant. “Presence” in the EU is the trigger.

What is the difference between a data processor and data controller?


Data Controller: is responsible for making decisions about the processing of personal data and has a direct relationship with the individual (i.e., when handling employee data, Heuckie acts as the Data Controller.)

Data Processor: processes personal data on behalf of a Data Controller. Importantly, the GDPR significantly changes the level of responsibility and accountability of Data Processors. Under the GDPR, Data Processors have direct liability and are subject to regulatory enforcement and civil actions. The GDPR also imposes statutory obligations related to processing records, data breach notification and erasure of personal data. Notably, when providing products to our customers, Heuckie acts primarily as a Data Processor with respect to personal data collected by customer networks.

How does the GDPR affect policy surrounding data breaches?


The GDPR requires Data Controllers, our customers, to notify relevant Data Protection Authorities (DPAs) within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of impacted data subjects. Data Controllers must also notify impacted data subjects without undue delay when a high risk to rights and freedoms is likely. Data Processors, like Heuckie, must notify Data Controllers of a data breach without undue delay.

Heuckie maintains security incident management policies and procedures, including detailed security incident escalation procedures. If Heuckie becomes aware of any unlawful destruction, loss, alteration or unauthorized disclosure of Customer Data (a “Security Incident”), then Heuckie will notify Customer without undue delay and provide Customer with relevant information about the Security Incident, including the type of customer data involved, the volume of customer data disclosed, the circumstances of the incident, mitigation steps taken, and remedial and preventative action taken.

What has Heuckie been doing in preparation for the GDPR?


Heuckie is dedicated to helping our customers and partners navigate the GDPR by protecting and respecting personal data, no matter where it is collected or processed, and is committed to compliance with applicable regulatory frameworks.

How does a company know if they are compliant with the GDPR?


Currently, there is no certification recognized by the European Commission to demonstrate that a company is in compliance with the GDPR. Companies and institutions that are within scope of the GDPR may choose to demonstrate GDPR readiness through third party certifications, contractual commitments regarding data protection practices, and internal policies and procedures. Heuckie is actively monitoring the development of a recognized certification.