GDPR
Appropriate technical and organisational measures are in place to protect PII
Appropriate technical and organisational measures are in place to protect PII
Documented processes are in place to manage subject requests
Documented processes are in place to manage subject requests
Data Processing Agreements are in place with all your sub-processors
Data Processing Agreements are in place with all your sub-processors
Documented process is in place for the deletion/redaction/anonymisation of PII. Describe/attach your deletion policy.
Documented process is in place for the deletion/redaction/anonymisation of PII. Describe/attach your deletion policy.
Data Privacy Impact Assessments are undertaken where a risk to PII is identified
Data Privacy Impact Assessments are undertaken where a risk to PII is identified
A formal data breach notification process is in place
A formal data breach notification process is in place
Does the organisation have security measures in place for data protection?
Does the organisation have security measures in place for data protection?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified under any international privacy jurisdictions?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified under any international privacy jurisdictions?
Are there policies and processes in place to address privacy inquiries, complaints and disputes?
Are there policies and processes in place to address privacy inquiries, complaints and disputes?
If Yes, Does the Vendor also support Surprise Audits by the customer or any Third Paties appointed by the customer
If Yes, Does the Vendor also support Surprise Audits by the customer or any Third Paties appointed by the customer
Does Supplier in its written agreements with Suprocessors prohibit Sub Processors from Processing Personal Data for any purpose except to provide services to Supplier?
Does Supplier in its written agreements with Suprocessors prohibit Sub Processors from Processing Personal Data for any purpose except to provide services to Supplier?
How will the Personal Data be accessed? By the customer BY Supplier
How will the Personal Data be accessed? By the customer BY Supplier
What are Supplier's procedures for responding to a data subject request that involves a customer's Personal Data?
What are Supplier's procedures for responding to a data subject request that involves a customer's Personal Data?
Confirm how Supplier performs audits on its Sub-processors to demonstrate their compliance.
Confirm how Supplier performs audits on its Sub-processors to demonstrate their compliance.
Describe the process in place for the customers to gain access to their personal data as required by the EU regulations
Describe the process in place for the customers to gain access to their personal data as required by the EU regulations
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Does the Cloud Hosting Provider provide independent audit reports (e.g., Service Operational Control - SOC) for their cloud hosting services?
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified under any international privacy jurisdictions? (2)
Is client scoped data collected, accessed, transmitted, processed, or retained that can be classified under any international privacy jurisdictions? (2)
Are there policies and processes in place to address privacy inquiries, complaints and disputes? (2)
Are there policies and processes in place to address privacy inquiries, complaints and disputes? (2)
Contract shall require supplier to comply with all applicable privacy and data security laws, e.g. EU Data privacy directive, (future GDPR) and preferrably have a specialized resource assigned with clear responsibilities to safeguard data protection and privacy. The solution should address data soverignty issues providing solutions to the customer been compliant with local regulations and laws for all countries the customer has operations.
Contract shall require supplier to comply with all applicable privacy and data security laws, e.g. EU Data privacy directive, (future GDPR) and preferrably have a specialized resource assigned with clear responsibilities to safeguard data protection and privacy. The solution should address data soverignty issues providing solutions to the customer been compliant with local regulations and laws for all countries the customer has operations.
Contract requires an immediate notification to the customer of circumstances that might suggest a breach has occurred, along with cooperation in investigation and remediation.
Contract requires an immediate notification to the customer of circumstances that might suggest a breach has occurred, along with cooperation in investigation and remediation.
1) Are you subject to the requirement of appointing a DPO under GDPR art. 37? 2) If yes, have you appointed such a Data Protection Officer, with the qualifications, tasks and position that follows from GDPR art. 37 – art. 39?
1) Are you subject to the requirement of appointing a DPO under GDPR art. 37? 2) If yes, have you appointed such a Data Protection Officer, with the qualifications, tasks and position that follows from GDPR art. 37 – art. 39?
Describe how the principles of Data Protection by Design and Default, as described in GDPR art. 25, have been or may be implemented in the services that you offer to the customer.
Describe how the principles of Data Protection by Design and Default, as described in GDPR art. 25, have been or may be implemented in the services that you offer to the customer.
Describe how you will be able to delete or fully anonymize Personal Data elements or Personal Data relating to specific individuals from the information systems that will be used to deliver the services to the customer, both during the engagement and upon termination. In addition, please describe how deletion or anonymization will cover Personal Data held in any back-up copies or by any (sub) processors.
Describe how you will be able to delete or fully anonymize Personal Data elements or Personal Data relating to specific individuals from the information systems that will be used to deliver the services to the customer, both during the engagement and upon termination. In addition, please describe how deletion or anonymization will cover Personal Data held in any back-up copies or by any (sub) processors.
