GDPR

General Data Protection Regulation





Our Solutions & GDPR

25 May 2018 - Implementation of the new European General Data Protection Regulation

With the General Data Protection Regulation - General Data Protection Regulation, widely known as GDPR or GDRP, a unified legal framework is established for the protection of personal data throughout the European Union.

This Regulation protects European citizens from any unlawful, without their consent, use of personal data that could cause them harm.

Personal data is any information that identifies natural persons. These can be, for example, the name, surname, VAT number, social security number as well as any other simple or sensitive information through which the identity of the person can be determined.

Every natural or legal person, public authority, service or body, regardless of size and sector, which collects, organizes, records, stores, modifies, searches, transmits, correlates, deletes etc., directly or indirectly, personal data has the obligation to comply with the Regulation. The processing of simple and sensitive personal data must be carried out with defined, explicit and lawful purposes for which consent has been given by the directly interested parties.

Breach of security that leads to accidental or unlawful destruction, loss, modification, unauthorized disclosure or access to personal data that have been transmitted, stored or otherwise processed results in criminal and administrative penalties. The financial fines imposed are large and put not only the stability of entities at risk, but also their reputation and credibility towards customers and competition.

The Data Controllers are required to ensure the implementation of appropriate technical measures and security levels in the processing of such data exclusively for a specific purpose and the Data Protection Officers of the entity are required to notify the competent authority and the affected individuals promptly in case of discovery of a security breach.


Ergon Iris is committed to respecting and protecting the personal data of its employees, with its primary concern being your security and privacy. Our applications provide a robust mechanism for ensuring the security and accessibility of your personal data, with tools defined by the entity itself.


Databases

Data Bases used by our applications are exclusively installed in one unique central unit. Administration is managed exclusively from the entity's unique Responsible.


Active Directory

Our Applications provides possibility of limitation or/and exclusion of groups and users that the entity desires to have partial or zero access and users certification by the entity.


Firewall

Through the server, the possibility of locking and exclusion of IP addresses of the computers that the entity decides not to allow access to the databases is provided.


Access

In our applications, only identified positions have access. Each position has its unique code/key for access. This key may have a defined lifespan, and beyond that, its validity is revoked and access is denied to the respective users. Ergon Iris has access to the entity's data only after authorization and consent from the entity's responsible party.



User Groups

With our solutions, the entity has the ability to create user groups with specific access rights to the databases. Groups or individual users can have access (insertion – deletion – reading – modification) only to specific tasks, information and data tables of the system, according to the rights defined by the entity.


Data Export

With our solutions, the entity has the ability to export data in various formats.

This capability is provided exclusively to authorized users as defined by the entity, in order to meet the requirements of the General Data Protection Regulation (GDPR).