GDPR Compliance
The General Data Protection Regulation (GDPR) is the European Union’s new data protection legislation designed to protect the privacy rights of EU individuals. The GDPR aligns fragmented privacy legislation across EU member states and is the most significant regulation to address modern privacy concerns. The regulation replaces the current EU Data Protection Directive (Directive 95/46/EC).
The purpose of the regulation is to strengthen the privacy rights of individuals in regards to how their personal data is being collected, processed, and used.
OnceHub is ready for the changes and here to help our customers comply with the new regulations.
Who does it affect?
Section titled “Who does it affect?”The GDPR applies to organizations that process the data of EU individuals (even if the business is not EU-based). GDPR regulated data can be stored outside the EU; however, data exports must meet additional requirements to ensure compliance. For example, there must be assurances that the country of transfer provides adequate protections for the data.
To protect personal data, the GDPR requires organizations to implement operational and technological controls. These controls cover:
1. How data is collected
2. The use of the collected data
3. Storage of the data
4. Individual’s rights to their data
GDPR Principles
Section titled “GDPR Principles”The GDPR includes key principles for data protection:
- Fairness and transparency ensures that data processing is transparent and clearly communicated. For example, the OnceHub privacy policy, which is prominently placed on our website, demonstrates this principle.
- Purpose limitation ensures that data is processed for the purpose that was originally intended. For example, at OnceHub, we only use the data we store to provide you with our services. We will never use your data for any other purpose.
- Data minimization and retention ensures data is only collected and retained as necessary. For example, OnceHub allows you to configure the data you wish to collect and data is deleted from our databases when you stop using our service.
- Data security is a key principle that ensures appropriate technical, administrative and physical safeguards are in place to protect your data from unauthorized access. OnceHub has a comprehensive security program that employs a multi-layered control system, designed to protect your data. For example, we continuously monitor our servers for suspicious activity and use advanced threat detection technologies to secure data.
- Individual rights are enforced by the GDPR. An individual has the right to access, retrieve and modify their data. Individuals also have the “right to be forgotten” and for their data to be deleted. OnceHub provides the mechanisms necessary for data subjects and controllers to exercise these rights.
What is OnceHub doing?
Section titled “What is OnceHub doing?”The GDPR establishes comprehensive requirements for the protection of personal data, and OnceHub is committed to maintaining appropriate privacy and data protection practices in accordance with applicable requirements.
As part of this commitment, OnceHub makes its Data Processing Addendum (DPA) available to customers that process personal data through the Services. The DPA addresses key GDPR requirements, including data security, confidentiality, data breach notification, use of subprocessors, and international data transfers.
OnceHub has established internal processes and controls to oversee its privacy and data protection obligations. We regularly review our privacy and security practices, including our breach notification processes, and maintain procedures designed to ensure that customers are notified of applicable personal data breaches in accordance with the DPA and applicable law.
Our DPA also identifies the subprocessors used to provide the Services. OnceHub maintains a process for reviewing subprocessors and provides customers with the rights and notifications regarding the introduction of new subprocessors as set out in the DPA.
These measures are part of OnceHub’s ongoing commitment to protecting personal data and supporting our customers in meeting their privacy and data protection obligations.