Does the cloud provider comply with the data privacy regulations incl. GDPR?
Does the cloud provider comply with the data privacy regulations incl. GDPR?
Does the Cloud provider offer any regulatory compliant data processor agreement? EU Standard Contractual Clauses for the transfer or availability of data outside the EU is regulatory compliant if used correctly. Please note, access to data from abroad is normally considered transfer of data even if the data is stored in country.
Does the Cloud provider offer any regulatory compliant data processor agreement? EU Standard Contractual Clauses for the transfer or availability of data outside the EU is regulatory compliant if used correctly. Please note, access to data from abroad is normally considered transfer of data even if the data is stored in country.
Does the contract ensure that Supplier is obliged to support the customer in facilitating exercise of data subjects' rights such as access/correct/erase their data, and (where applicable) notify the customer of any data breaches affecting the customer's data?
Does the contract ensure that Supplier is obliged to support the customer in facilitating exercise of data subjects' rights such as access/correct/erase their data, and (where applicable) notify the customer of any data breaches affecting the customer's data?
Does the contract clarify Supplier's responsibilities to notify the customer in the event of any data breach which affects the customer's data?
Does the contract clarify Supplier's responsibilities to notify the customer in the event of any data breach which affects the customer's data?
Does the contract ensure that Supplier is obliged to co-operate with regard to the customer's right to monitor / audit processing operations?
Does the contract ensure that Supplier is obliged to co-operate with regard to the customer's right to monitor / audit processing operations?
Does the contract specify the conditions for returning the personal data and destroying the data once the service is concluded?
Does the contract specify the conditions for returning the personal data and destroying the data once the service is concluded?
Does the contract include specific safeguards like Privacy Shield arrangement, standard contractual clauses (SCC) or binding corporate rules to regulate transfers of data to non-adequate third countries?
Does the contract include specific safeguards like Privacy Shield arrangement, standard contractual clauses (SCC) or binding corporate rules to regulate transfers of data to non-adequate third countries?
How does the cloud provider provide customer data at end of term? (Data portability and methodology to be followed). Transfer technology, file formats, protocols, metadata etc.
How does the cloud provider provide customer data at end of term? (Data portability and methodology to be followed). Transfer technology, file formats, protocols, metadata etc.
Are you complaint with Data Privacy standards like GDPR?
Are you complaint with Data Privacy standards like GDPR?
Link to GDPR Compliance Page or Privacy Policy page
Link to GDPR Compliance Page or Privacy Policy page
Is Data Processing Agreement (DPA) available publically? If available, provide the link.
Is Data Processing Agreement (DPA) available publically? If available, provide the link.
List of subprocessors
List of subprocessors
What are the Personal Information collected? Also mention the mandatory and optional fields.
What are the Personal Information collected? Also mention the mandatory and optional fields.
If it involves data of the users in the EU region, does it comply with the GDPR regulations? For example, user data should not leave the EU physical geography?
If it involves data of the users in the EU region, does it comply with the GDPR regulations? For example, user data should not leave the EU physical geography?
Information hosted and processed
Information hosted and processed
When would UP be notified?
When would UP be notified?
Do your sub-processors (vendors) access your customer's information? If YES, please complete our PII Data Sub-processor Template
Do your sub-processors (vendors) access your customer's information? If YES, please complete our PII Data Sub-processor Template
Do these sub-processors (vendors) contractually comply with your security standards for data processing?
Do these sub-processors (vendors) contractually comply with your security standards for data processing?
(Only applicable if your company/data centers are based in the US) For the provision of services, do you process EU citizens' personal data?
(Only applicable if your company/data centers are based in the US) For the provision of services, do you process EU citizens' personal data?
Have you appointed a Data Protection Officer (DPO)?
Have you appointed a Data Protection Officer (DPO)?
Do you plan on being Privacy Shield certified withing the next 12 months?
Do you plan on being Privacy Shield certified withing the next 12 months?
Describe or attach your Security Incident Response Program?
Describe or attach your Security Incident Response Program?
Do you have formally defined criteria for notifying a client during an incident that might impact the security of their data or systems? What are your SLAs for notification?
Do you have formally defined criteria for notifying a client during an incident that might impact the security of their data or systems? What are your SLAs for notification?
