Assessing compliance readiness

By Simon Zeller October 22, 2021

Assessment

Determining the regulatory framework to be considered is the first and vital step on the path to regulatory compliance. To decide whether you are covered under GDPR, DSGVO or DSV-CH, you need to consider both the ‘material scope’ (i.e. whether your processing activity is regulated by the according framework), and the ’territorial scope’ (i.e. wether you are in a jursidiction where the framework applies).

Together with our partners we will assess your business to determine the regulatory frameworks concerned.

Material Scope

GDPR, DSGVO, and DSV-CH apply to the processing of personal information. Whether the process is carried out automatically, partially automated, or manual is of no concern. The regulations focus on processing data such including collecting, recording, storing, accessing, viewing, using, analyzing, combining, disclosing, or deleting data, and therefore most certainly apply to your organization.

Terrotorial Scope

Whether you are in the jurisdiction concerned is depending on your business (i.e. your location as data controller, or your mandated data processors) as well as the location of your clients (i.e. data subjects). If one of these falls into the jurisdiction, you must comply to the corresponding regulations

  • Territorial Scope
  • Material Scope
  • Data Flow Analysis
  • Gap Analysis

Action Plan

The action plan highlights the path to regulatory compliance

  • Consulting by Ergonomics for project scope, data flow analysis and gap analysis
  • Implementing eStealth suite to fullfill technical regulatory requirements