Accord additionnel
Accord additionnel
Relatif au traitement de données à caractère personnel
&RQIRUPpPHQW j O¶DUWLFOH GX 5*3'
Préambule
Parmi les Services fournis par ▇▇▇▇▇▇▇ (ci-après le « Sous-traitant ») au bénéfice du Client (ci-après le
« Responsable de traitement » ; et conjointement avec le Sous-traitant les « Parties ») figure, entre autres, le traitement de données à caractère personnel.
Les stipulations du présent Accord additionnel ont vocation à s’appli Sous-traitant dans le cadre de sa prestation de Services conformément du Contrat de Services Individuel et,
dans cette perspective, précisent les obligations des Parties au vu des dispositions légales applicables en matière de protection des données personnelles. Les stipulations du Contrat de Services Individuel
continueront à s’appliqueArccorcd oadnditcioonnmel.itamment au présent
1. Objet et durée de la mission
(1) La mission a pour objet la fourniture de Services tels que décrits dans le Contrat de Services Individuel.
(2) La durée de cette mission sera équivalente à celle du Contrat de Services Individuel. En conséquence, cette mission prendra fin concomitamment au Contrat de Services Individuel.
2. Précisions sur les détails de la mission
(1) Nature et objet du traitement de données envisagé
La nature et l’objet des -trtaiâtanct hcoenssiste àen laafocurcnioturme pdelSierrvicespliaésr le S aux communications, tels que ceux-ci sont plus précisément décrits au Contrat de Services Individuel.
La traitement contractuellement convenu devra être réalisé au sein d’un européenne (UE) ou d’un Etat membre de l’Espace Econ Etat non membre de l’UE ou de l’EEE devra préalablement êt et ne pourra être réalisé que si les conditions particulières des articles 44 et suivants du RGPD sont bien remplies. L’accord préalambelntene ddevurait Rpaes sêtpreodinffésréaobu lreefusé ddee trai manière déraisonnable.
(2) Catégories de données traitées
Le traitement portera sur les catégories de données suivantes :
[x] Données personnelles de base
[x] Données de communications (à savoir téléphone, e-mail, fax) [ ] Données contractuelles de base
[ ] Données de facturation et de paiement
[ ]
(3) Catégories de personnes concernées
Les catégories de personnes suivantes sont concernées par le traitement de données :
[x] Destinataires et expéditeurs de messages adressés ou envoyés par le Responsable de traitement
[x] Salariés / contacts du Responsable de traitement [ ] Clients
[ ] Fournisseurs
[ ] Conseil d’administration [ ]
3. Mesures techniques et organisationnelles
(1) Le Sous-traitant s’obliglesemeàsuresmteecthntiqurees et eorgnanispatlionancellees visées à l’articl 32 du RGPD permetatssaunrertunedp’rotection adéquate des données du Responsable de traitement
et ce, afin de préserver en permanence la confidentialité, ▇▇▇’tégrité, la disponibilité et la résilience du système de traitement et des services. (Les mesures à mettre en place par le Sous-traitant sont plus précisément détaillées en annexe du présent Accord additionnel).
(2) Les mesures techniques et organisationnelles devront faire l’objet des aendfoancptiotn ations des progrès technologiques et évolutions à venir. A cet égard, le Sous-traitant devra à tout moment
implanter les mesures alternatives adéquates, à condition que le niveau de sécurité des mesures ne soit pas réduit. Les modifications substantielles devront être documentées.
4. Droits des personnes concernées
(1) Le Sous-traitant s’interdira de recprotpirefiniitiaetivre ,les deonfnféeas tcraeitéres ou re
pour le compte du Responsable de traitement, si ce n supposer que le Sous-traitant soit contacté directement par une personne concernée demandant que les données la concernant soient rectifiées ou supprimée ou adressant une demande -trdait’anit nferfa osarnsmdaétlaiisouivnre,la dlemeandSe odeulsa
personne concernée au Responsable de traitement.
