GDPR
Handling of personal data
On May 25th, 2018, the General Data Protection Regulation (GDPR), a new data protection regulation from the EU, came into effect. This EU regulation is designed to enhance the protection of individuals’ personal data during processing activities. It replaces the previous Data Protection Directive of 1995 and supersedes the existing national regulations of all member states. The GDPR signifies a significant step towards bolstering the rights and privacy of individuals in the handling of their personal information.
The GDPR imposes new obligations on companies, authorities, and organizations involved in the collection and management of personal data. In essence, the GDPR provides concrete guidelines and establishes clear responsibilities for the handling and storage of data. It is crucial for entities that store or process personal data to have a fundamental understanding of the GDPR and its implications. Familiarizing yourself with the basics of GDPR ensures compliance with privacy and data protection regulations.
For information about GDPR and its implications, please refer to the following resources:
Yiplahost’s Role as a Controller:
Yiplahost serves as a controller for the personal data you provide when registering for our services, assuming responsibility as per the GDPR. We are accountable for the processing of your personal data. On our “Data Protection Policy” page, you will find all the relevant information pertaining to your registration with us. It’s important to note that our customers may also have their own data responsibilities for the information they collect and store within our services. In such cases, our role will be that of a Personal Data Advisor to our customers.
Yiplahost’s Role as a Processor:
As a personal data assistant (processor), we handle personal information for those who store data within our services. It is essential for you as a customer, serving as the personal data controller, to ensure that you have a data processing agreement in place. We have collaborated with our legal partners to create a comprehensive data protection agreement (DPA) that applies to all our customers. When considering us as a processor, please review the DPA, Appendix 1 (“Privacy policy”), our Terms and Conditions, and our Data Protection Policy.
Please note that we are unable to make modifications to the offered agreement or physically sign it for our customers in the case of web hosting or cloud services. However, we provide a standard digital agreement available in the documents section below. If you purchase consultancy services or hosting services through our sales team or account management, you may have the possibility to obtain a physically signed agreement. For this, please contact your sales representative directly.
Considerations for Processing Personal Data in Yiplahost’s Services:
It is crucial to have a clear understanding of what constitutes personal data and the implications of processing such data. When it comes to personal data processing in relation to our services, we offer the following tips:
- Avoid processing personal information unless it is necessary, even with consent, and minimize the handling of highly sensitive data.
- Ensure that the information you process and collect is done in accordance with legal requirements.
- Maintain awareness of your responsibilities as a personal data controller.
- Utilize encrypted protocols, such as for web, mail, and file transfers, to enhance data security.
- Keep your applications used for data processing secure, regularly updated, and restrict access to the data as much as possible.
Partners:
We maintain an ongoing collaboration with our law firm to ensure clear and comprehensive terms and conditions. Additionally, we have established robust practices and systems for data protection and GDPR compliance through a dedicated supplier specializing in this area.
Aware and Educated Staff Members:
All our employees, across all departments, have undergone thorough training and internal GDPR certification. We conduct these sessions annually to ensure our staff remains well-informed and up to date. Furthermore, we benefit from reliable supplier and system support to stay informed and actively adhere to the guidelines, aiming to simplify GDPR compliance for our customers.
Other:
Further important information on how we handle GDPR, both as a processor and controller, can be found in our Data Protection Policy and our Data Processing Agreement attachment. These documents outline our approach to handling personal data as a processor. We understand that GDPR may raise questions and concerns, but we regretfully cannot address inquiries beyond our own services and customers based on the information provided here. For other inquiries, we recommend referring to https://www.datainspektionen.se/in-english/, which offers valuable information and guides on working with GDPR.