SlideShare une entreprise Scribd logo
1  sur  5
Télécharger pour lire hors ligne
ALTOUR INTERNATIONAL INC
1270 Avenue of the Americas,
New York, NY 10020
Tel: 1 (800) 4 ALTOUR
altour.gdpr@altour.co.uk
ALTOUR – www.altour.com
ALTOUR GDPR Compliance Statement
Introduction
The EU General Data Protection Regulation (“GDPR”) came into force across the European Union on
25th May 2018 and brings with it the most significant changes to data protection law in two decades.
Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet
the requirements of the digital age.
The 21st Century brings with it broader use of technology, new definitions of what constitutes
personal data, and a vast increase in cross-border processing. The new Regulation aims to standardise
data protection laws and processing across the EU; affording individuals stronger, more consistent
rights to access and control their personal information.
Our Privacy Policy can be found here: http://www.altour.com/Privacy-Policy
Our Commitment
ALTOUR is committed to ensuring the security and protection of the personal information that we
process, and to provide a compliant and consistent approach to data protection. We have always had
a robust and effective data protection program in place which complies with existing law and abides
by the data protection principles. However, we recognise our obligations in updating and expanding
this program to meet the demands of the GDPR and the UK’s Data Protection Bill.
At ALTOUR, we are dedicated to safeguarding the personal information under our remit and in
developing a data protection regime that is effective, fit for purpose and demonstrates an
understanding of, and appreciation for the new Regulation. Our preparation and objectives for GDPR
compliance have been summarised in this statement and include the development and
implementation of new data protection roles, policies, procedures, controls and measures to ensure
maximum and ongoing compliance.
How ALTOUR is complying with the GDPR
Currently, ALTOUR maintains a consistent level of data protection and security across our
organization, and we have implemented the necessary policies and procedures to ensure compliance
with the GDPR and the UK’s Data Protection Bill by 25th May 2018. Our preparation includes: -
• Information Audit – Our GDPR compliance program includes an ongoing company-wide
information audit to continuously identify and assess what personal information we hold,
where it comes from, how and why it is processed and if and to whom it is disclosed. We also
main
• Policies & Procedures – We have revised and implemented new data protection policies and
procedures to meet the requirements and standards of the GDPR and any relevant data
protection laws, including: -
ALTOUR INTERNATIONAL INC
1270 Avenue of the Americas,
New York, NY 10020
Tel: 1 (800) 4 ALTOUR
altour.gdpr@altour.co.uk
ALTOUR – www.altour.com
o Data Protection – Our main policy and procedure document for data protection has
been overhauled to meet the standards and requirements of the GDPR. Accountability
and governance measures are in place to ensure that we understand and adequately
disseminate and evidence our obligations and responsibilities; with a dedicated focus
on privacy by design and the rights of individuals.
o Data Retention & Erasure – We have updated our retention policy and schedule to
ensure that we meet the ‘data minimisation’ and ‘storage limitation’ principles and
that personal information is stored, archived and destroyed compliantly and ethically.
We have dedicated erasure procedures in place to meet the new ‘Right to Erasure’
obligation and are aware of when this and other data subject’s rights apply; along with
any exemptions, response timeframes and notification responsibilities.
o Data Breaches – Our breach procedures ensure that we have safeguards and measures
in place to identify, assess, investigate and report any personal data breach at the
earliest possible time. Our procedures are robust and have been disseminated to all
employees, making them aware of the reporting lines and steps to follow.
o International Data Transfers & Third-Party Disclosures – Where ALTOUR stores or
transfers personal information outside the EU, we have robust procedures and
safeguarding measures in place to secure, encrypt and maintain the integrity of the
data. Our procedures include a continual review of the countries with sufficient
adequacy decisions, as well as provisions for binding corporate rules; standard data
protection clauses or approved codes of conduct for those countries without. We carry
out strict due diligence checks with all recipients of personal data to assess and verify
that they have appropriate safeguards in place to protect the information, ensure
enforceable data subject rights and have effective legal remedies for data subjects
where applicable.
o Subject Access Request (SAR) – We have revised our SAR procedures to accommodate
the revised 30-day timeframe for providing the requested information and for making
this provision free of charge. Our new procedures detail how to verify the data subject,
what steps to take for processing an access request, what exemptions apply and a suite
of response templates to ensure that communications with data subjects are
compliant, consistent and adequate.
• Legal Basis for Processing - We have reviewed and continue to review all processing activities
to identify the legal basis for processing and ensuring that each basis is appropriate for the
activity it relates to. Where applicable, we also maintain records of our processing activities,
ensuring that our obligations under Article 30 of the GDPR and Schedule 1 of the Data
Protection Bill are met.
o If you are a current customer, an employee, or a job applicant, the personal
information we hold, may be used because it is necessary for the performance of the
services contract to which you are a party, because it is necessary for our legitimate
interest in processing such personal information in the context in which you provided it
to us, or for another lawful basis. We will endeavor to inform you of the legal basis for
collection of your personal information prior to or at the time we collect it.
ALTOUR INTERNATIONAL INC
1270 Avenue of the Americas,
New York, NY 10020
Tel: 1 (800) 4 ALTOUR
altour.gdpr@altour.co.uk
ALTOUR – www.altour.com
o If you are a prospective customer, the personal information we collect, and use is
necessary for our legitimate interest in providing you with information about the
services we offer, and about which you have expressed an interest or that we believe
will be of benefit to you. If another legal basis applies to our collection and use of your
data, we will endeavor to inform you prior to or at the time we collect it.