Data Protection Training and Awareness – Indicate what awareness-raising controls are carried out with regards to colleagues
Data Protection Training and Awareness – Indicate what awareness-raising controls are carried out with regards to colleagues
Managing personal data breaches - Indicate whether IT incidents are subject to a documented and tested management procedure
Managing personal data breaches - Indicate whether IT incidents are subject to a documented and tested management procedure
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
When a person working with the customer data no longer performs that role, are their permissions to the customer data revoked?
Service provider shall include commitment for response time in the event of security incident in line with the customer requirements
Service provider shall include commitment for response time in the event of security incident in line with the customer requirements
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
Describe your security model, including network, data, and application security; data center security; application and system support; upgrades and maintenance; and personnel access rights.
Has the retention period of the collected PII data decided?
Has the retention period of the collected PII data decided?
Does the application have the feasibility to cater to data subject access requests for erasure, restriction and data portability?
Does the application have the feasibility to cater to data subject access requests for erasure, restriction and data portability?
Do you ensure that the data processing is restricted to as required by the signed TCS contract?
Do you ensure that the data processing is restricted to as required by the signed TCS contract?
Do you have personal data breach management process defined and followed?
Do you have personal data breach management process defined and followed?
Do you have processes to identify data subject requests and direct them to TCS where TCS is the Data Controller and support TCS in the execution of these requests?
Do you have processes to identify data subject requests and direct them to TCS where TCS is the Data Controller and support TCS in the execution of these requests?
Does this application have any personal data touch points? (Collect / Store / Process / Transfer)
Does this application have any personal data touch points? (Collect / Store / Process / Transfer)
Does this application have personal information of EU citizens as well?
Does this application have personal information of EU citizens as well?
Whose personal information is being collected? (ex. Customer, Vendor, Employee, Visitor etc.)
Whose personal information is being collected? (ex. Customer, Vendor, Employee, Visitor etc.)
Does the application perform any automatic decision making (arriving at a decision solely on the basis of processing of PII automatically) or profiling on the PII captured?
Does the application perform any automatic decision making (arriving at a decision solely on the basis of processing of PII automatically) or profiling on the PII captured?
Is a privacy notice displayed to the Data Subject?
Is a privacy notice displayed to the Data Subject?
Is consent taken and recorded from the Data Subject?
Is consent taken and recorded from the Data Subject?
Do you have a defined retention period for personal data categories selected above? Please mention the agreed retention period.
Do you have a defined retention period for personal data categories selected above? Please mention the agreed retention period.
If Yes, do you provide the Data Subject the option to Opt-out or Unsubscribe?
If Yes, do you provide the Data Subject the option to Opt-out or Unsubscribe?
Is the application managed or maintained by any external third-party? (Third party having access to the personal data elements selected above)
Is the application managed or maintained by any external third-party? (Third party having access to the personal data elements selected above)
Do you consider yourself the data owner or data processor?
Do you consider yourself the data owner or data processor?
Do you meet international privacy requirements? (GDPR, NDB Scheme, PDPA)
Do you meet international privacy requirements? (GDPR, NDB Scheme, PDPA)
How long will our data be retained for? Does the service provider have a data retention and disposal policy?
How long will our data be retained for? Does the service provider have a data retention and disposal policy?
What arrangements are in place for return of data to corporate upon contract conclusion or termination?
What arrangements are in place for return of data to corporate upon contract conclusion or termination?
What arrangements are in place for deletion of data upon contract conclusion or termination?
What arrangements are in place for deletion of data upon contract conclusion or termination?
Please reconfirm or confirm the following: The company will notify Nova Professional Services of an incident or data breach within 24 hours. The company agrees to keep Nova Professional Services fully informed of incident response and investigation.
Please reconfirm or confirm the following: The company will notify Nova Professional Services of an incident or data breach within 24 hours. The company agrees to keep Nova Professional Services fully informed of incident response and investigation.
Have you identified all legal/regulatory requirements that your company is supposed to adhere to? Please list the key ones. How do you ensure compliance to the same? Please describe
Have you identified all legal/regulatory requirements that your company is supposed to adhere to? Please list the key ones. How do you ensure compliance to the same? Please describe
Do you have a process to manage any request arising from Infosys end on data subject rights, towards access, rectify, erase or restrict processing, to the extent such request extends to processing of personal data as part of your service.
Do you have a process to manage any request arising from Infosys end on data subject rights, towards access, rectify, erase or restrict processing, to the extent such request extends to processing of personal data as part of your service.
Is only required data is displayed and transmitted by the application?
Is only required data is displayed and transmitted by the application?
CCPA/CPRA
What are the regulations around indemnity/liability for data privacy breaches?
What are the regulations around indemnity/liability for data privacy breaches?
The PII protection standards met by the cloud service provider.
The PII protection standards met by the cloud service provider.
