View Categories

Vdata – Customer Data Protection

The measures implemented to protect customer data must be appropriate for the technical, security and organisational levels. Only relevant and adequate personal data shall be processed. 

If personal data are stored, this must be limited to what is necessary.

Main Question

Are appropriate measures (technical, security, organizational) in place to protect customer data?

Sub-Questions:

  1. Are there contractual safeguards to protect and restrict the amount of personal data in the event of outsourcing?
  2. Is data privacy addressed by using  publicly available and well-tested cryptographic methods?
  3. Is anonymisation, pseudonymisation and de-identification applied where appropriate?
  4. Is the data processed based on a contract, with the consent of the customer, to comply with legal obligations?
  5. Is personal data kept in a form that permits identification of data subjects for no longer than necessary for the purposes for which it is stored?