To strengthen an individual’s rights to privacy, the European Union brought about the General Data Protection Regulation or GDPR. Fortifying existing directives on data protection, the GDPR defines guidelines for businesses collecting, storing and processing personal data. The regulation issued by the European Union applies to businesses processing personal data of European residents, and has an enforcement deadline of May 2018.
The regulation encompasses steps to be taken in all areas of protecting an individual’s privacy — setting up security mechanisms, compliance, repercussions of breach and more. Non-compliance beyond the enforcement date is liable to attract heavy penalties.
We have a strong commitment to protecting our customer’s personal data, Stafford Hosts is here to help customers and end-users understand the significance of the GDPR, its requirements and our allegiance to comply with global standards.
Deliver business value by optimizing service efficiency with secure and scalable systems for collecting, storing and processing data
Increase customer and partner awareness on regulation requirements, ensuring consistent application of data protection measures.
Any information relating to an identified or identifiable natural person (‘data subject’). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as – name, email address or location, and also online identifiers like IP address, types of website cookies and other device identifiers.
For eg: Support tickets carrying personal data like name, location, social identity for purposes to record and solve an individual’s support requests; CRM software collecting online identifiers to learn prospect activity on from the company website/product.
A data controller is an entity/person that determines purposes and means of processing personal data of the EU resident. For eg. Stafford Hosts is a data processor and Stafford Hosts customers are controllers of the EU resident’s data.
The GDPR applies to both data controllers and processors. Controllers collect data from the end-user that is the EU resident, for purposes clearly stated and with appropriate consent. Data processors provide services to the controller in accordance with each controller’s instructions. Processors also use data collected to perform benchmarking analysis, so that it can sell further services allowing controllers to compare their data to industry averages.
Another category called sub-processors or third-party businesses performing data processing for other companies are also accountable for protection of personal data, according to the GDPR
Any information relating to an identified or identifiable natural person. The identifiers are classified into two types: direct (e.g., name, email, phone number, etc.) and indirect (e.g., date of birth, gender, etc.).
When you contact us in relation to a migration we’ll put together a proposal for you. On approval of this proposal we will require full access to your existing website, your control panel account with your existing provider.