Vertec and GDPR

The General Data Protection Regulation, or DSGVO, came into force in 2016. But you definitely have to apply it from the end of May 2018. What do these new data protection guidelines mean for Vertec and Vertec users, whether in the EU or Switzerland?
First of all, it must be noted that the DSGVO is a fairly natural continuous improvement of the already existing data protection laws, which surprises mainly because of the high threats of fines, less because of the content. With this, the legislator has secured the attention of companies, which is probably why the current somewhat hectic discussions about the concrete and correct applications are being held.
All data protection laws always cover only personal data, as is also the case in the DSGVO. Personal data are data about natural (and only natural!) persons (literally the standard in German, Article 1 paragraph 1: “This Regulation contains provisions on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.”). Data protection must therefore not be confused with IT or information security (ISMS, ISO 27001). But if you are familiar with such topics, it will certainly be easier to deal with data protection (see also our Blog Entry on this topic).
Does the DSGVO now prohibit the collection and storage of such personal data?
Not at all, on the contrary: it formulates the rules that must be followed if one wishes to or has to process personal data. In many cases, other standards require that one has to have personal data (e.g. the obligation to keep orders and invoices for accounting purposes, including those of natural persons, which often include address, telephone number or date of birth, or data on employees, which one must have, among other things, in order to correctly calculate social benefits or salaries). The DSGVO or data protection laws in general do not take precedence over other standards; but they define rules on how such data may be processed.
The “processing of special categories of personal data” is very strictly regulated (Article 9, in the current Swiss Data Protection Act “personal data particularly deserving of protection”). This refers to “the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or [...]”. This also includes health data, data on sex life, etc. You can see that this is very personal data, which goes far beyond the address, telephone number and quantity of children. The collection of such data is prohibited in principle, with exceptions, of course. A doctor, for example, has to collect such data just to be able to make a diagnosis. We at the Vertec group do not need such data, nor do most of our customers, which means that no such data collections are created in the Vertec software.
For us and Vertec customers, it is at most about the processing of “normal” personal data, here the question arises, what rules apply?
When can I collect and process such data?
The rule here is very clear in Article 6: processing must be “lawful,” for example according to point (a) where the data subject has given his or her consent and according to point (b) where “processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract”.

Therefore, if a contractual relationship exists or if a natural person has initiated a request to a company, e.g. via a contact form on the homepage, no further explicit consent is required. If an order includes the telephone numbers of the persons involved (e.g. for support topics), this is also unproblematic. However, it should be clear that in a CRM like Vertec, you should only save the data about a person that is necessary for the fulfillment of an order or for the preparation of an offer, i.e. no personal opinions, affiliation to parties, etc. (although your own sales staff naturally loves such information).
The standard now requires that such data collections be known, documented and ensured that the processing is lawful. If you adhere to certain basic rules, this is easily possible, especially since we ourselves, and also the vast majority of Vertec’s customers, are active in the B2B sector and therefore, by nature, little personal data is generated. The DSGVO is absolutely technology- and implementation-neutral, a software cannot be DSGVO-compatible per se, it depends on how you use it – personal data can also be saved on paper, in an e-mail program or in Word, for example... The DSGVO does not require a complete recording of personal data or its alteration anywhere. For Vertec customers, the sophisticated Role and authorization concepts in vertec software certainly help here. Your Vertec advisor will be happy to help you!
What does the DSGVO mean for Vertec as a company?
For the Vertec group, the DSGVO means that we are expanding our existing processes around our ISO 27001 Information Security Management System (ISMS) and clarifying our Role as contract data processors for Cloud Suite customers – we do not actually “process” data here, but we ensure the operation of Vertec software in the cloud and are responsible for the day-to-day backup of the data. Here, of course, we are obliged, not only since the DSGVO, to adequately protect your data, not only with regard to the actual data protection (i.e. personal data), but also with regard to your trade secrets. In the event that you operate the Vertec software yourself, we are generally not a data processor within the meaning of the DSGVO.
Does the DSGVO also apply in Switzerland?

One more remark for customers in Switzerland: anyone who thinks that the DSGVO only affects companies in the EU is probably wrong for 2 reasons: 1. the scope of the standard will be understood very broad – every company with any connection to the EU will fall under it, even if it does not operate directly in the EU and 2. the Swiss data protection laws will probably be brought to a similar level in the near future – it is in any case a favour to deal with the DSGVO now!
Conclusion
If you have never dealt with data protection before, you will probably find it difficult to entered the whole of the DSGVO in the first place – but this is not necessary; you need to be aware of what collections of personal data you have and need and whether you are allowed to process this data legally (e.g. because of a contract). The obligation to protect data should be used to scrutinise your own processes critically and to eliminate unnecessary data collections – if you take advantage of this opportunity, then the debate with the DSGVO will turn from a mandatory exercise to an service type that also makes business sense!
Disclaimer: we are not lawyers and this blog post does not represent a court-approved practice in dealing with the GDPR. This post only summarizes our interpretation and application of the GDPR. If in doubt, it should be worthwhile for any company to seek expert advice and read the original text of the GDPR.





