Legislation
GDPR. Privacy and security in the same place.
The GDPR asks you to know which personal data you process, why, with whom and how you protect it. Much of the protection already sits in your ISO 27001 controls. Trustbird keeps your privacy records next to those controls, so a supplier, a system or an incident is recorded once and seen from both sides.
- Records of processing linked to systems and suppliers
- Data breaches handled from your incident register
- Privacy measures linked to ISO 27001 controls
What Trustbird keeps for the GDPR
Privacy work is mostly record keeping and follow-up. Trustbird keeps those records in the same model as your management system, so they stay consistent.
Records of processing
Record each processing activity with its purpose, categories of data and people, retention period and the systems and suppliers involved.
Data processing agreements
Keep track of the data processing agreements you have with customers and suppliers, what they cover and when they need another look.
Data protection impact assessments
Record where a DPIA is needed, work through it step by step and link the resulting measures to your risks and controls.
Data breach register
Every security incident can be marked as a personal data breach. You record every breach, including those you do not notify, with the assessment, the decision on notifying the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens, within 72 hours and the follow-up in one place.
Data subject requests
Log requests for access, correction or deletion, assign an owner and track each request against the response period, which is one month as a rule.
Linked to your security controls
Access control, encryption, logging and supplier management are shared with ISO 27001. Evidence you supply there also supports your privacy measures.
Getting your privacy records in order
-
01
Map your processing
Answer questions about the personal data you handle for yourself and for your customers.
-
02
Record agreements
Link data processing agreements to the customers and suppliers they apply to.
-
03
Assess high-risk processing
Identify where a DPIA is needed and work through it with the people involved.
-
04
Keep it current
Handle breaches and requests as they come in and review the records during your management review.
Frequently asked questions
- Is the GDPR a certifiable standard?
- Not in the way you certify against ISO 27001. The GDPR is a regulation, not a management system standard. Trustbird treats it as a set of requirements you keep records for, linked to the controls of the standards you do certify against.
- Does Trustbird decide whether a breach must be reported?
- No. Trustbird helps you record the facts and the assessment. The decision is made by the responsible person in your organization, and Trustbird does not give legal advice.
- We are mostly a processor for our customers. Does this still help?
- Yes. As a processor you still keep records of processing on behalf of customers, manage data processing agreements and support customers with breaches and requests. Trustbird covers those tasks too.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.