(2) Le Sous-traitant devra se conformer aux instructions du Responsable de traitement et las’sister dans la mise en place de sa politique de suppression des données ainsi que dans le traitement des demandes des personnes concernées au regard des droits dont ces dernières disposent (càd en termes de rectification, portabilité des données, suppression et accès aux données).
5. Assurance qualité et autres obligations du Sous-traitant
Le Sous-traitant devra remplir les conditions ci-après énoncées:
(1) La désignation d’un délégué à la protection des donnée articles 38 et suivants du GDPR.
Le Sous-traitant de traitement a désigné un délégué à la protection des données qui peut être contacté par e-mail :
D’autres coordonnées de contact sont a-triaistanét.ment access
(2) La réalisation périodique d’un moent idets omresiurnesgtechdneiquses ept roces organisationnelles c3oci-ndefssousr, mafién dmees’natssàurle’rarqtuiecllee traitem champ de responsabilité du Sous-traitant soit conforme aux exigences posées par la règlementation
applicable en matière de protection des données, tout en prenant en considération, plus particulièrement, mais de manière non exhaustive, les droits de la personne concernée.
(3) Le Sous-traitant assure que (i) ses salariés en charge du traitement des données du Responsable de traitement et (ii) toutes les personnes travaillant pour le compte du Sous-traitant seront pas amenés à traiter les données, sauf sur instructions du Responsable de traitement. Par ailleurs, le Sous-traitant garantit que les personnes autorisées à traiter les données se sont engagées à une obligation de confidentialité ou sont soumises à une obligation statutaire de confidentialité.
(4) Le Sous-traitant informera sans délai le Responsable de ce dernier seraient menacées du fait de leur saisie, de l’oouu vtouet rture
autre évènement ou toutes mesu-trreasitéamnatnasn’tobdl’iugne tàieirns
toutes les personnes responsables dans ce contexte que les données appartiennent exclusivement au Responsable de traitement en tant que « responsable » au sens du RGPD.
6. Sous-traitance
(1) Dans le cadre du présent article 6, la notion de sous-traitance doit sc’omemnetlaefonudrnirturee de services se rapportant directement à la fourniture du Service principal. Sont exclus les services
accessoires, tels que les services de téléphonie, po aux utilisateurs, ainsi que toutes les mesures ayant vocation à assurer la confidentialité, la disponibilité,
l’intégrréistiélieetnclea des équipements matériels et logici
soit, le Sous-traitant s’oblige à souscrire aux contrats néc
appropriées afin edc’tioan set slausércuerirté deqs udoennéels adu Rperspoontsable de traitement
soient assurées, même en cas d’externalisation de services ann
(2) Le Sous-traitant ne pourra recourir à des sous-traitants (sous-traitants complémentaires) q agrément du Responsable de traitement. Le Responsable de traitement ne pourra refuser son agrément
que pour un motif impérieux relevant la règlementation applicable à la protection des données.
(3) Le responsable de traitement sera réputé avoir agréé au recours à un sous-traitant, lorsque (i) le Sous- traitant aura informé par écrit le Responsable de traitement de son intention de recourir à un sous-traitant
et que (ii) le Responsable de traitement n’aura pas les 14 jours calendaires suivant la réception de l’i
traitement, il ne sera mCionstrat duenServticeesrInmdievidueql uaff’ecatéuesxpar ple arerfusties d d’agrémunesonuts-tradita’nt.
(5) Le « délai de prduéréae rvaisiosnnabdle’» uaunseens du paragraphe quatre (4) ci-dessus comporte au maximum 6 mois ou la durée contractuelle restant à courir et ce, en fonction de laquelle de ces deux durées est la plus courte.