o In some cases, our legal basis for collecting your personal data is because you have
expressly consented to our collection and use of your personal information.
o If you object to the processing of your personal information under these basis, please
contact our privacy team at altour.gdpr@altour.co.uk .
• Privacy Notice/Policy – We have revised our Privacy Notice(s) to comply with the GDPR,
ensuring that all individuals whose personal information we process have been informed of
why we need it, how it is used, what their rights are, who the information is disclosed to and
what safeguarding measures are in place to protect their information.
• Obtaining Consent - We have revise our consent mechanisms for obtaining personal data,
ensuring that individuals understand what they are providing, why and how we use it and
giving clear, defined ways to consent to us processing their information. We have developed
stringent processes for recording consent, making sure that we can evidence an affirmative
opt-in, along with time and date records; and an easy to see and access way to withdraw
consent at any time.
• Direct Marketing - We have revised the wording and processes for direct marketing, including
clear opt-in mechanisms for marketing subscriptions; a clear notice and method for opting out
and providing unsubscribe features on all subsequent marketing materials.
• Data Protection Impact Assessments (DPIA) – Where we process personal information that is
considered high risk, involves large scale processing or includes special category/criminal
conviction data; we have developed stringent procedures and assessment templates for
carrying out impact assessments that comply fully with the GDPR’s Article 35 requirements.
We have implemented documentation processes that record each assessment, allow us to rate
the risk posed by the processing activity and implement mitigating measures to reduce the risk
posed to the data subject(s).
• Processor Agreements – Where we use any third-party to process personal information on our
behalf (i.e. Payroll, Recruitment, Hosting etc), we have drafted compliant Processor
Agreements and due diligence procedures for ensuring that they (as well as we), meet and
understand their/our GDPR obligations. These measures include initial and ongoing reviews of
the service provided, the necessity of the processing activity, the technical and organisational
measures in place and compliance with the GDPR.
• Special Categories Data - where we obtain and process any special category information, we
do so in complete compliance with the Article 9 requirements and have high-level encryptions
and protections on all such data. Special category data is only processed where necessary and
is only processed where we have first identified the appropriate Article 9(2) basis or the Data
Protection Bill Schedule 1 condition. Where we rely on consent for processing, this is explicit
with the right to modify or remove consent being clearly signposted.
ALTOUR INTERNATIONAL INC
1270 Avenue of the Americas,
New York, NY 10020
Tel: 1 (800) 4 ALTOUR
altour.gdpr@altour.co.uk
ALTOUR – www.altour.com
Data Subject Rights
In addition to the policies and procedures mentioned above that ensure individuals can enforce their
data protection rights, we provide easy to access information via our website of an individual’s right
to access any personal information that ALTOUR processes about them and to request information
about: -
• What personal data we hold about them
• The purposes of the processing
• The categories of personal data concerned
• The recipients to whom the personal data has/will be disclosed
• How long we intend to store your personal data for
• If we did not collect the data directly from them, information about the source
• The right to have incomplete or inaccurate data about them corrected or completed and the
process for requesting this
• The right to request erasure of personal data (where applicable) or to restrict processing in
accordance with data protection laws, as well as to object to any direct marketing from us and
to be informed about any automated decision-making that we use
• The right to lodge a complaint or seek judicial remedy and who to contact in such instances
Information Security & Technical and Organisational Measures
ALTOUR takes the privacy and security of individuals and their personal information very seriously
and take every reasonable measure and precaution to protect and secure the personal data that we
process. We have robust information security policies and procedures in place to protect personal
information from unauthorised access, alteration, disclosure or destruction and have several layers of
security measures, including Technical security measures such as;
• Secure Inventory and Asset management for all Hardware & Software assets containing EU
residents’ data.
• Secure Network Architecture and proper data segregation
• Secure configuration standards for Hardware and Software assets
• A continuous vulnerability management and remediation program
• Proper Identity and Access Management controls
• Secure maintenance, monitoring and analysis of audit logs
• Proper Intrusion prevention, Perimeter and Malware Defenses
• A well-test and functioning Disaster Recovery & Business Continuity Program
• Data-at-Rest & Data-in-Transit protections such as Data loss prevention and encryption
• Access to customer data is controlled on a need-to-know basis and monitored.
• All employees undergo mandatory privacy and security awareness training on a regular basis.
• A functioning incidence response and management program
• Annual and Quarterly Security Assessments are conducted by an external 3rd party security
company.
ALTOUR INTERNATIONAL INC
1270 Avenue of the Americas,
New York, NY 10020
Tel: 1 (800) 4 ALTOUR
altour.gdpr@altour.co.uk
ALTOUR – www.altour.com
GDPR Roles and Employees
ALTOUR has designated an internal Data Privacy Officer and have appointed a data privacy team to
develop and implement our roadmap for complying with the new data protection Regulation. The
team are responsible for promoting awareness of the GDPR across the organisation, assessing our
GDPR readiness, identifying any gap areas and implementing the new policies, procedures and
measures.
ALTOUR understands that continuous employee awareness and understanding is vital to the
continued compliance of the GDPR and have involved our employees in our preparation plans. We
have implemented an employee training program specific to the which will be provided to all
employees prior to May 25th, 2018, and forms part of our induction and annual training program.
If you have any questions about our preparation for the GDPR, please contact our Data Privacy Team
at altour.gdpr@altour.co.uk

