Corporate GDPR Statement

In May 2018, the EU General Data Protection Regulation (GDPR) replaces the existing 1995 EU Data Protection Directive (European Directive 95/46/EC).

iob.fi DAO currently complies with applicable data protection regulations and is committed to GDPR compliance across its relevant services when the GDPR takes effect May 25, 2018. iob.fi DAO has a dedicated internal team made up of cross-functional stakeholders overseeing iob.fi DAO’s GDPR readiness. iob.fi DAO’s ongoing compliance efforts include:

Assessment

iob.fi DAO has reviewed where and how our relevant services collect, use, store and dispose of personal data and has updated policies, standards, governance and documentation where needed. iob.fi DAO is dedicated to keeping such due diligence current and carrying out re-assessments periodically and/or as required by changed circumstances.

Contractual Commitments

Working in conjunction with our partners and customers, iob.fi DAO is reviewing our contractual commitments and updating as needed to directly address GDPR requirements. iob.fi DAO has released a Data Processing Addendum (DPA) with provisions to assist our partners and customers with their GDPR compliance.

Cross-border Data Transfer

In addition to ensuring iob.fi DAO’s contractual commitments meet the requirements to legally transfer data from the EU to the rest of the world under applicable law, iob.fi DAO plans to certify under the EU-US Privacy Shield Framework.

Employee Training and Awareness

All iob.fi DAO employees must complete data privacy and security training. iob.fi DAO will supplement existing training modules with GDPR-specific content. In addition to these training requirements, iob.fi DAO conducts ongoing awareness initiatives on a variety of topics, including data protection, security.

iob.fi DAO Investors, Partners, and Customers

Compliance with the GDPR requires a partnership between iob.fi DAO and our partners and customers in their use of applicable iob.fi DAO services. In this context, iob.fi DAO generally will act as a data processor and our partners and customers generally will act as data controllers. Working together, we hope to explore opportunities within our relevant service offerings to assist our partners and customers meet their GDPR obligations. In the meantime, iob.fi DAO encourages partners and customers to independently familiarize themselves with the GDPR.

Last updated