(6) Par la présente, le Responsable de traitement agréé le sous-traitant suivant :
x retarus GmbH, ▇▇▇▇▇▇▇▇ ▇▇▇▇▇▇ ▇▇, ▇▇▇▇▇ ▇▇▇▇▇▇, ▇▇▇▇▇▇▇▇▇
Dans la mesure où des prestations dans le domaine de l'EDI et/ou de l'OCR font l'objet du Contrat de Services Individuel:
x Ametras Documents GmbH, ▇▇▇▇▇▇▇▇▇ ▇, ▇▇▇▇▇ ▇▇▇▇▇▇▇▇▇▇▇▇, ▇▇▇▇▇▇▇▇▇
x retarus (Romania) S.R.L., Piața Consiliul Europei, Nr. ▇▇, ▇▇▇▇ ▇▇▇▇▇▇ ▇▇▇▇▇▇▇▇▇, ▇▇▇▇▇▇▇
Dans la mesure où des prestations dans le domaine de la sécurité de la messagerie électronique (E-Mail Security) font l'objet du Contrat de Services Individuel:
x Bitdefender S.R.L., Orhideea Towers Building, ▇▇▇ ▇▇▇▇▇▇▇▇▇▇ ▇▇▇▇▇▇, ▇▇▇ ▇▇▇▇▇▇▇▇, ▇▇▇▇▇▇ ▇▇▇▇▇▇▇▇, ▇▇▇▇▇▇▇
(7) Dans l’hypothè-trsaiteant aourùait rleceoursSà ounussous-traitant, le Sous-traitant devra répercuter sur ce sous-traitant ses propres obligations en matière de protection des données telles que celles-ci
ressortent du présent accord supplémentaire et ce, par la conclusion d’un co 28 (2) –(4) du RGPD.
7. Pouvoir de surveillance du Responsable de traitement
(1) Le Sous-traitant devra rapporter la preuve, par tout moyen approprié, de sa conformité avec les obligations
incombant au sous-traitant en vertu de l’article 28 du RGPD et cas de figure, l’information nécessaire.
traitement –qu’au dt’eurnmedéprélvaeniancedde’au m10ojoiurns scalendaires, durant les horaires
habituels d’ouverture dudSeouss-trabitauntreet saanus xque cela ne vienne perturber le cours de ses
affaires. Le Sous-traitant pourra soumettre la réalisation d’un
(au moins 10 jours à l’avance) pa’rà lea Rreésgpuonlnaacscroaridbslaetidoe
de confidentialité. Le Sous-traitant pourrait refuser l’implication de l’inspec
de traitemenhtèse odùacent isnspelct’euhr syerpaitoêttre un concurrent du Sous-traitant.
(3) Dans leunecvioalastion dde’données par le Sous-traitant, un contrôle portant sur cette violation pourra être réalisé, sous respect d’un délai de prévenance Toute perturbation du cours des affaires du Sous-traitant devra toutefois autant que possible être évitée.
(4) L’ar7t, ailincéal(e2) ci-dessus devra tout autant s’appliquer en ca contrôle ou toute autre autorité de surveillance du Responsable de traitement. Il pourra être renoncé à la signature d’un accord de ctroôlne efstistdateutanirtemienat lsoiumtiséà unseiobliglat’▇▇▇▇ utori de confidentialité.
(5) La preuve de telles mesures, qui ne concernent pas qu’umnisseion en particulier, devra également être fournie par :
x l’applicoadteisondedeconduite conformément à l’article
x l’obtdeenctertiificoatns délivrés conformément à un mécanisme de certification mis en place conformément de l’article 42 du RGPD
x des certificats d’audit, des rapports ou extraits indépendants (par exemple par un auditeur, un délégué à la protection des données, un département sécurité des systèmes d’sidnonfnéoesr, munation, auditeur qualité) ; ou
x l’obtention ddu’n’uaundit scéecrutriiftiécadtes systèmes d’informa
données.
