GDPR Commitment
TABLE OF CONTENTS
1. The Basics
- AskField is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable data protection laws.
- This GDPR Commitment outlines AskField's approach to protecting personal data and respecting the privacy rights of individuals in the European Economic Area (EEA).
- AskField processes personal data as a Data Processor on behalf of our customers, who act as Data Controllers.
2. GDPR Principles
AskField adheres to the following GDPR principles:
- Lawfulness, fairness, and transparency: We process personal data lawfully, fairly, and transparently.
- Purpose limitation: We collect personal data for specified, explicit, and legitimate purposes.
- Data minimization: We only collect personal data that is necessary for the specified purposes.
- Accuracy: We take steps to ensure personal data is accurate and kept up to date.
- Storage limitation: We retain personal data only for as long as necessary.
- Integrity and confidentiality: We implement appropriate security measures to protect personal data.
- Accountability: We are responsible for demonstrating compliance with GDPR principles.
3. Data Subject Rights
AskField supports the following data subject rights under GDPR:
- Right of access: Individuals have the right to obtain confirmation as to whether their personal data is being processed.
- Right to rectification: Individuals have the right to have inaccurate personal data corrected.
- Right to erasure ("right to be forgotten"): Individuals have the right to request deletion of their personal data.
- Right to restrict processing: Individuals have the right to request restriction of processing in certain circumstances.
- Right to data portability: Individuals have the right to receive their personal data in a structured, commonly used format.
- Right to object: Individuals have the right to object to processing of their personal data.
- Rights related to automated decision-making: Individuals have rights regarding automated decision-making and profiling.
4. Compliance Measures
To ensure GDPR compliance, AskField has implemented:
- Data Processing Addendum (DPA) for customers
- Technical and organizational security measures
- Data protection impact assessments
- Regular staff training on data protection
- Privacy by design and default principles
- Records of processing activities
- Appointment of a Data Protection Officer where required
5. Data Breach Notification
In the event of a personal data breach, AskField will:
- Notify the relevant supervisory authority without undue delay, and where feasible, within 72 hours
- Notify affected customers without undue delay
- Document all breaches, including the facts, effects, and remedial actions taken
6. International Data Transfers
When transferring personal data outside the EEA, AskField ensures appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other mechanisms recognized under GDPR.