Skip to content

Home › Blog

Blog

We Are Fiber follows GDPR procedures to protect customer data

We Are Fiber segue le procedure GDPR a tutela dei dati dei clienti

On 24 May 2016, Regulation (EU) 2016/679 — known as GDPR (General Data Protection Regulation) — came into force, introducing a new approach to privacy and providing a unified set of rules on data processing that responds to the new challenges brought about by technological evolution and globalisation.

The legislation contained in EU Regulation 2016/679 aims to protect the confidentiality of personal data, to prevent improper use of it from damaging or harming everyone’s fundamental freedoms and personal dignity.

This is even more evident in the reality of a company that daily processes a plurality of personal data, most often concerning the identification and payment details of customers and employees.

Fiber Group quickly adapted to the new privacy context, in order to offer all the required guarantees to the companies that have chosen it and will choose it as a reliable partner for their business.

How to protect personal privacy data?

compliance with GDPR legislation

In particular, the data processed by Fiber Group, indispensable for the delivery and management of the requested services, is used by staff in compliance with professional secrecy, official secrecy and the rights of the data subject (articles 12 to 22 of the GDPR) and is therefore based on principles of legitimacy, fairness, lawfulness, indispensability, relevance and non-excess with respect to the purposes for which the data was collected, in compliance with the provisions of the GDPR.

One of the most significant innovations of the Regulation is the introduction of the principle of accountability, which assigns to data controllers the task of ensuring, and being able to demonstrate, compliance with the principles applicable to the processing of personal data.

Fiber Group Sh.p.k., in order to implement the aforementioned principle, protects data from the design stage, through technical and organisational measures (By Design), and puts in place appropriate technical and organisational measures in order to ensure that, by default, only the data necessary for the specific purposes of the processing is processed (By Default).

The path taken by the company to obtain certification

Again by virtue of the aforementioned principle, thanks to its rigorous approach to privacy, security and compliance, Fiber Group Sh.p.k has an extensive compliance portfolio in the sector.

After a period of documentary implementation to comply with the rules of GDPR 679/2016, and after passing first-party audits, carried out internally, and second-party audits, carried out by our commercial partners, the company autonomously requested a third-party audit carried out by a certification body which, finding full compliance, issued the certificate of conformity with GDPR 679/2016.

Furthermore, in full compliance with the requirements for the assessment and treatment of information security risks, Fiber Group has also obtained ISO/IEC 27001 certification.

Staff training and awareness

The company organises data-security training courses, including courses dedicated to staff. It is essential to ensure that employees and suppliers respect and are aware of their responsibilities regarding data security. Staff with specific security responsibilities or with privileged access to company security systems are adequately trained and qualified.

Getting to know the role of the Data Protection Officer

Regulation (EU) 2016/679 introduces the role of the Data Protection Officer; Fiber Group has appointed a data protection officer, whose tasks are precisely indicated in the GDPR at article 39 and are essentially three: to inform, to monitor and to cooperate.

The Regulation establishes the need to appoint the Data Protection Officer (DPO), that is, the natural person, legal entity, public administration or body that processes personal data on behalf of the data controller. For these reasons the appointment of the DPO was indispensable for Fiber Group, which pays the utmost attention to the processing of personal data.

The DPO fundamentally has the task of informing and advising the controller or processor and the employees who carry out the processing. In addition, the DPO must monitor compliance with the effective observance of data protection and retention according to the regulation, as well as the responsibility and training of the staff in charge of processing.

If requested, the DPO is consulted to provide an opinion regarding the data protection impact assessment, as established by article 35. Finally, the DPO must cooperate actively with the supervisory authorities, representing a point of reference in all matters relating to processing.

Facebook
Twitter
LinkedIn
Try & Buy

Start with a pilot project.
Scale with confidence.

With the Try & Buy formula you can test the service for up to 3 months before choosing us come partner. Analizziamo i tuoi flussi, definiamo insieme il perimetro e attiviamo un team dedicato a rischio contenuto.