What is GDPR
The General Data Protection Regulation (“GDPR”) is the European privacy regulation which replaced the EU Data Protection Directive (“Directive 95/46/EC”). The GDPR addresses the processing of personal data and the free movement of such data. It aims to strengthen the security and protection of personal data in the EU and harmonize EU data protection law. Broadly, it sets out a number of data protection principles and requirements which must be adhered to when personal data is processed.
The GDPR also established the European Data Protection Board (“EPDB”), which ensures that the data protection law is applied consistently across the EU and works to ensure effective cooperation amongst data protection authorities.
How does this apply to Orlo’s customers?
Customers that collect and store personal data are considered data controllers under the GDPR. Data controllers bear the primary responsibility for ensuring that their processing of personal data is compliant with relevant EU data protection law, including the GDPR and uniquely determine what personal data is submitted to, and processed by, Orlo in accordance with the Services.
Are the systems used by Orlo GDPR compliant?
We have carried out a Privacy Impact Assessment of our software, systems and services and have made changes to ensure we meet and, in some cases, exceed GDPR requirements.
Our system architecture was developed with data protection and data security in mind. The databases in which your personal data is stored are only accessible by a small division of the internal development team who are internally vetted and have worked for us for a substantial amount of time. If you would like to find out more about our security and infrastructure please see our public Security & Compliance Page
As a data processor, how do we handle requests made by End-Users?
If Orlo receives a data subject request from a Subscriber’s End-User (i.e., a user of the Services to whom a Subscriber has provided our Services), Orlo is the Processor, and Orlo will, to the extent that applicable legislation does not prohibit Orlo from doing so, promptly inform the End-User to contact our Subscriber (i.e. the Controller) directly about any request relating to his/her Personal Data such as access or deletion. Orlo will not further respond to a data subject request without the Subscriber’s prior consent.
Does Orlo need access to your systems?
We do not need access to your system unless requested for training or demo purposes.
Will Orlo help us comply with data subject rights?
You have full control over your user data and data from followers so you should be able to manage all data subject rights yourself just by using the application. If you need any specific guidance on how to do this, you can use our ‘help’ feature in the application, consult our user guide or use our online chat facility.
Will we be able to audit Orlo premises and systems for compliance?
You will appreciate how important it is that our systems and premises ensure confidentiality for all of our clients and we do not normally allow clients to have access. We do, however, engage an external CREST accredited specialist to check our systems and provide a report on compliance each year and we are happy to make that available to you for your peace of mind. You can find a copy of the latest report here
Of course, if a court or regulatory body requires us to give you access, we will honour that requirement but will require that you comply with our security and health and safety requirements in doing so.