Contenu connexe

Tendances

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014Rachel Aldighieri
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...Harrison Clark Rickerbys
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...Harrison Clark Rickerbys
 
[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul Lanois[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul LanoisAIIM International
 
Data Processing - data privacy and sensitive data
Data Processing - data privacy and sensitive dataData Processing - data privacy and sensitive data
Data Processing - data privacy and sensitive dataOpenAIRE
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsHarrison Clark Rickerbys
 
Privacy Ordinance in Hong Kong
Privacy Ordinance in Hong KongPrivacy Ordinance in Hong Kong
Privacy Ordinance in Hong Kong若水 鲁
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Robert MacLean
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparationPromapp Solutions
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Actmrmwood
 
Legal and data protection update
Legal and data protection updateLegal and data protection update
Legal and data protection updateRachel Aldighieri
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processingTim Gough
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentationOvationsGroup
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data SecurityWilmerHale
 
Intro to information governance booklet
Intro to information governance bookletIntro to information governance booklet
Intro to information governance bookletGerardo Medina
 

Tendances (19)

GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014An introduction to data protection - 30 Jan 2014
An introduction to data protection - 30 Jan 2014
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 
[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul Lanois[AIIM18] GDPR: whose job is it now? - Paul Lanois
[AIIM18] GDPR: whose job is it now? - Paul Lanois
 
Data Processing - data privacy and sensitive data
Data Processing - data privacy and sensitive dataData Processing - data privacy and sensitive data
Data Processing - data privacy and sensitive data
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Privacy Ordinance in Hong Kong
Privacy Ordinance in Hong KongPrivacy Ordinance in Hong Kong
Privacy Ordinance in Hong Kong
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
A practical guide to GDPR preparation
A practical guide to GDPR preparationA practical guide to GDPR preparation
A practical guide to GDPR preparation
 
Data Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service OverviewData Protection & GDPR Health Check Service Overview
Data Protection & GDPR Health Check Service Overview
 
Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?Payroll Data & GDPR: What you need to know?
Payroll Data & GDPR: What you need to know?
 
Data Protection Act
Data Protection ActData Protection Act
Data Protection Act
 
Legal and data protection update
Legal and data protection updateLegal and data protection update
Legal and data protection update
 
Building a register of data processing
Building a register of data processingBuilding a register of data processing
Building a register of data processing
 
POPI Act compliance presentation
POPI Act compliance presentationPOPI Act compliance presentation
POPI Act compliance presentation
 
Popi act presentation
Popi act presentationPopi act presentation
Popi act presentation
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
Intro to information governance booklet
Intro to information governance bookletIntro to information governance booklet
Intro to information governance booklet
 

Similaire à ALTOUR GDPR Compliance Statement v4

Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyRay ABOU
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Data Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance StrategiesData Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance StrategiesShyamMishra72
 
GDPRpresentationFeb-Apr2018.pptx
GDPRpresentationFeb-Apr2018.pptxGDPRpresentationFeb-Apr2018.pptx
GDPRpresentationFeb-Apr2018.pptxpixvilx
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law Owako Rodah
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")Parsons Behle & Latimer
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...Financial Poise
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistChristina Gagnier
 
Are you GDPR ready?
Are you GDPR ready?Are you GDPR ready?
Are you GDPR ready?INSZoom
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uaeRishalHalid1
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Financial Poise
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1rtjbond
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Aaron Banham
 

Similaire à ALTOUR GDPR Compliance Statement v4 (20)

Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Ready for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital EconomyReady for the GDPR, Ready for the Digital Economy
Ready for the GDPR, Ready for the Digital Economy
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
Data Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance StrategiesData Privacy Laws: A Global Overview and Compliance Strategies
Data Privacy Laws: A Global Overview and Compliance Strategies
 
GDPRpresentationFeb-Apr2018.pptx
GDPRpresentationFeb-Apr2018.pptxGDPRpresentationFeb-Apr2018.pptx
GDPRpresentationFeb-Apr2018.pptx
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
Things to know about GDPR in 2018
Things to know about GDPR in 2018Things to know about GDPR in 2018
Things to know about GDPR in 2018
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event Vuzion Love Cloud GDPR Event
Vuzion Love Cloud GDPR Event
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
Are you GDPR ready?
Are you GDPR ready?Are you GDPR ready?
Are you GDPR ready?
 
Data privacy and security in uae
Data privacy and security in uaeData privacy and security in uae
Data privacy and security in uae
 
Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...Introduction to EU General Data Protection Regulation: Planning, Implementati...
Introduction to EU General Data Protection Regulation: Planning, Implementati...
 
28014_EY Safe Harbor_UK
28014_EY Safe Harbor_UK28014_EY Safe Harbor_UK
28014_EY Safe Harbor_UK
 
The general data protection act overview
The general data protection act overviewThe general data protection act overview
The general data protection act overview
 
Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1Auditing your EU entities for data protection compliance 5661651 1
Auditing your EU entities for data protection compliance 5661651 1
 
Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0Associates quick guide to gdpr v 1.0
Associates quick guide to gdpr v 1.0
 
GDPR Demystified
GDPR Demystified GDPR Demystified
GDPR Demystified
 

Dernier

Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodKasia Chojecki
 
Where to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdWhere to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdusmanghaniwixpatriot
 
"Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa""Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa"flyn goo
 
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxHoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxChung Yen Chang
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersMakena Coast Charters
 
Aeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyAeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyFlyFairTravels
 
question 2: airplane vocabulary presentation
question 2: airplane vocabulary presentationquestion 2: airplane vocabulary presentation
question 2: airplane vocabulary presentationcaminantesdaauga
 
Moroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxMoroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxOmarOuazzani1
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)Mazie Garcia
 
Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)RanjeetKumar108130
 
Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Updatejoymorrison10
 
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCRdollysharma2066
 
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCRsoniya singh
 
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big JuicyDubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big Juicyhf8803863
 
Haitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxHaitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxhxhlixia
 
Italia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue muraItalia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue murasandamichaela *
 
Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxGregory DeShields
 
Exploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideExploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideTime for Sicily
 

Dernier (20)

Inspirational Quotes About Italy and Food
Inspirational Quotes About Italy and FoodInspirational Quotes About Italy and Food
Inspirational Quotes About Italy and Food
 
Where to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasdWhere to Stay in Lagos, Portugal.pptxasd
Where to Stay in Lagos, Portugal.pptxasd
 
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 74 Noida Escorts Delhi NCR
 
"Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa""Fly with Ease: Booking Your Flights with Air Europa"
"Fly with Ease: Booking Your Flights with Air Europa"
 
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsxHoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
Hoi An Ancient Town, Vietnam (越南 會安古鎮).ppsx
 
How Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s WatersHow Safe Is It To Witness Whales In Maui’s Waters
How Safe Is It To Witness Whales In Maui’s Waters
 
Aeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change PolicyAeromexico Airlines Flight Name Change Policy
Aeromexico Airlines Flight Name Change Policy
 
question 2: airplane vocabulary presentation
question 2: airplane vocabulary presentationquestion 2: airplane vocabulary presentation
question 2: airplane vocabulary presentation
 
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 62 Noida Escorts Delhi NCR
 
Moroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptxMoroccan Architecture presentation ( Omar & Yasine ).pptx
Moroccan Architecture presentation ( Omar & Yasine ).pptx
 
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
5S - House keeping (Seiri, Seiton, Seiso, Seiketsu, Shitsuke)
 
Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)Apply Indian E-Visa Process Online (Evisa)
Apply Indian E-Visa Process Online (Evisa)
 
Revolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI UpdateRevolutionalizing Travel: A VacAI Update
Revolutionalizing Travel: A VacAI Update
 
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
8377087607 Full Enjoy @24/7 Call Girls in INA Market Dilli Hatt Delhi NCR
 
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Nand Nagri 🔝 Delhi NCR
 
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big JuicyDubai Call Girls O528786472 Call Girls Dubai Big Juicy
Dubai Call Girls O528786472 Call Girls Dubai Big Juicy
 
Haitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptxHaitian culture and stuff and places and food and travel.pptx
Haitian culture and stuff and places and food and travel.pptx
 
Italia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue muraItalia Lucca 1 Un tesoro nascosto tra le sue mura
Italia Lucca 1 Un tesoro nascosto tra le sue mura
 
Authentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptxAuthentic Travel Experience 2024 Greg DeShields.pptx
Authentic Travel Experience 2024 Greg DeShields.pptx
 
Exploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel GuideExploring Sicily Your Comprehensive Ebook Travel Guide
Exploring Sicily Your Comprehensive Ebook Travel Guide
 