8. 1RWLILFDWLRQV HW REOLJD-WtraLitRanQt G¶DVVLVWDQFH GX 6RXV
Le Sous-traitant devra aider le Responsable de traitement à se conformer à ses obligations te ressortent des articles 33 et 36 du RGPD. Cette aide devra notamment (mais non exhaustivement)
comprendre :
x La notification immédiate au Responsable de traitement de toute violation de données
x L’idae au Responsable de traitement à se conformer à concernées. A cet égard, le Sous-traitant devra immédiatement fournir au Responsable de
traitement toutes les informations pertinentes ;
x L’idae au Responsable de traitement lors de son analyse d; ’impact sur
x L’idae au Responsable de traitement pour la consultation préalable de l
9. 3RXYRLU GX 5HVSRQVDEOH GH WUDLWH; PObHligQaWtio nGde¶npotPifiHcaWtioWnUduH GHV L Responsable de traitement
(1) Les instructions du Responsable de traitement devront immédiatement être confirmées par lui par écrit (ou pour le moins sous format texte).
(2) Le Sous-traitant est tenu d’informe trsaintsemdeénltais’▇▇▇▇ ▇▇▇▇▇
instructions portent atteinte à la règlementation en matière de protection des données personnelles. Le
Sous-traitant sera alors autorisé à suspendre l’exécution des instructio Responsable de traitement confirme ou modifie ses instructions.
(3) Le Responsable de traitement devra immédiatement informer le Sous-traitant dèsrelelvéors qu dans les réalisations ou les résultats de travail du Sous-traitant des erreurs ou irrégularités au regard de
la règlementation en matière de protection des données personnelles.
10. Suppression et restitution de données personnelles
(1) Aucune copie ou duplication de données ne pourra êt exception faite toutefois de copies de sauvegarde po pour assurer le traitement conforme de données, ou de données nécessaires pour satisfaire à des
obligations légales de conservation de données.
(2) Après achèvement des travaux contractuels ou avant cela, à la demande du Responsable de traitement,
en tout cas au plus tard Clonotrart dseqSuerv’icieslIndisvideuerl aou emnciorse lorsuqnue terme
ce dernier arrivera à terme, le Sous-traitant devra remettre au Responsable de traitement ou, si le Responsable de traitement le lui demande, détruire tous les documents et tout ensemble de données se rapportant au contrat et dont le Sous-traitant pourrait avoir eu connaissance et ce, sous une forme qui soit conforme à la protection des données. Le fichier log de la destruction ou suppression devra être fourni si la demande en est faite.
(3) Toute la documentation utilisée pour prouver le traitement en bonne et due forme de données conformément aux instructions reçues, devra être sauvegardé par le Sous-traitant au-delà de la durée du contrat en conformité avec les durées de conservation des données respectivement applicables. Le Sous- traitant pourra remettre au Responsable de traitement cette documentation au terme du contrat et ce, afin de libérer le Sous-traitant de ses obligations contractuelles.
11. Affectation des coûts
(1) Dans le cas où, sur instructions du Responsable de traitement, le Sous-traitant (i) aiderait le Responsable de traitement à se conformer à ses obligations en vertu des articles 33 à 36 du RGPD (cf. article 8 ci- dessus) ou (ii) fournirait d4ecis-desssues,rlevSioucs-terasitantcseoranit fenodrroimt d’exiger une rémunération calculée sàucrette lépaoquebpaousr ela
ément de s
fourniture de services dCeetctoen
sutlitpiunlgateitond’naes
si’satpapnlcie
dans le mesure où les services/ obligations contractuelles.
, lpa’r alesSsouis-stratitaantn, dceeses sont
(2) Dans l’hydp’oitnhsèpseections su7 rci-desssiust),ele S(oucs-ftra.itantaproutrraiecxligeer une rémunération pour les efforts mis en œuvàrbieen eat/ofu aifinn
de p
de fournir son aide à la réalisation de l’inspectio mobilisent plus d’une journée homme par année calend taux horaires alors applicables chez le Sous-traitant pour des services de co
12. Stipulations finales
(1) Le présent Accord additionnel remplacera tous les ac portant sur le même objet que le présent Accord additionnel (traitement de données).
