GDPR Security Documentation

As part of the services we provide, our role also includes the comprehensive preparation of customized safety documentation for each client, ensuring that the documentation contains all necessary elements in accordance with Regulation (EU) 2016/ 679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as well as Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments to Certain Acts. To ensure comprehensive and high-quality preparation of the documentation, the following must be performed:

1. An analysis of the current state of personal data protection and identification of all personal data processing operations, which serves as the basis for properly configuring the processes that will ensure compliance with the GDPR. Based on a thorough analysis, we can:

  • map the flow of personal data,
  • identify which categories of personal data you handle (general or sensitive personal data),
  • define all operations you perform with personal data,
  • define third parties to whom personal data is provided, whether based on a contractual relationship or a legal obligation,
  • determine whether you have adequate personal data protection in place, specifically in the areas of physical security, personnel security, and IT security.

2. Preparation of all necessary documentation to ensure compliance with the GDPR, in which we will define all personal data procedures and propose processes to ensure the protection of personal data. This documentation must include:

  • Risk Analysis, which quantifies all possible threats and their impact on personal data protection,
  • Security Policy, which describes the basic security measures necessary to maintain the integrity of personal data,
  • Guidelines to provide direction to individuals who work with personal data. They include a description of procedures for handling personal data in various situations (providing information to data subjects or in the event of security incidents),
  • A customized privacy notice designed to help you inform all data subjects about what personal data you process about them, to whom you disclose it, and what rights data subjects have,
  • Data Processing Agreements, which serve to ensure the protection of personal data when data is provided to another controller for processing. These model agreements are prepared separately for each processor, based on the type of service the processor provides to the controller,
  • All necessary forms, which are tailored to the purpose and processing of personal data (consents, authorizations, records, and others).

Cookies

The use of cookies on websites and in online stores is not governed solely by the GDPR. In Slovakia, cookies are also subject to a separate legal regulation—Act No. 452/2021 Coll. on Electronic Communications (hereinafter the “Electronic Communications Act”), which took effect on February 1, 2022, and replaced the previously applicable Act No. 351/2011 Coll.

In practice, this means that whenever cookies are deployed on a website, compliance must be assessed simultaneouslywith two legal regulations—the Electronic Communications Act (which governs the actual technical storage of and access to information on the user’s terminal device) and the GDPR (which governs the subsequent processing of personal data obtained through cookies).

We provide clients and those interested in modifying and configuring cookies with comprehensive services in this area, consisting of:

  • an analysis of currently used cookies;
  • preparing disclosure requirements;
  • designing a “cookie banner” in accordance with legal requirements;
  • collaborating on the implementation of necessary adjustments to cookie settings on the client’s website.

You can read more about preparing security documentation in the service GDPR Security Documentation at TRC: Link

 

Are you interested in this service?