Introduction
If there’s one thing that’s guaranteed to make marketers nervous, it’s ‘GDPR’. The there is one thing that guarantees the security of sensitive user data, it was the announcement of the General Data Protection Regulation (GDPR) that caused a huge stir, not just only in Europe but across throughout the world. Approved by the European Parliament in April 2016, the GDPR introduced a number of major changes to how organizations are allowed to the way organizations can store and utilize customer data, with huge heavy penalties looming hanging over anyone who fails to doesn't take the new regulations new regulations seriously.
Under the new GDPR regulations, citizens in the European Union have much greater control over their personal data. The new laws focus on privacy and consent, giving customers every right to know when and how their data is being used, and even when it has those have been compromised. These days, almost every service provider uses online data in one form or another, including banks, government agencies, retailers, and employees, as well as online giants like Facebook and or Google. Crucially, customers even have the ‘right "right to be forgotten’ forgotten" and can withdraw consent to use their data at any time.
According to the In accordance with this EU regulation 2016/679 for the data protection (GDPR), the platform has proceeded to adopt adopted the necessary requirements in the design and development of software development to ensure guarantee the privacy and protection of personal data protection for the user .The users in any possible scenario. Users will have their personal data secured and protected. They will be able to define the restrictions and use allowances the assignments of the information. The , guaranteeing at all times the rights established in the GDPR will be guaranteed.This will apply to all fields of the new European normative:.
These are the main novelties established by the new norm in relation to the regime of Organic Law 15/1999, of December 13, on the Protection of Personal Data (LOPD).
PRINCIPLE OF RESPONSIBILITY (ACCOUNTABILITY)
Onesait Platform implements the mechanisms by adopting the necessary measures for the treatment processing of personal data as required by the standard, complying with:
- Responsibility.
- Accountability.
PRINCIPLES OF PROTECTION
From the beginning of the Onesait Platform, the design focused on full compliance with the standard, adopting the necessary measures in all processes that involve data processing, as a rule and from the source. The platform provides mechanisms for authentication, authorization (by roles) and encryption (encrypted information) mechanisms, both in the transfer of information from systems and devices to the platform each other, and in the consumption of stored information. This guarantees the confidentiality and integrity of the stored information stored, complying at all times with:
- Data protection by design and by default.
- Anonymization.
TRANSPARENCY PRINCIPLE
Onesait Platform is completely transparent, both in terms of architecture and data management. The platform is an open-source solution, which has available the Onesait Platform Community version on github. The solution Onesait Platform contemplates at all times:
- Right of access.
- Right to erasure.
- Records of processing activities.
- Enables the existence of a data protection officer.
The user will have the possibility to manage both
theirher profile and all
theirher information, from the ControlPanel, maintaining a principle of complete transparency and
completeprivacy for the user.
Sign up & PrivacyRegistration and privacy options
To register an account in the system the , users must accept the terms and conditions to use for using the platform.
The users Users are informed about the use of the data and rights according to in accordance with the GDPR and how to exercise them (contact information). After that, by using only using the credentials (user/password), a user can access to his or her personal platform account of the platform.:
El usuario puede editar o eliminar su perfil directamente en la aplicación (haciendo clic en el nombre de usuario en la barra superior) o enviando un correo electrónico a los datos de contacto proporcionados en los términos y condiciones (por ejemplo, si ha olvidado la contraseña). En el segundo caso, el administrador solicitará algunas preguntas de seguridad para validar las credenciales como correo electrónico, fecha de registro, operaciones realizadasThe user can edit or delete her profile directly in the application (by clicking on the username in the top bar) or by sending an email to the contact details provided in the terms and conditions (for example, if she has forgotten the password). In the second case, the administrator will request some security questions to validate the credentials such as email, registration date, operations performed, etc.
Once the user has deleted his or her account, all of the user 's information is also deleted as well if the user checked marked it as “private”"private". If the information (ontologies) were checked as “public”was verified as "public", that information will remain.
The user can define the Privacy options according to privacy options in accordance with the GDPR:
- Forget my data: The user can delete any information contained in the
- ontologies that she
- has.
- Revoke consent: The user can revoke any previously given consent:
- View my data: The user can consult that user's data stored in ontologies
- of which she is the owner.
- Forget me:
- The user can delete
- her profile,
- deleting all the information: