Controls
Comprehensive overview of the security control frameworks we run — grouped by category so you can jump straight to the domain you care about.
Control Environment
Board oversight briefings conducted
Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.
Monitoring Activities
Board oversight briefings conducted
Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.
Logical and Physical Access Controls
Data center access reviewed
The company reviews data center access at least once a year.
Additional Criteria for Availability
Environmental monitoring devices implemented
The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.
Rights of the Data Subject
Data subject request handling is managed
Mandatory: - Requests from data subjects are handled without undue delay - Procedures are established to support the controller in responding to data subject requests - Employees are trained to immediately notify the responsible contact upon receipt of a data subject request and to coordinate subsequent actions accordingly
Controller and Processor
Privacy and Impact Assessment
To establish a privacy impact assessment process and to perform a privacy impact assessment as necessary.
Privacy Monitoring and Auditing
To monitor and audit PII protection controls and the effectiveness of internal PII protection policy.
Data subject request handling is managed
Mandatory: - Requests from data subjects are handled without undue delay - Procedures are established to support the controller in responding to data subject requests - Employees are trained to immediately notify the responsible contact upon receipt of a data subject request and to coordinate subsequent actions accordingly
Transfers of personal data to third countries or international organisations
International data transfer process is defined
Mandatory: - Transfers of data to third countries are identified and systematically documented - Documentation of third-country transfers is maintained, for example within the register of processing activities - Appropriate safeguards for international data transfers are in place in accordance with Chapter 5 of GDPR, including consideration of relevant court decisions and transfer impact assessments where applicable - It is determined whether consent from the responsible party is required for each transfer to a third country