GDPR FAQ
Who is responsible for maintaining a data processing agreement?
It is a shared responsibility among the companies involved.
What type of personal data is in our systems?
The following applies to Chemsoft
Mandatory information
- Username
- Email address
Optional information
- First and last name
- Title
- Phone number
Where is the data stored?
Within the EU.
There is personal data in our risk assessments. Is it okay to save it according to GDPR?
A: Regarding risk assessments, other regulations apply, and saving personal data is OK.
Who is responsible for the removal of personal data when an employee terminates employment?
Data Controller.
We save personal data in History and in the risk assessment functions. Is it okay to save it here?
We use personal data deemed necessary for the system.
What measures have we taken to ensure the transfer of personal data?
This is done through SCC agreements, i.e., Standard Contractual Clauses (SCC)
When is the transfer outside the EU/EEA allowed?
Under certain conditions, it is allowed to transfer personal data outside the EU/EEA-
There is a decision from the EU Commission that a specific country outside the EU/EEA ensures an adequate level of protection
Appropriate safeguards have been taken, such as Binding Corporate Rules (BCR) or Standard Contractual Clauses (SCC).
Special situations and individual cases.