<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>News Archives - Wrangu</title>
	<atom:link href="https://www.wrangu.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Integrated risk management solutions, full security operations BCM.</description>
	<lastBuildDate>Tue, 26 May 2026 11:17:21 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://www.wrangu.com/wp-content/uploads/2022/03/favicon.png</url>
	<title>News Archives - Wrangu</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Wrangu and TemplarShield Announce Partnership</title>
		<link>https://www.wrangu.com/news/wrangu-and-templar-shield-partnership-announcement/</link>
		
		<dc:creator><![CDATA[Victor Lemmens]]></dc:creator>
		<pubDate>Thu, 23 Oct 2025 21:00:07 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=13813</guid>

					<description><![CDATA[<p> Wrangu and TemplarShield announce partnership.</p>
<p>The post <a href="https://www.wrangu.com/news/wrangu-and-templar-shield-partnership-announcement/">Wrangu and TemplarShield Announce Partnership</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="99" data-end="541"><span style="font-size: 14pt;">We are proud to announce a partnership between <strong data-start="169" data-end="191">TemplarShield Inc.</strong> and <strong data-start="196" data-end="211">Wrangu B.V.<br />
</strong><br />
Two Elite ServiceNow partners are joining forces to deliver deep <strong data-start="277" data-end="311">Enterprise Risk and Resilience</strong> expertise for customers across <strong data-start="343" data-end="360">North America</strong> and <strong data-start="365" data-end="373">EMEA</strong>. This collaboration brings together decades of delivery experience and a shared commitment to helping organizations turn risk into resilience and strategy into action.</span></p>
<p data-start="543" data-end="1013"><span style="font-size: 14pt;"><strong data-start="543" data-end="580"><br />
What this means for our customers</strong></span><br data-start="580" data-end="583" /><span style="font-size: 14pt;">Together, TemplarShield and Wrangu provide end-to-end consulting and implementation services on the ServiceNow Platform. We combine regional strength, TemplarShield across the United States and Canada, Wrangu across Europe, the Middle East and Africa.  The result is a unified team that helps you reduce risk, improve operational resilience and accelerate value from ServiceNow.</span></p>
<p data-start="1015" data-end="1040"><span style="font-size: 14pt;"><strong data-start="1015" data-end="1040"><br />
How we deliver impact</strong></span></p>
<ul data-start="1041" data-end="1872">
<li data-start="1041" data-end="1182">
<p data-start="1043" data-end="1182"><span style="font-size: 14pt;"><strong data-start="1043" data-end="1080">Integrated Risk Management (IRM):</strong> End-to-end programs for identifying, assessing and mitigating risk in the right enterprise context.</span></p>
</li>
<li data-start="1183" data-end="1325">
<p data-start="1185" data-end="1325"><span style="font-size: 14pt;"><strong data-start="1185" data-end="1224">Third-Party Risk Management (TPRM):</strong> Holistic oversight of vendor and supply chain risk, from onboarding through continuous monitoring.</span></p>
</li>
<li data-start="1326" data-end="1453">
<p data-start="1328" data-end="1453"><span style="font-size: 14pt;"><strong data-start="1328" data-end="1369">Business Continuity Management (BCM):</strong> Planning, response and recovery that keep your business moving during disruption.</span></p>
</li>
<li data-start="1454" data-end="1625">
<p data-start="1456" data-end="1625"><span style="font-size: 14pt;"><strong data-start="1456" data-end="1490">IT and OT Security Operations:</strong> Vulnerability Response and Security Incident Response, integrated with Operational Technology Management to protect critical assets.</span></p>
