Technical and organisational measures
1. Introduction
1.1. Controller
The controller pursuant to Art. 4 No. 7 of the EU General Data Protection Regulation (GDPR) is comstruct ICT GmbH, Agnes-Pockels-Bogen 1, 80992 München, Germany, email: kontakt@comstruct.com. We are legally represented by Henric Meinhardt.
1.2. Data protection officer
Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, email: datenschutz@heydata.eu.
1.3. Subject of this document
This document summarises the technical and organisational measures taken by the controller within the meaning of Art. 32(1) GDPR. These are measures by which the controller protects personal data. The purpose of this document is to support the controller in fulfilling its accountability obligation under Art. 5(2) GDPR.
2. Confidentiality (Art. 32(1)(b) GDPR)
2.1. Physical access control
The following implemented measures prevent unauthorised persons from gaining physical access to data processing facilities:
- Manual locking system (e.g. keys)
- Visitor logging (e.g. visitor register)
- Visitors accompanied by employees only
- Careful selection of cleaning staff
2.2. System access control
The following implemented measures prevent unauthorised persons from gaining access to data processing systems:
- Authentication with username and password
- Use of antivirus software
- Use of firewalls
- Use of mobile device management
- Use of VPN technology for remote access
- Encryption of data storage media
- Automatic desktop locking
- Encryption of notebooks / tablets
- Management of user permissions
- Creation of user profiles
- Central password rules
- Use of 2-factor authentication
- Visitor logging (e.g. visitor register)
- Key policy / key register
- General company policy on data protection or security
- Company policy on secure passwords
- Company "Clean Desk" policy
- Company policy on the use of mobile devices
- General instruction to lock the desktop manually when leaving the workstation
2.3. Data access control
The following implemented measures ensure that unauthorised persons have no access to personal data:
- Use of document shredders (with cross-cut function)
- Physical erasure of data storage media before reuse
- Logging of data destruction
- Logging of access to applications (particularly when entering, modifying and deleting data)
- Use of an authorisation concept
- The number of administrators is kept as small as possible
- Management of user rights by system administrators
2.4. Separation control
The following measures ensure that personal data collected for different purposes is processed separately:
- Separation of production and test systems
- Encryption of data sets processed for the same purpose
- Logical tenant separation (software-based)
- Definition of database permissions
3. Integrity (Art. 32(1)(b) GDPR)
3.1. Transfer control
It is ensured that personal data cannot be read, copied, modified or removed without authorisation during transmission or storage on data storage media, and that it is possible to verify which persons or bodies have received personal data. The following measures have been implemented to ensure this:
- Establishment of VPN tunnels
- Wi-Fi encryption (WPA2 with a strong password)
- Logging of access and releases
- Provision of data via encrypted connections such as SFTP or HTTPS
- Use of signature procedures
- Creation of an overview of regular release and transmission processes
- Transfer of data in anonymised or pseudonymised form
3.2. Input control
The following measures ensure that it is possible to verify who processed personal data in data processing facilities and at what time:
- Logging of data entry, modification and deletion
- Manual or automatic review of logs
- Traceability of data entry, modification and deletion through individual usernames (not user groups)
- Assignment of rights to enter, modify and delete data on the basis of an authorisation concept
4. Availability and resilience (Art. 32(1)(b) GDPR)
The following measures ensure that personal data is protected against accidental destruction or loss and is always available to the client:
- Regular backups
- Creation of a backup & recovery concept
- Monitoring of the backup process
- Storage of data backups at a secure, off-site location
- Creation of an emergency plan (e.g. BSI IT-Grundschutz 100-4)
- Regular data recovery tests and logging of results
- Hosting (at least of the most important data) with a professional hosting provider
5. Procedures for regularly testing, assessing and evaluating (Art. 32(1)(d) GDPR; Art. 25(1) GDPR)
5.1. Data protection management
The following measures are intended to ensure that an organisational structure meeting the basic requirements of data protection law is in place:
- Use of the heyData platform for data protection management
- Appointment of heyData as data protection officer
- Requiring employees to maintain data confidentiality
- Regular employee training on data protection
- Maintaining a record of processing activities (Art. 30 GDPR)
5.2. Incident response management
The following measures are intended to ensure that notification processes are initiated in the event of personal data breaches:
- Process for notifying supervisory authorities of personal data breaches pursuant to Art. 4 point 12 GDPR (Art. 33 GDPR)
- Process for notifying data subjects of personal data breaches pursuant to Art. 4 point 12 GDPR (Art. 34 GDPR)
- Involvement of the data protection officer in security incidents and data breaches
- Use of antivirus software
- Use of firewalls
5.3. Data protection-friendly default settings (Art. 25(2) GDPR)
The following implemented measures meet the requirements of the principles of "Privacy by design" and "Privacy by default":
- Training employees in "Privacy by design" and "Privacy by default"
- No more personal data is collected than is necessary for the respective purpose.
5.4. Processing instruction controls
The following measures ensure that personal data can only be processed in accordance with instructions:
- Written instructions to the contractor or instructions in text form (e.g. through a data processing agreement)
- Ensuring the destruction of data after completion of the contract, e.g. by requesting corresponding confirmations
- Confirmation from contractors that they require their own employees to maintain data confidentiality (typically in the data processing agreement)
- Careful selection of contractors (particularly with regard to data security)
- Ongoing review of contractors and their activities