|
|
|
|
|
by mehdim
1344 days ago
|
|
We are building one such service and I agree (to name a few services doing GDPRaaS : soveren.io, ethyca.com, securiti.ai, datagrail.com, alias.dev) .this is so much needed as there is almost no legally valid answer on the whole comment section!
I started to write an article on all the points above… should get back in 2 hours and post it here |
|
- for any personal data (PII) all companies must declare the following :
So all companies must do a internal data mapping to know and declare where is the data and where it flows in production and write for every PII a ROPA (record of processing activity) You can find an open source specification UROPA here)https://github.com/uropa-project/uropa
- consent is just one of the 6 legal bases to collect and treat data. The comment above that everything is possible with consent is wrong.
- below 250 employees you don’t need officially a DPO