</li>
<li data-start="1626" data-end="1757">
<p data-start="1628" data-end="1757"><span style="font-size: 14pt;"><strong data-start="1628" data-end="1679">AI Governance with ServiceNow AI Control Tower:</strong> Practical guardrails that keep autonomous systems controlled and compliant.</span></p>
</li>
<li data-start="1758" data-end="1872">
<p data-start="1760" data-end="1872"><span style="font-size: 14pt;"><strong data-start="1760" data-end="1780">Global coverage:</strong> Follow-the-sun support and on-site consulting so programs run continuously and efficiently.<br />
</span></p>
</li>
</ul>
<p data-start="1760" data-end="1872"><strong style="font-size: 14pt;" data-start="1874" data-end="1899"><br />
Why this partnership now</strong></p>
<p data-start="1874" data-end="2179"><span style="font-size: 14pt;">Risk exposures are more complex. Regulations are evolving quickly. Cyber threats continue to grow. By combining our domain expertise with the power of ServiceNow and the practical use of AI, we can help clients scale programs, improve visibility and act faster with confidence.</span></p>
<p data-start="2181" data-end="2206"><span style="font-size: 14pt;"><strong data-start="2181" data-end="2204"><br />
From our leadership</strong></span></p>
<blockquote data-start="2207" data-end="2682">
<p data-start="2209" data-end="2682"><span style="font-size: 14pt;"><em data-start="2209" data-end="2644">“Wrangu is excited to team up with TemplarShield to reimagine what is possible for our customers on the ServiceNow Platform. By combining our strengths, we offer a comprehensive, end-to-end approach to digital risk management — from third-party risk to business continuity to AI oversight. Our clients can accelerate innovation and growth with the peace of mind that their risk, security and AI governance needs are in expert hands.”</em></span><br data-start="2644" data-end="2647" /><span style="font-size: 14pt;">— <strong data-start="2651" data-end="2682">Victor Lemmens, CEO, Wrangu</strong></span></p>
<p>&nbsp;</p></blockquote>
<p data-start="2181" data-end="2206"><span style="font-size: 14pt;"><strong data-start="2181" data-end="2204">From TemplarShield leadership</strong></span></p>
<blockquote data-start="2207" data-end="2682">
<p data-start="2209" data-end="2682"><span style="font-size: 14pt;">“We are thrilled to unite with Wrangu in this partnership. Templar Shield and Wrangu share an unwavering commitment to innovation and excellence in risk and security, and together we’re creating a global powerhouse capable of delivering transformative, unified solutions for our clients wherever they operate. By joining forces across North America and EMEA, we’re raising the bar for integrated risk management and security operations – enabling organizations to proactively manage IT and OT risks and govern AI with confidence. This partnership isn’t just about expanding our reach; it’s about elevating the standard of how enterprises protect themselves in the digital age.”</span><br data-start="2644" data-end="2647" /><span style="font-size: 14pt;">— <strong data-start="2651" data-end="2682">Nicholas Friedman, CEO, TemplarShield</strong></span></p>
</blockquote>
<p data-start="2684" data-end="2815"><br data-start="2954" data-end="2957" /><span style="font-size: 14pt;"> <a href="https://www.templarshield.com/">TemplarShield Website</a></span></p>
<p>The post <a href="https://www.wrangu.com/news/wrangu-and-templar-shield-partnership-announcement/">Wrangu and TemplarShield Announce Partnership</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data Protection Management Framework In-Depth Guide</title>
		<link>https://www.wrangu.com/downloads/data-protection-management-framework-in-depth-guide/</link>
		
