What is GDPR?
The General Data Protection Regulation, better known as the AVG or GDPR, has been in effect throughout the European Union since May 2018. All companies based in the EU and companies that process data of individuals in the EU must comply with the new rules for the protection of personal data. The rules ensure that companies must be demonstrably more responsible to protect personal data, and that customers have more control over their own data.
The following principles are important for implementation:
- Integrity: Personal data must be protected with appropriate technical and organizational security measures.
- Legality: Organizations must, among other things, ensure that they have a legal basis for processing personal data and that they process this data fairly and transparently.
- Restricted use: Personal information may only be collected for specific, explicit, legitimate purposes.
- Data minimization: Data collection should be limited to only those data that are relevant and necessary for the intended use.
- Accuracy: Personal information must be accurate and up to date.
- Storage limit: Personal information should only be stored for as long as is necessary and reasonable, subject to relevant exceptions.
Under the GDPR, it is very important that you:
- personal data is well protected and only processed for the associated purpose
- demonstrably meets your obligations
- be transparent with your customers and other stakeholders
- makes clear and conclusive agreements with parties that process personal data for you
- takes responsibility for the personal data that you control
- personal data well protected
- respects and facilitates the privacy rights of customers and other stakeholders
Managing and monitoring GDPR
Management System
Why a digital management system for AVG?
Many organizations have already switched from a âhandbook in the closetâ to an environment such as SharePoint or a Document Management System to also be able to view their documentation remotely.
But then these questions and sources of stress linger:
- How do you easily deposit the processing agreement in the organization?
- How are adjustments planned and managed?
- How do I control the quality of the processes such as outsourcing, etc.?
- How do you clearly and easily evaluate the results of the information security?
- How can I easily become aware of AVG in my organization?
- What measures have been or still need to be implemented for risk management of AVG?
- How construction am I simply bearing the burden of proof of the various registrations?
ISO2 HANDLE
Why ISO2HANDLE's management system?
because ISO2 HANDLE tracks, chases and maps everything for you, giving you control and overview and continuously managing the certification in the background.
Our platform helps with all the activities associated with obtaining and maintaining certifications, in all phases from implementation to optimization:
Deploy:
- âUse our GDPR template and customize with the drag & drop editor
- Personalize forms
- Apply workflow schedules so that registrations are automatically forwarded to the right colleague
Adopt:
- Handbook and forms are also accessible via mobile
- Automatic task management keeps track of all pending actions in a clear dashboard
Monitors:
- Dashboards in the blink of an eye with trend & cost analysis
- Track your KPIs
Optimization & Audits:
- Access for Certification Authorities; decide the components and time limit yourself
- Download and share dashboards and reports
Consultancy firms
Partner network of organizational consulting firms
ISO2 HANDLE works for a large number of certification advice agencies in the Netherlands, each with their own expertise and focus. A consultancy firm helps with the customized implementation and provides substantive advice on how the processes surrounding certification seamlessly fit with your organization and way of working. They can also help switch from your current system to ISO2 HANDLE.