(2) Les stipulations du présent Accord additionnel s’app les Parties portant sur la fourniture de Services par le Sous-traitant au bénéfice du Responsable de traitement, à moins qu’il n’en soit convenu autremen
(3) Si l’une des stipulations du présent Accord addition de lacune du présent Accord additionnel, les autres demeureraient pas moins applicables. Les Parties devront remplacer la stipulation nulle ou non applicable
ou combler la lacune, selon le cas, par une stipulation valide et applicable se rapprochant autant que possible de l’objectif économique du présent Accord
(4) Dans la mesure où des stipulations du Contrat de Services Individuel ne se trouveraient pas affectées par
le présent Accord additionnel, celles-ci resteront en l’état, pleinement a
(5) Toute modification ou tout avenant au présent Accord additionnel requiert la forme écrite ou la format texte et devra faire expressément référence à cet Accord additionnel. La même chose vaut pour renoncer à cette exigence de forme écrite.
Annexe Mesures techniques et organairtisclea3t2 iduoRnGPnDelles confor
Annexe
0HVXUHV WHFKQLTXHV HW RUJDQLVDWLRQQHOOHV FRQIRUPp
T³echnical and organizational measures pursuant to Art. 32 GDPR´
Status of document: V3.1 of 18. February 2021
The following package of measures encompasses the individual technical and organizational measures pursuant to Art. 32 GDPR to be implemented by the Proc behalf.
The statements on the data center relate to the Retarus headquarters at Aschauer Str. 30, Munich. They are intended as an example to be applied to all Processor data centers and apply as standard for any future Processor data centers.
This document contains the following sections:
I. Confidendiality (Art. 32 (1) (b) GDPR) 8
1. Physical access control 8
2. Access control 10
3. Data access control 11
4. Separation control 12
5. Encryption 12
II. Integrity (Art. 32 (1) (b) GDPR) 13
1. Transfer control 13
2. Input control 13
III. Availability and capacity (Art. 32 (1) (b) GDPR) 14
1. Availability control 14
IV. Procedures for regular review, assessment and evaluation (Art. 32 (1) (d) GDPR; Art. 25 (1) GDPR)
………………………………………………………………………………………………………..………1…6 1. Order Control ....................................................................................................................................... 16
2. Management-Systems 16
V. List of Changes 17
I. Confidentiality (Art. 32 (1) (b) GDPR)
1. Physical access control
Measures as a protection against unauthorized access to data processing systems.
1.1 Property protection (data center)
a) Separate security zone, access to data center secured by access control system with chip cards
b) Door security (magnetic locks, badge readers and access logging)
c) CCTV with 24 hour recording
d) Burglar alarm system –see Section I.1.7 below
e) No external windows in the data center
f) Service shafts secured (air conditioning, ventilation, lifts etc.)
g) Emergency exits are secured against misuse –alarm triggered by escape door control units in basement
1.2 Property protection (building and offices)
a) Access to offices by access control system with chip cards
b) Door security (motor locks, badge readers and access logging)
c) CCTV of entrance doors after office hours
d) Protection of building exterior by motion sensors in staircase area
1.3 Security zones
a) Data center is a separate area with strict physical access restrictions and surveillance
b) The departments in charge of the administration “Application Management”, are grouped together, access control
1.4 Organizational access control
a) Inspections by security service after office hours
b) Regulations governing the use of keys
c) Regulations governing the locking of doors (doors and windows must be kept closed at all times, alarm system in data center armed in case of absence)
▇) ▇▇▇▇▇▇▇ of emergency exits and escape routes
1.5 Regulations regarding physical access authorization
(Relating to the data center)
a) Physical access regulations for persons and groups of people (employees, managers, third parties, visitors, servicing and cleaning personnel, suppliers, delivery companies etc.)
b) Regulations governing authorized personnel leaving the company and changes in authorization
c) Regulations / follow-up measures relating to the loss of badges, keys etc.
d) Regulations governing visitors incl. obligation to comply with data protection upon access
e) Registration and accompaniment of visitors and third parties
f) Supervision of servicing, maintenance and cleaning personnel
g) Ability to revise the allocation and revocation of physical access authorization
1.6 Personnel checks
a) Operating personnel control
b) Service, maintenance and cleaning personnel control
c) Visitor control
1.7 Alarm systems
a) Hazard detection system certified by the VdS
b) Disarming only possible for authorized personnel with chip card and additional code entry
c) Disarming ("forgotten" arming) outside core hours triggers an alarm in the permanently manned security guards office
d) Alarm in case of “door open“ longer than 30 secon
e) Monitoring of data center by means of motion sensors
f) Duration until security team is on site: approximately 10 minutes
g) Detection lines for sabotage alarm, malfunctions etc. as standard
h) Maintenance contract in place
2. Access control
Measures to prevent unauthorized system access.
