Adpoint: Our commitment to the General Data Protection Regulation (GDPR)
The EU General Data Protection Regulation (GDPR) is the most significant piece of European privacy legislation in the last twenty years. It replaces the 1995 EU Data Protection Directive, strengthening the rights that EU individuals have over their data, seeking to unify data protection laws across Europe.
Our customers can count on the fact that Lineup is committed to GDPR compliance across our managed Adpoint services when the GDPR takes effect on May 25, 2018. We will make important updates to contractual commitments that directly address GDPR requirements. We are also a committed partner in our customers’ GDPR compliance efforts. Customers can leverage Lineup services with confidence understanding the robust data protection capabilities built-in to Adpoint.
Where do we stand?
At Lineup, we have always worked diligently to help our customers directly address EU data protection requirements. These efforts have been critical in our ongoing preparations for the GDPR:
- Data processing terms: Strong data protection commitments between cloud providers and customers are fundamental to compliance. Our data processing terms for Adpoint clearly articulate our privacy commitments to customers. We have evolved our terms over the years based on feedback from our customers and regulators. Our terms will be updated for the GDPR as well.
- Third-party audits and certifications: We offer a number of third-party audits and certifications for Adpoint. In 2016, we introduced a new third-party audit SOC1 part II to cover numerous services within Adpoint cloud.
- International data transfers: The GDPR, like the Data Protection Directive it will replace, includes provisions on international data transfer mechanisms. We will be using model contract clauses that have been confirmed to be compliant by European Data Protection Authorities, affirming that Lineup contractual commitments fully meet the requirements to legally frame transfers of data from the EU to the rest of the world, in accordance with the Data Protection Directive.
- Data export: The GDPR includes certain requirements for the export of personal data. The data you store in Adpoint is yours. We strive to include data portability capabilities and are continually working to enhance the robustness of our data export capabilities.
- Incident notifications: GDPR contains requirements around breach notifications. Lineup has always provided a framework around incident notification. We will continue to invest in our security, incident response, threat detection and prevention capabilities.
GDPR Readiness: 5 Things You Can Do Today
Now is a great time for you to begin preparing for the GDPR. Five things you can do today to prepare for GDPR:
- Familiarize yourself with the provisions of the new regulation, particularly how they may differ from your current data protection obligations. Be aware that new requirements may require new agreements with service providers or completely new solutions that meet the stringent requirements ahead.
- Consider creating an updated and precise inventory of personal information that you process (you can use some of our tools like Data Loss Prevention to help).
- Review your current controls and processes to ensure that they're adequate, and build a plan to address any gaps.
- Consider how you can leverage Adpoint compliance capabilities as part of your own regulatory compliance framework. Conduct a review of Adpoint third-party audit materials to see how they may help with this exercise.
- Stay abreast of updated regulatory guidance as it becomes available and consider consulting a legal expert to obtain guidance applicable to you.
Lineup is working to make additional operational changes in light of the new legislation, and will collaborate closely with our customers, partners, and regulatory authorities throughout this process. We have a team who continue to carefully monitor GDPR implementation guidance, and will update our contractual commitments accordingly. We will make our updated data processing amendment available to our customers soon. We are also producing additional materials to assist customers with their due diligence efforts as they prepare for GDPR.
We work to earn the trust of our customers every day. As such, protecting the privacy and security of our customers’ information is a top priority, and compliance is central to this mission. We will continue to evolve our capabilities in accordance with the changing regulatory landscape and work with you to help facilitate your GDPR compliance efforts.