		<dc:creator><![CDATA[Gemma]]></dc:creator>
		<pubDate>Tue, 01 Nov 2022 14:48:43 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Downloads]]></category>
		<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=10664</guid>

					<description><![CDATA[<p>Download the Data Protection Management Framework In-Depth Guide. Find out how your company can ensure data protection security and mitigate potential data breaches with these 12 detailed steps. </p>
<p>The post <a href="https://www.wrangu.com/downloads/data-protection-management-framework-in-depth-guide/">Data Protection Management Framework In-Depth Guide</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The post <a href="https://www.wrangu.com/downloads/data-protection-management-framework-in-depth-guide/">Data Protection Management Framework In-Depth Guide</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wrangu is pleased to announce the latest version of PRIVACY HUB is now available</title>
		<link>https://www.wrangu.com/news/wrangu-is-pleased-to-announce-the-latest-version-of-privacy-hub-is-now-available/</link>
					<comments>https://www.wrangu.com/news/wrangu-is-pleased-to-announce-the-latest-version-of-privacy-hub-is-now-available/#respond</comments>
		
		<dc:creator><![CDATA[Thomas Van Hellemondt]]></dc:creator>
		<pubDate>Wed, 11 May 2022 13:24:23 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=3196</guid>

					<description><![CDATA[<p>&#160; Amsterdam, July 6th – Security, Risk and Data Privacy specialists Wrangu announced the launch of the latest version of their data privacy management tool: Privacy Hub by Wrangu. it is built on the world-class ServiceNow platform. The tool provides the technology solution for organisations to manage their extensive global privacy program efficiently, driving their [&#8230;]</p>
<p>The post <a href="https://www.wrangu.com/news/wrangu-is-pleased-to-announce-the-latest-version-of-privacy-hub-is-now-available/">Wrangu is pleased to announce the latest version of PRIVACY HUB is now available</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">&nbsp;</p>



<p class="wp-block-paragraph"><strong>Amsterdam, July 6<sup>th</sup></strong> – Security, Risk and Data Privacy specialists <a href="/" target="_blank" rel="noreferrer noopener">Wrangu</a> announced the launch of the latest version of their data privacy management tool: <a href="https://www.wrangu.com/solutions/data-privacy/" target="_blank" rel="noreferrer noopener">Privacy Hub by Wrangu</a>. it is built on the world-class ServiceNow platform. The tool provides the technology solution for organisations to manage their extensive global privacy program efficiently, driving their compliance with global data privacy regulations from the Americas to Asia.</p>



<p class="wp-block-paragraph">The GDPR has undoubtably inspired a new era of data privacy and has had a domino effect on the wider data privacy world with many global regulations coming into force following the GDPR. The latest version of the Privacy Hub has extensive support for multiple privacy regulations requirements across the globe. “Our customers are battling with the complexity of global regulations, tirelessly trying to manage privacy requirements with endless tools and significant manual effort. I hear common questions from DPOs: ‘How do I drive the privacy efforts of the business efficiently and with consistency? How do I push adoption of privacy efforts across all functions within my company? How do I ensure compliance across regulations, without significant spend or causing the business to have to be completely re-engineered?’.</p>
<p>We listened to our customers’ needs and built the latest version of the Privacy Hub to help our customers solve those challenges. Harmonising their privacy processes, staying compliant, and staying in control – all without costing a fortune! It is THE go-to solution for data privacy management.” says Lee Grant, CEO of Wrangu.</p>





<h2><strong>Most comprehensive global privacy tool </strong></h2>



<p class="wp-block-paragraph">The latest version of the <a href="https://www.wrangu.com/solutions/data-privacy/" target="_blank" rel="noreferrer noopener">Privacy Hub by Wrangu</a> now supports extensive privacy regulations across the globe from the Americas to Asia. Including 5 US states, Canada (federal and state), Singapore, Europe (GDPR), Brazil (LGPD) and Turkey (LPPD). “To many DPOs it may seem impossible to co-ordinate multiple people, spreadsheets and formats to drive compliance, let alone to get real time visibility. The Privacy Hub by Wrangu replaces your old manual processes and systems, drives work activities and gives you a 360 view of your compliance” says Grant.</p>



<p class="wp-block-paragraph"><a href="https://www.wrangu.com/solutions/data-privacy/">Privacy Hub by Wrangu</a> offers affordable module solutions including:</p>



<ul>
<li>Data Protection Impact Assessments (PIA/DPIA), Incident and Breach Response, Data Mapping, Record of Processing Activities, Data Subject/Consumer Rights Management and Policy &amp; Notice Management.

</li>
<li>Privacy Hub by Wrangu is validated by independent privacy consultants, who provide an un-biased, in-depth and up-to-date source of privacy, security and regulatory requirements.