2.1 Regulation of access rights
(related to complete systems or individual applications)
a) Processes governing the allocation and management of access authorizations under redundant supervision (principle of multiple-assessor verification)
b) Regular checks on the validity of access authorization
c) Authorized persons are required to identify themselves by user ID and password
d) Password management for emergency users (administrator, root, etc.)
e) Password policy in place governing the use of passwords
f) Computers must be locked at all times in case of absence from the workplace
g) Limited authorization (account activation) for temporary employees / third parties
h) Regulations and defined procedures for company leavers and changing authorizations
i) Regulations in case of loss (forgetting) of the password(s)
j) Limitation of logon attempts
k) Disconnection in case of repeated failed attempts or timeouts
2.2 Network security
a) Separated networks for Services, internal/office use and visitors
b) Implementation of network security mechanisms (network access control via 802.1x or MAC filters) that prevent unauthorized access to the network.
c) Network protection through firewalls and virus scanners
d) Use of Intrusion Prevention Systems (IPS) and protection against DDOS attacks
e) Regular control of configurations and adjustment against specifications for the hardening of systems
f) Regulations for the release of new devices before commissioning in productive environments
2.3 Additional measures for remote access
a) Regulation governing the use of the remote connection, particularly for third parties
b) Only defined personnel will be permitted to log in remotely
c) Network access protection by hardware and software measures; e.g. access exclusively possible via VPN with 2-factor authentication
d) Regulations governing remote administration and maintenance (remote maintenance concept)
e) Regulations governing the remote access available to business partners (extranet)
f) Prevention of unauthorized access from the Internet (firewall)
2.4 Access logging
a) Evidence of the use of data processing systems (access logging)
b) Logging of failed login attempts (unblocking users)
c) Logging of allocations/changes of access authorizations
3. Data access control
Measures against unauthorized reading, copying, alteration or removal of personal data within the Retarus System.
3.1 Authorization concept
a) Regulations governing the allocation and management of access authorizations
b) Service-related definition of authorization management regulation for the input, information, modification and deletion of stored data (level of detail, assignment practice, signature authorization)
c) Individual access rights –creation of user groups
d) Guidelines for data management (e.g. expiry dates, retention periods, protection categories)
3.2 Access protection
a) Password-protected files
b) Separation of testing and production operations
c) Network access protection
d) Restricted authorizations for the use of utility programs or features that are appropriate to circumvent security measures
e) Limitation of unrestricted SQL query options of databases
f) Implementation of the erasure strategies through automated erasure of data in accordance with the respective retention periods.
3.3 Handling procedure for data storage devices
(Relating to the data center)
a) Regulation governing the applicable location/zone of specific data carriers
b) Zones are secured by access control system
c) Regulation on secure data carrier storage depending on the type of data carrier (blank/new, recorded, etc.)
d) Organizational regulations for data carrier storage (storage periods, clear identification of data carriers)
e) Determination of authorized persons for the removal of data media (key management/acknowledgement, return)
f) Generally no repair of data carriers, but disposal in accordance with data protection requirements (with confirmation of destruction and proof of disposal)
g) Regulations governing the production/distribution of copies and duplicates (archives inside and outside the company, printed matter etc.)
h) Regulation regarding the destruction of data carriers depending on the type of data carriers (HDD, magnetic tapes, flash memory etc.)
