Preparation of new basic security documentation for the operator, tailored to their needs, updated in accordance with current legislation, available decision-making and interpretative practice of the authority (internal regulations for the protection of personal data), containing the guidelines described below.
The security documentation contains:
- security policy in accordance with the Regulation, the Act, Decree of the National Security Authority No. 336/2004 Coll. on physical security and facility security, as amended (processing of security strategy in individual areas of security;
- physical and facility security;
- security of information systems in the IT area;
- personnel security with a focus on personal data protection;
- technical and organizational measures (guidelines and procedures for the processing of personal data by authorized persons);
- processing of the scope and permitted activities in the processing of personal (sensitive) data (without processing specific access rights for job positions);
- security risk analysis in the processing of personal data protection pursuant to Articles 25 and 32(2) of the Regulation, in accordance with the STN ISO/IEC 27002 standard – information technology, list of personal data pursuant to Article 13 of the Regulation;
- records of processing operations, if this obligation arises for the client from the results of the basic process analysis;
- documentation on the investigation of security incidents;
- contingency plan;
- templates for the registration of persons processing personal data for the controller (identification and instruction of persons processing personal data for the controller, i.e., authorized persons);
- preparation of a tailored information obligation for data subjects, according to the individual purposes of personal data processing identified at the client's premises during the basic process analysis;
- processing of tailor-made intermediary contracts pursuant to Article 28 of the Regulation for third parties identified in the basic analysis who process personal data on behalf of the client;
- preparation of sample forms necessary to achieve compliance with the GDPR and the law (sample consents to the processing of personal data, guidelines, advice and recommendations on websites, etc.);
- provision of information and explanations on the implementation of established processes and the application of procedures within the client's actual operations, consultation on recommended measures as needed.