GDPR Compliance
Purpose
This chapter aims to define the conditions under which the processor undertakes to carry out, on behalf of the client data controller, the personal data processing operations defined below.
As part of their contractual relationship, the parties undertake to comply with the regulations in force applicable to the processing of personal data, and in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, applicable as of 25 May 2018, hereinafter referred to as "the European data protection regulation".
Description of the processing covered by the subcontracting
The processor is authorized to process, on behalf of the client data controller, the personal data necessary to provide the following services:
1. Hosting of data in Data Centers
- We work with OVH, certified under the GDPR by CISPE (Cloud Infrastructure Services Providers in Europe).
- See the following link: https://www.ovh.com/fr/protection-donnees-personnelles/gdpr.xml
2. Data backup for daily backups
- We run backup scripts every night for all our client data controllers under maintenance contract.
- Backups are a copy of the active production database.
- Backups are stored on hard drives encrypted in XTS AES 128-bit with a 256-bit key.
- Backups are deleted after a life cycle of 15 days.
3. Support on local environment data
- For testing, support, or development purposes, our teams may need to make a partial or full copy of data from the production database.
- When such copies are made, they are stored on local hard drives encrypted in XTS AES 128-bit with a 256-bit key.
The nature of the operations carried out on the data is based on this contract, and more specifically on the maintenance contract between the client data controller and the processor.
For the performance of the services covered by this contract, the client data controller may provide additional information.
The processor is not entrusted with any task other than storing and backing up the data.
Obligations of the processor towards the data controller
Purpose and instructions
The processor undertakes to process the data solely for the purposes covered by the subcontracting agreement, namely exclusively their storage and backup.
It undertakes to process the data in accordance with the documented instructions of the data controller.
If the processor considers that an instruction constitutes a violation of the European data protection regulation or any other provision of Union or Member State law relating to data protection, it shall immediately inform the data controller.
Furthermore, if the processor is required to transfer data to a third country or an international organization, under Union or Member State law to which it is subject, it must inform the data controller of this legal obligation before processing, unless the law concerned prohibits such information on important grounds of public interest.
Confidentiality
The processor undertakes to guarantee the confidentiality of the personal data processed.
It further undertakes to ensure that service providers or staff members involved in the storage and backup of personal data in the performance of this contract:
- Are not entitled to process the data themselves,
- Undertake contractually to respect confidentiality or are subject to an appropriate legal obligation of confidentiality,
- Receive the necessary training in personal data protection as well as on the importance of complying with privacy protection legislation.
The confidentiality commitments made under this contract shall remain in effect for the entire duration of the contract, as well as for a period of two years from the date of its termination.
Finally, the processor undertakes to take into account, with regard to its tools, products, applications, or services, the principles of data protection by design and data protection by default.
Subcontracting
The processor may engage another processor, hereinafter referred to as "the subsequent processor," to carry out specific processing activities.
In this case, it shall inform the data controller in advance and in writing of any intended change concerning the addition or replacement of other processors.
This information must clearly indicate the subcontracted processing activities, the identity and contact details of the processor, and the dates of the subcontracting agreement.
The data controller has a minimum period of fifteen days from the date of receipt of this information to raise objections.
This subcontracting may only take place if the data controller has not raised any objection within the agreed period.
The subsequent processor is required to comply with the obligations of this contract on behalf of and according to the instructions of the data controller.
It is the responsibility of the initial processor to ensure that the subsequent processor provides the same sufficient guarantees regarding the implementation of appropriate technical and organizational measures, so that the processing meets the requirements of the European data protection regulation.
If the subsequent processor fails to fulfill its data protection obligations, the initial processor remains fully liable to the data controller for the performance of the other processor's obligations.
Right of data subjects to be informed
It is the responsibility of the data controller to provide information to data subjects at the time the data is collected.
As far as possible, the processor may assist the data controller in fulfilling its obligation to respond to requests to exercise the rights of data subjects:
- Right of access, rectification, erasure, and objection,
- Right to restriction of processing,
- Right to data portability,
- Right not to be subject to an automated individual decision, including profiling.