3.4 Access logging
In addition to the measures pursuant to Sect. II.2. the following applies:
a) Logging of read accesses
b) Logging of allocations/modifications of access authorizations
4. Separation control
Measures for the separate processing of personal data collected for different purposes.
4.1 Client segregation
a) Logical data segregation
b) Multi-client capability of applications
c) Authorization concept considers the assignment of rights for different purposes
d) Separated systems for production, testing and development
e) Restrictive use of SQL
4.2 Further organizational measures
a) Internal guidelines for data collection and processing
b) Documentation of database(s)
c) Documentation of processing programs
d) Documentation of data collection purposes
e) No integrated data storage
5. Encryption
Personal data processing measures in order to ensure that data cannot be attributed to a specific data subject without the use of additional information.
5.1 Use of encryption
a) Use of encryption routines (data carrier or file encryption) according to the risk classification
b) Encryption of passwords
c) Encrypted transmission of data from or to external networks using suitable transport protocols (SSL/TLS, SSH, S/MIME, PGP, etc.)
II. Integrity (Art. 32 (1) (b) GDPR)
1. Transfer control
Measures to prevent the unauthorized reading, copying, alteration or removal of personal data during electronic transmission or transport.
1.1 Electronic transmission control
a) Encrypted transmission of data from or to external networks using suitable transport protocols (SSL/TLS, SSH, S/MIME, PGP, etc.)
b) Email authentication (digital signature)
c) Determination of the points (third parties) to which data may be transmitted by data transmission facilities
d) Determination of authorized persons for the data transmission (authorization concept)
e) Documentation of the points to which transmission is intended as well as the transmission channels
f) Documentation of the download and transmission programs (e.g. FTP = File Transfer Protocol, Firewall, Remote Access)
g) Logging of data transmission and recipients
1.2 Handling of data carriers
In addition to the stipulations pursuant to Sect. I.3.3 the following applies:
a) Personal data will not be stored on removable media
b) Transport of data carriers with personal data is not provided for
2. Input control
Measures to determine whether and by whom personal data has been entered, modified or removed in data processing systems.
2.1 Monitoring and evaluation
a) Definition of responsibilities for data input (including substitution arrangements)
b) Logging of all entries, changes or deletions of personal data
c) Implementation of the principle of dual control
d) Differentiated user roles (▇.▇. ▇▇▇▇, write, change/delete)
III. Availability and capacity (Art. 32 (1) (b) GDPR)
1. Availability control
Protective measures against accidental or willful destruction or loss of personal data.
1.1 Creation and storage of backup copies
a) General backup concept
b) Regular backup of user files and databases
c) Name conventions for backup files
d) Labelling of data carriers
e) Use of write-protection on data storage devices
f) Inventory of backup copies (files, data carriers)
g) Archiving regulations
h) Inventory control of data carriers
i) Logging of security backups
j) Storage in highly protected areas
k) Definition of retention periods
1.2 Ensuring continuous operations
a) Power supply:
x Uninterruptible power supply through two UPS systems for the data center and emergency work stations
x Emergency power generator with sufficient fuel supply
x UPS for the NOC with sufficient capacity (UPS bridging up to 1 hour)
x Regular tests of the emergency power supply (load and open circuit tests)
x Maintenance contracts in place
b) Fire protection:
x N2 extinguishing system in the data center made by Total Walther. Certified by the VdS, approved pursuant to SprüfV (Safety Equipment Inspection Order)
x Connection to the building‘s central fire detec fire brigade Munich
x In addition, connection to the alarm system when triggered (gas flow meter in the pipe system) with forwarding to the permanently manned security guards office
x Responsible Retarus employees (operating, IT management, technology management) will be notified by security service if alarm is triggered
x Optical and acoustic warnings in the data center in the event of a triggered alarm
x Operating panel of the Retarus central fire detection unit is being checked several times a day
x Maintenance contracts in place
c) Air conditioning:
x Two separate air conditioning systems of different technical designs and with separate routings
x Nine indoor units for optimized cooling distribution
x Leakage warning with forwarding to the permanently manned security guard office
x Responsible Retarus personnel (operating, IT management, technology management) will be notified by security service if alarm is triggered
x Temperature monitoring at several points, integration into the Retarus operating and incident management systems
x Maintenance contracts in place
d) IP-Connection:
x Redundant internet connection with separate routing and building connection/lead-in
x Direct connection to provider’s fiber glass cit
e) Telephone Backbone connection:
x Backbone connection to at least two carriers
x Constant load balancing
x 24x7x365 service agreement
f) Monitoring:
x 24x7 monitoring of IT Systems
x On-call services for interference elimination
g) Redundancies:
x High availability through cluster operation of key systems (network, server, peripherals)
x Provision of hardware replacements
1.3 Measures for emergency and disaster control
a) Emergency plan in the case of disasters (incl. responsibilities, recovery policy, on-call service, alternative data center premises etc.).
