Skip to content
English
  • There are no suggestions because the search field is empty.

Lawful Protection and Processing of Personal and Sensitive Data

How does Eye-Able protect and process personal and sensitive data throughout the entire lifecycle – from data subject rights and DPIA to data sharing and authority access?

This article gives an overview of Eye-Able's data protection and data security programme and the measures used to protect personal and sensitive data throughout their entire lifecycle.


Data protection and data security programme

Eye-Able operates a comprehensive data protection and data security programme that takes into account all data protection requirements arising from the GDPR, ISO/IEC 27701 and other relevant standards.


Policies for data processing and data flows

Documented policies are in place for the classification, processing, sharing, storage and deletion of sensitive and personal data.

Data flows are inventoried, documented in terms of content and reviewed regularly.

Systems and processes are designed according to the principle of "Privacy by Design & Default".


Data protection impact assessment (DPIA)

Before personal data is used in new processes or tools, a data protection impact assessment (DPIA) is carried out where required.


Upholding data subject rights

The upholding of data subject rights (Art. 15 et seq. GDPR) is ensured technically and organisationally, including access, rectification and erasure.


Sub-processors and production data

Access by sub-processors takes place only on the basis of transparent contracts and after prior notification of the controller.

Production data must not be used in test environments unless documented approval by the data controller is in place.


Handling of authority requests

Requests from investigating authorities are processed only in compliance with legal requirements. Eye-Able informs affected customers where possible, unless statutory confidentiality obligations prevent this.


Storage, encryption and deletion

All data is handled, stored, encrypted according to its protection class and, once retention periods have expired, deleted or anonymised.


Further help

Do you have further questions or need personal support? The following article explains how you can get in touch with us: