GDPR

Frequently asked questions about the GDPR at Acerta

1. Which steps is Acerta taking in the context of the GDPR?

2. Which technical measures has Acerta taken as part of the protection of personal data?

3. Which organisational measures has Acerta taken as part of the protection of personal data?

4. Which measures does Acerta take to guarantee the rights of the person involved?

5. Which measures does Acerta take to detect data leaks?

6. Which measures does Acerta take to report data leaks?

Enter the challenge together with Acerta!

1. Which steps is Acerta taking in the context of the GDPR?

The GDPR applies to all employees within Acerta and all personal data processing operations within Acerta. We therefore elected to address Acerta’s compliance as a company-wide project. In doing so, we engage in different areas and work with the aid of a road map developed in collaboration with an external party that supports us. This road map is based on the thirteen-step plan as developed by the Privacy commission and is intended to assist organisations with their GDPR compliance.

This road map contains items like:

 

Acerta action plan GDPR [pdf - 5.8mb]

2. Which technical measures has Acerta taken as part of the protection of personal data?

At Acerta, we frequently use information that falls within the category of personal privacy. We are fully aware of the sensitive nature of this information.

In the past, we have always implemented the best possible technical measures to protect the privacy of people associated with us (customers, employees, suppliers, …) as carefully as possible and in accordance with the law.

We remain continuously focused on improving our systems. This was already the case before the GDPR became effective. In response to the GDPR, we are performing additional research for potential improvements.

3. Which organisational measures has Acerta taken as part of the protection of personal data?

At Acerta, we frequently use information that falls within the category of personal privacy. We are fully aware of the sensitive nature of this information.

In the past, our organisation has always made every effort to protect the privacy of people we offer our services to (customers, employees, suppliers, …), as efficiently as possible and in accordance with the law.

The introduction of the General Data Protection Regulation (GDPR) motivates us to further refine our approach.

We have taken the following measures:

4. Which measures does Acerta take to guarantee the rights of the person involved?

Acerta recognises that the right to privacy is a fundamental right for each individual and therefore undertakes the necessary measures to guarantee this right, in accordance with the applicable laws and regulation and Acerta’s capacity. Acerta will operate in full compliance with the law and therefore set up the required procedures and processes.

5. Which measures does Acerta take to detect data leaks?

All activity on our systems and network is extensively logged. In addition, we have implemented several control mechanisms that monitor our IT environments and issue an alert in the event of a breach.

In the future, Acerta will expand its resources to detect potential data leaks. For this purpose, we rely on the best techniques available in the area of data loss prevention, security information and event management (SIEM), behaviour analysis, ...

6. Which measures does Acerta take to report data leaks?

Acerta has an incident management process with built-in escalation channel for the reporting and limiting of incidents that involve the loss of data and other security leaks. This process will accommodate the reporting requirement as well, in accordance with the applicable laws and regulation.