Understanding GDPR and Its Impact
The General Data Protection Regulation (GDPR) is a comprehensive privacy law in the EU that aims to standardize data protection rules. Enforced in all EU member states since May 2018, GDPR requires companies to protect consumer data and imposes strict regulations on data processing, access, and security. The GDPR is built on six core principles, including lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, and integrity/confidentiality.
Evisort's Commitment to GDPR Compliance
Evisort takes GDPR compliance seriously, particularly regarding data privacy and security. As a Processor under GDPR, Evisort provides a software application that helps customers with contract management and ensures compliance with the GDPR. Evisort assists Controller customers in meeting GDPR requirements by offering features like processing records analysis, data retention policies, data protection policies, breach procedures, international data transfer mechanisms, and more.
Enhanced Data Security Measures by Evisort
Evisort prioritizes data security and has implemented robust measures to protect personal data. The platform has enterprise-grade security features and adheres to GDPR requirements by employing security processes, policies, and standards. Evisort is SOC 2 Type 2 certified and undergoes regular penetration testing and vulnerability monitoring. The platform ensures data control and monitoring, encrypts data at rest and in transit, offers customized access control, and runs a world-wide bounty program to discover vulnerabilities.
GDPR Contract Update and Shared Responsibilities
Under GDPR, both Evisort (Processor) and its customers (Controllers) share responsibilities to protect individuals' privacy rights. GDPR Article 28 mandates a contract between the Processor and Controller detailing their respective GDPR obligations. Evisort ensures that the contractual agreements with its customers reflect these shared responsibilities and outline the necessary actions to comply with GDPR requirements.