b) Business-Continuity-Policy (BCM)
c) Disaster-Recovery-Policy (DR)
d) Pandemic Preparedness Plan (PPP)
e) Protection against water influx/flooding
f) Regular testing of the components of the concepts
1.4 Organizational measures
a) Functional segregation of respective departments and IT unit
b) Staff substitution policies
c) Central and uniform procurement of hardware and software
d) Formalized approval process for new data processing methods and material changes to existing processes
e) Use of tested and approved third-party software only
f) Guidelines for process and program documentation
g) Issuance of instructions and safety guidelines
h) Appropriate user training
i) Appointment of a security officer
j) maintenance contracts and SLA's when using service providers
k) provision of network schematics
1.5 Further technical measures
a) Distribution of IT services across multiple systems
b) Central asset management of all components (CMDB)
IV. Procedures for regular review, assessment and evaluation (Art. 32 (1) (d) GDPR; Art. 25 (1) GDPR)
1. Order control
No order processing within the meaning of Art. 28 GDPR without corresponding instructions from the Controller.
1.1 Contractual arrangements
a) There is a written or at least electronic agreement (text form) in place for order processing between the Controller and the Processor.
b) Controller’s instructions to the Processor shal instructions shall be confirmed promptly at least in text form.
c) Processor shall have sufficient internal instructions relating to the order and the corresponding instructions of the Controller.
1.2 Subcontracting
a) Sufficient measures to ensure compliance with data protection laws by potential subcontractors may also be examined by the Controller.
1.3 Supervisory authorities
a) If the Processor has been inspected by a supervisory authority, the Controller may request the audit report. The same applies to inspections of potential subcontractors.
2. Management-Systems
2.1 Data protection management
a) Appointed data protection officer
b) Employees committed to data protection by written obligation
c) Operation of an information security management system (ISMS)
2.2 Incident-Response-Management
a) Regulations for the handling of data protection and security incidents
b) Regulations for inquiries from affected parties/data subjects
2.3 Change management
a) Changes to systems are subject to the central change management process
b) Implementation of a multi-eye principle for changes (Change Advisory Board)
2.4 Patch management
a) Regular updates of operating systems and applications
b) Automated routines for detecting patch requirements and performing updates
2.5 Regular review
a) Regular internal reviews and audits by IT compliance department
b) Regular vulnerability scans (vulnerability monitoring)
c) Regular external PEN tests to verify network and application security
d) Annual external audits of the internal control system in accordance with ISAE 3402 (SOC1) and ISAE 3000 (SOC2)
V. List of Changes
Version | Date | Changes | Editor |
V3.0 | 07 March 2018 | Redesign of the document due to implementation GDPR, all previous changes were deleted from the history | ▇▇▇▇▇▇▇ ▇▇▇▇ |
V3.1 | 18 February 2021 | Revision and slight changes to the formatting Expansion of the catalog of measures Chapter I: 1.5 d), 2.1 a), 2.2 b), 3.2 f) Chapter III: 1.2 f) g), 1.3 d), 1.4 b) j) k), 1.5 Chapter IV: 2.3, 2.4, 2.5 | ▇▇▇▇▇▇▇ ▇▇▇▇ |
