By Simon Zeller October 22, 2021
Assessment
Determining the regulatory framework to be considered is the first and vital step on the path to regulatory compliance. To decide whether you are covered under GDPR, DSGVO or DSV-CH, you need to consider both the ‘material scope’ (i.e. whether your processing activity is regulated by the according framework), and the ’territorial scope’ (i.e. wether you are in a jursidiction where the framework applies).
Together with our partners we will assess your business to determine the regulatory frameworks concerned.
Material Scope
GDPR, DSGVO, and DSV-CH apply to the processing of personal information. Whether the process is carried out automatically, partially automated, or manual is of no concern. The regulations focus on processing data such including collecting, recording, storing, accessing, viewing, using, analyzing, combining, disclosing, or deleting data, and therefore most certainly apply to your organization.
Terrotorial Scope
Whether you are in the jurisdiction concerned is depending on your business (i.e. your location as data controller, or your mandated data processors) as well as the location of your clients (i.e. data subjects). If one of these falls into the jurisdiction, you must comply to the corresponding regulations
- Territorial Scope
- Material Scope
- Data Flow Analysis
- Gap Analysis
Action Plan
The action plan highlights the path to regulatory compliance
- Consulting by Ergonomics for project scope, data flow analysis and gap analysis
- Implementing eStealth suite to fullfill technical regulatory requirements