Compliance

GDPR

The EU's General Data Protection Regulation governs how organisations process the personal data of individuals inside the EU.

The General Data Protection Regulation (GDPR) has governed the handling of personal data within the EU since May 2018. It also applies to companies outside the EU offering goods or services to people in the EU or monitoring their behaviour in the EU.

How it works

GDPR requires a legal basis for all processing of personal data. It grants data subjects rights of access, rectification, and erasure. Organisations must implement appropriate technical and organisational measures.

A personal data breach must be reported to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to result in a risk. If there is a high risk, the data subjects must also be informed. Fines can reach up to €20 million or 4% of the worldwide annual turnover, whichever is higher.

A practical example: a Swiss online retailer also sells products to customers in Germany. An attacker exfiltrates customer data through a vulnerability. GDPR applies to the German customers. The retailer must report the incident within 72 hours. This requires rapid access to clear details about the affected data and people.

What to look out for

  • Check if you specifically target people in the EU. GDPR will then apply to your organisation.
  • Appoint a representative in the EU if required.
  • Keep a record of your processing activities up to date.
  • Establish a data breach response plan that respects the 72-hour deadline.

Switzerland and regulation

Switzerland has its own law, the revFADP (revised Federal Act on Data Protection). It is similar to GDPR in many respects. The EU recognises Switzerland's level of data protection as adequate. For Swiss companies with EU business, both laws often apply concurrently.

Relevance for the SOC

SOC logs contain personal data such as names, IP addresses and login times. Their processing requires a clear purpose and a defined retention period. The SOC also provides the factual basis required for a notification.

How we implement it

Data is stored in Switzerland or the European Union. In the event of an incident, we provide the details for your notification.

How ANOMAL implements this