ALTOUR GDPR Compliance Statement v4

  • 1. ALTOUR INTERNATIONAL INC 1270 Avenue of the Americas, New York, NY 10020 Tel: 1 (800) 4 ALTOUR altour.gdpr@altour.co.uk ALTOUR – www.altour.com ALTOUR GDPR Compliance Statement Introduction The EU General Data Protection Regulation (“GDPR”) came into force across the European Union on 25th May 2018 and brings with it the most significant changes to data protection law in two decades. Based on privacy by design and taking a risk-based approach, the GDPR has been designed to meet the requirements of the digital age. The 21st Century brings with it broader use of technology, new definitions of what constitutes personal data, and a vast increase in cross-border processing. The new Regulation aims to standardise data protection laws and processing across the EU; affording individuals stronger, more consistent rights to access and control their personal information. Our Privacy Policy can be found here: http://www.altour.com/Privacy-Policy Our Commitment ALTOUR is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles. However, we recognise our obligations in updating and expanding this program to meet the demands of the GDPR and the UK’s Data Protection Bill. At ALTOUR, we are dedicated to safeguarding the personal information under our remit and in developing a data protection regime that is effective, fit for purpose and demonstrates an understanding of, and appreciation for the new Regulation. Our preparation and objectives for GDPR compliance have been summarised in this statement and include the development and implementation of new data protection roles, policies, procedures, controls and measures to ensure maximum and ongoing compliance. How ALTOUR is complying with the GDPR Currently, ALTOUR maintains a consistent level of data protection and security across our organization, and we have implemented the necessary policies and procedures to ensure compliance with the GDPR and the UK’s Data Protection Bill by 25th May 2018. Our preparation includes: - • Information Audit – Our GDPR compliance program includes an ongoing company-wide information audit to continuously identify and assess what personal information we hold, where it comes from, how and why it is processed and if and to whom it is disclosed. We also main • Policies & Procedures – We have revised and implemented new data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including: -
  • 2. ALTOUR INTERNATIONAL INC 1270 Avenue of the Americas, New York, NY 10020 Tel: 1 (800) 4 ALTOUR altour.gdpr@altour.co.uk ALTOUR – www.altour.com o Data Protection – Our main policy and procedure document for data protection has been overhauled to meet the standards and requirements of the GDPR. Accountability and governance measures are in place to ensure that we understand and adequately disseminate and evidence our obligations and responsibilities; with a dedicated focus on privacy by design and the rights of individuals. o Data Retention & Erasure – We have updated our retention policy and schedule to ensure that we meet the ‘data minimisation’ and ‘storage limitation’ principles and that personal information is stored, archived and destroyed compliantly and ethically. We have dedicated erasure procedures in place to meet the new ‘Right to Erasure’ obligation and are aware of when this and other data subject’s rights apply; along with any exemptions, response timeframes and notification responsibilities. o Data Breaches – Our breach procedures ensure that we have safeguards and measures in place to identify, assess, investigate and report any personal data breach at the earliest possible time. Our procedures are robust and have been disseminated to all employees, making them aware of the reporting lines and steps to follow. o International Data Transfers & Third-Party Disclosures – Where ALTOUR stores or transfers personal information outside the EU, we have robust procedures and safeguarding measures in place to secure, encrypt and maintain the integrity of the data. Our procedures include a continual review of the countries with sufficient adequacy decisions, as well as provisions for binding corporate rules; standard data protection clauses or approved codes of conduct for those countries without. We carry out strict due diligence checks with all recipients of personal data to assess and verify that they have appropriate safeguards in place to protect the information, ensure enforceable data subject rights and have effective legal remedies for data subjects where applicable. o Subject Access Request (SAR) – We have revised our SAR procedures to accommodate the revised 30-day timeframe for providing the requested information and for making this provision free of charge. Our new procedures detail how to verify the data subject, what steps to take for processing an access request, what exemptions apply and a suite of response templates to ensure that communications with data subjects are compliant, consistent and adequate. • Legal Basis for Processing - We have reviewed and continue to review all processing activities to identify the legal basis for processing and ensuring that each basis is appropriate for the activity it relates to. Where applicable, we also maintain records of our processing activities, ensuring that our obligations under Article 30 of the GDPR and Schedule 1 of the Data Protection Bill are met. o If you are a current customer, an employee, or a job applicant, the personal information we hold, may be used because it is necessary for the performance of the services contract to which you are a party, because it is necessary for our legitimate interest in processing such personal information in the context in which you provided it to us, or for another lawful basis. We will endeavor to inform you of the legal basis for collection of your personal information prior to or at the time we collect it.
