Javascript is required
logo-dastralogo-dastra

GDPR Data processing modelGDPR compliance management with Dastra

By: Ludwig Karneth
PrivatePublicCurrentGDPR
The purpose of this processing is to list all activities that are carried out using the Dastra RGPD solution.

Purposes (10)

A purpose is the objective pursued by the setting up of your file. It indicates what the processing of personal data will be used for, its purpose. This purpose must be clear and understandable

1
Management of the register of processing activities
Legal obligation
Article 30 of the RGPD requires the keeping of a register including the names and contact details of the parties involved in a processing operation
2
Register management of processing activity categories
Legal obligation
Article 30 of the RGPD requires the keeping of a register including the names and contact details of the parties involved in a processing operation
3
Compliance task management
Legitimate interest
RGPD compliance
4
Stakeholder directory management
Legitimate interest
5
People rights management
Legal obligation
Articles 15 et seq. of the RGPD
6
Data breach monitoring
Legal obligation
Article 33 of the RGPD
7
Documentation management
Legitimate interest
RGPD compliance
8
Audit management
Legitimate interest
RGPD compliance
9
Cookie consent evidence management
Legitimate interest
RGPD compliance
10
Application activity and security monitoring
Connection history and authorization management
Legitimate interest
Security monitoring on the application

Data categories (8)

Personal data is any information relating to an identified or identifiable natural person. A natural person can be identified either directly (eg surname and first name) or indirectly (eg phone number, social security number, email or postal address, but also voice or image)

rights data

Data details


Postal Addressrequired
Email addressrequired
Follow-up requestrequired
Request Detailrequired
Applicant's first and last namerequired

Data conservation rules

Active base:

Duration of demand management + 1 year

Cookie data

Data details


Consent Cookiesrequired

Data conservation rules

Active base:

Duration of consent

EU representative contact details

Data details


Professional contact detailsrequired
Name and surname of EU representativerequired

Data conservation rules

Active base:

As long as the person is a representative within the EU

Intermediate archiving:

The registers will be archived for 5 years

Article 2224 du code civil

activity data

Data details


Auditsrequired
Comments on the platformrequired
Internal commentsrequired
Activity Historyrequired

Data conservation rules

Active base:

For user accounts, as long as the account is active.

Intermediate archiving:

5 years after cessation of treatment

Data Protection Officer contact details

Data details


Professional contact detailsoptional
Name and surname of the data protection officerrequired

Data conservation rules

Active base:

As long as the person is delegated to data protection

Intermediate archiving:

The registers will be archived for 5 years

Article 2224 du code civil

Identification data

Data details


Profile photograph or avataroptional
business physical addressoptional
Companyrequired
Function optional
phone numberoptional
Email addressrequired
FirstName

Definition

First name of employee, intern and internship tutor

required
name

Definition

Name of the person

required

Data conservation rules

Active base:

For user accounts, for as long as the account is active.For actors, for the lifetime of compliance treatments and actions.

Intermediate archiving:

5 years after cessation of processing

In the event of justification to the supervisory authority

Data controller contact details

Data details


Professional contact detailsrequired
Name and surname of legal representativerequired

Data conservation rules

Active base:

As long as the person is the legal representative of the organization

Intermediate archiving:

Records will be archived for 5 years

General civil prescription rule (article 2224 of the French Civil Code)

Connection data recorded to ensure the security and proper operation of computer applications and networks

Data details


Logout date and timerequired
Date and time of connectionrequired
Identifierrequired

Data conservation rules

Active base:

Log data of connections and actions are kept for one year (security audits)

Data subject (3)

A data subject is any person whose data is collected, retained or processed by the data processing. e.g. In a recruitement process, any candidate for a position proposed in recruitement management process

  • Other
  • Other
  • Customers

Author:
Ludwig Karneth
Ludwig Karneth

Created at:07/08/2023

Updated on:10/29/2023

License: © Creative commons :
Attribution / Pas d'utilisation commerciale
CC-BY-NC AttributionPas d'utilisation commerciale

Nb using:14


Access the full processing template

Try Dastra now to access all of our data processing templates that you can customize for your organization.It's free and there's no obligation for the first 30 days (no credit card required)

Add to my data processings record
Subscribe to our newsletter

We will send you a few emails to keep you informed of our news and what's new in our solution

* You will always be able to unsubscribe on each newsletter. Learn more.