When data subjects send requests to exercise their rights to the processor, the processor must forward them upon receipt by email to the contact indicated by the data controller.
Notification of personal data breaches
The processor shall notify the data controller of any personal data breach within a maximum of twenty-four hours after becoming aware of it, and by email.
This notification shall be accompanied by all useful documentation to enable the data controller, if necessary, to notify the breach to the competent supervisory authority.
It shall then be the responsibility of the data controller to notify the personal data breaches found to the supervisory authority and to communicate them to the data subject, as soon as possible, unless the breach in question is unlikely to result in a risk to the rights and freedoms of the data subject.
Notification to the supervisory authority and communication to the data subject must include all the information required by the European data protection regulation.
Security measures
The processor undertakes to implement appropriate technical and organizational security measures, taking into account the risks inherent to the processing and the nature of the personal data.
It shall in particular take measures to:
- Prevent unauthorized persons from accessing the IT systems that process personal data in such a way that they cannot consult, copy, modify, delete, or disclose such data,
- Ensure that authorized users of the data processing systems can only access the personal data covered by their access rights,
- Prevent personal data from being read, copied, or deleted during transfer and during the transport of storage media,
- Ensure the confidentiality, integrity, and availability of processing services,
- Restore the availability of and access to personal data within an appropriate timeframe in the event of a physical or technical incident,
- Regularly evaluate the effectiveness of the technical and organizational measures ensuring the security of the processing.
Fate of the data
At the end of this contract, the processor undertakes, at the choice of the data controller, to:
- Destroy all personal data, or
- Return all personal data to the data controller, or
- Return the personal data to the processor designated by the data controller.
The data controller must inform the processor of its choice within fifteen days of the end of this contract, failing which all personal data will be destroyed with no recourse against the processor.
The return shall be accompanied by the destruction of all existing copies in the processor's information systems, which shall be certified in writing.
Data Protection Officer
The processor shall communicate to the data controller the name and contact details of its Data Protection Officer, if one has been appointed, in accordance with Article 37 of the European data protection regulation.
The Data Protection Officer of the data controller can be contacted at info@anb-rimex.be
Obligations of the client data controller towards the processor
The client data controller undertakes to:
- Provide the processor with the information necessary to fulfill its commitments.
- Set out in writing any instruction concerning the processing of data by the processor. Services provided by the processor to assist the client controller in carrying out these instructions are support services governed under the maintenance contract linked to the original agreement. The processor will only carry out the services once the request has been submitted and validated by the client controller.
- Ensure, both prior to and throughout the duration of processing, compliance by itself and by the processor with the obligations set out in the European data protection regulation on the part of the processor,
- Supervise the processing.
Miscellaneous
Liability
The processor shall only be held liable for damage caused by the processing entrusted to it if it has failed to comply with the obligations of the European data protection regulation specifically applicable to processors, or if it has acted outside of, or contrary to, the lawful instructions of the data controller.
It shall be released from any liability if it proves that the event causing the damage is in no way attributable to it.
Force majeure
Neither party shall be liable to the other for any delay or failure to perform its contractual obligations due to one or more causes beyond its reasonable control, including but not limited to natural disaster, government decision, war, fire, flood, explosion, and civil unrest, this list not being exhaustive.
Provided that the party experiencing the delay promptly notifies the other party in writing of the reason for the delay and its likely duration, performance of the delayed party's obligations shall be suspended to the extent that the obligations are affected by the delay, for as long as the cause of the delay persists.
Assignment
Neither party may assign the rights and obligations resulting from this contract without the prior written authorization of the other party, which shall not unreasonably withhold or delay such authorization.
Amendment
Any amendment to this contract must be made in writing and signed by a person authorized to bind the parties.
Governing law and jurisdiction
This contract is governed by Belgian law.
Any dispute relating to its validity, interpretation, performance, resolution, or termination shall fall under the exclusive jurisdiction of the courts of the processor's registered office.
The processor may, however, summon the data controller for intervention and warranty before another court responsible for ruling on a main action justifying the data controller being brought into the proceedings.
The data controller may, however, summon the processor for intervention and warranty before another court responsible for ruling on a main action justifying the data controller being brought into the proceedings.