  • 3. ALTOUR INTERNATIONAL INC 1270 Avenue of the Americas, New York, NY 10020 Tel: 1 (800) 4 ALTOUR altour.gdpr@altour.co.uk ALTOUR – www.altour.com o If you are a prospective customer, the personal information we collect, and use is necessary for our legitimate interest in providing you with information about the services we offer, and about which you have expressed an interest or that we believe will be of benefit to you. If another legal basis applies to our collection and use of your data, we will endeavor to inform you prior to or at the time we collect it. o In some cases, our legal basis for collecting your personal data is because you have expressly consented to our collection and use of your personal information. o If you object to the processing of your personal information under these basis, please contact our privacy team at altour.gdpr@altour.co.uk . • Privacy Notice/Policy – We have revised our Privacy Notice(s) to comply with the GDPR, ensuring that all individuals whose personal information we process have been informed of why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their information. • Obtaining Consent - We have revise our consent mechanisms for obtaining personal data, ensuring that individuals understand what they are providing, why and how we use it and giving clear, defined ways to consent to us processing their information. We have developed stringent processes for recording consent, making sure that we can evidence an affirmative opt-in, along with time and date records; and an easy to see and access way to withdraw consent at any time. • Direct Marketing - We have revised the wording and processes for direct marketing, including clear opt-in mechanisms for marketing subscriptions; a clear notice and method for opting out and providing unsubscribe features on all subsequent marketing materials. • Data Protection Impact Assessments (DPIA) – Where we process personal information that is considered high risk, involves large scale processing or includes special category/criminal conviction data; we have developed stringent procedures and assessment templates for carrying out impact assessments that comply fully with the GDPR’s Article 35 requirements. We have implemented documentation processes that record each assessment, allow us to rate the risk posed by the processing activity and implement mitigating measures to reduce the risk posed to the data subject(s). • Processor Agreements – Where we use any third-party to process personal information on our behalf (i.e. Payroll, Recruitment, Hosting etc), we have drafted compliant Processor Agreements and due diligence procedures for ensuring that they (as well as we), meet and understand their/our GDPR obligations. These measures include initial and ongoing reviews of the service provided, the necessity of the processing activity, the technical and organisational measures in place and compliance with the GDPR. • Special Categories Data - where we obtain and process any special category information, we do so in complete compliance with the Article 9 requirements and have high-level encryptions and protections on all such data. Special category data is only processed where necessary and is only processed where we have first identified the appropriate Article 9(2) basis or the Data Protection Bill Schedule 1 condition. Where we rely on consent for processing, this is explicit with the right to modify or remove consent being clearly signposted.
  • 4. ALTOUR INTERNATIONAL INC 1270 Avenue of the Americas, New York, NY 10020 Tel: 1 (800) 4 ALTOUR altour.gdpr@altour.co.uk ALTOUR – www.altour.com Data Subject Rights In addition to the policies and procedures mentioned above that ensure individuals can enforce their data protection rights, we provide easy to access information via our website of an individual’s right to access any personal information that ALTOUR processes about them and to request information about: - • What personal data we hold about them • The purposes of the processing • The categories of personal data concerned • The recipients to whom the personal data has/will be disclosed • How long we intend to store your personal data for • If we did not collect the data directly from them, information about the source • The right to have incomplete or inaccurate data about them corrected or completed and the process for requesting this • The right to request erasure of personal data (where applicable) or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us and to be informed about any automated decision-making that we use • The right to lodge a complaint or seek judicial remedy and who to contact in such instances Information Security & Technical and Organisational Measures ALTOUR takes the privacy and security of individuals and their personal information very seriously and take every reasonable measure and precaution to protect and secure the personal data that we process. We have robust information security policies and procedures in place to protect personal information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures, including Technical security measures such as; • Secure Inventory and Asset management for all Hardware & Software assets containing EU residents’ data. • Secure Network Architecture and proper data segregation • Secure configuration standards for Hardware and Software assets • A continuous vulnerability management and remediation program • Proper Identity and Access Management controls • Secure maintenance, monitoring and analysis of audit logs • Proper Intrusion prevention, Perimeter and Malware Defenses • A well-test and functioning Disaster Recovery & Business Continuity Program • Data-at-Rest & Data-in-Transit protections such as Data loss prevention and encryption • Access to customer data is controlled on a need-to-know basis and monitored. • All employees undergo mandatory privacy and security awareness training on a regular basis. • A functioning incidence response and management program • Annual and Quarterly Security Assessments are conducted by an external 3rd party security company.
  • 5. ALTOUR INTERNATIONAL INC 1270 Avenue of the Americas, New York, NY 10020 Tel: 1 (800) 4 ALTOUR altour.gdpr@altour.co.uk ALTOUR – www.altour.com GDPR Roles and Employees ALTOUR has designated an internal Data Privacy Officer and have appointed a data privacy team to develop and implement our roadmap for complying with the new data protection Regulation. The team are responsible for promoting awareness of the GDPR across the organisation, assessing our GDPR readiness, identifying any gap areas and implementing the new policies, procedures and measures. ALTOUR understands that continuous employee awareness and understanding is vital to the continued compliance of the GDPR and have involved our employees in our preparation plans. We have implemented an employee training program specific to the which will be provided to all employees prior to May 25th, 2018, and forms part of our induction and annual training program. If you have any questions about our preparation for the GDPR, please contact our Data Privacy Team at altour.gdpr@altour.co.uk