</li>
<li>The software, available in multiple languages, was awarded the app of the year by ServiceNow in 2019.</li>
</ul>
<p class="wp-block-paragraph">

More than <a href="https://www.wrangu.com/about-us/" target="_blank" rel="noreferrer noopener">60 customers</a>, among the largest enterprises across the globe, trust Wrangu’s products and services to implement their privacy, security, and integrated risk programs.</p>
<p class="wp-block-paragraph">&nbsp;</p>


<hr class="wp-block-separator has-text-color has-background has-light-green-cyan-background-color has-light-green-cyan-color" />


<h3><strong>About Wrangu</strong></h3>



<p class="wp-block-paragraph">Wrangu provides tailor-made software and solutions for integrated risk, security and privacy management based on the ServiceNow Platform. Founded in 2016 with the mission to build tailored software solutions to enable clients to manage very complex requirements regarding security, privacy and integrated risk management.</p>



<p class="wp-block-paragraph">The #WranguDreamTeam are incredibly passionate about what they do, and 100% customer focused. Working together we build a roadmap based on our customers’ needs ensuring our customers receive a solution of the highest level of quality tailored to their business needs. Wrangu’s customers are supported by a dedicated global team ensuring success from consultation through implementation to ongoing support including resources and boasts a customer satisfaction score of 100%.</p>



<p class="wp-block-paragraph">Wrangu’s dedicated team are located across headquarters in Amsterdam with an additional office in London. To learn more, visit <a href="/" target="_blank" rel="noreferrer noopener">www.wrangu.com</a> or connect on <a href="http://www.linkedin.com/company/wrangu" target="_blank" rel="noreferrer noopener">LinkedIn.</a></p>



<p class="wp-block-paragraph">Wrangu and Privacy hub by Wrangu are registered trademarks of Wrangu BV.</p>



<p class="wp-block-paragraph">&nbsp;</p>


<hr class="wp-block-separator" /><p>The post <a href="https://www.wrangu.com/news/wrangu-is-pleased-to-announce-the-latest-version-of-privacy-hub-is-now-available/">Wrangu is pleased to announce the latest version of PRIVACY HUB is now available</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/wrangu-is-pleased-to-announce-the-latest-version-of-privacy-hub-is-now-available/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Victor Lemmens appointed new CEO of Wrangu BV</title>
		<link>https://www.wrangu.com/news/victor-lemmens-appointed-new-ceo-of-wrangu-bv/</link>
					<comments>https://www.wrangu.com/news/victor-lemmens-appointed-new-ceo-of-wrangu-bv/#comments</comments>
		
		<dc:creator><![CDATA[Wrangu]]></dc:creator>
		<pubDate>Fri, 22 Apr 2022 11:37:27 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=8948</guid>

					<description><![CDATA[<p>Wrangu BV is pleased to announce the appointment of Victor Lemmens as Chief Executive Officer with effect from 11th of April. Victor came from the position of Director Benelux at EIT Digital with a strong background in sustainably transforming innovations into profit-generating entities and the development of human capital beyond current performance.</p>
<p>The post <a href="https://www.wrangu.com/news/victor-lemmens-appointed-new-ceo-of-wrangu-bv/">Victor Lemmens appointed new CEO of Wrangu BV</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Wrangu BV is pleased to announce the appointment of Victor Lemmens as Chief Executive Officer with effect from 11<sup>th</sup> of April. Victor came from the position of Director Benelux at EIT Digital with a strong background in sustainably transforming innovations into profit-generating entities and the development of human capital beyond current performance.</p>



<p class="wp-block-paragraph">“I am very excited to lead Wrangu in the next phase of its journey as CEO. Low code software is shifting paradigms in the software sector. Combined with several imminent changes in the way technology will support professionals in <a class="wpil_keyword_link " title="Governance" href="https://www.wrangu.com/solutions/governance-risk-compliance/" data-wpil-keyword-link="linked">Governance</a>, Risk and Compliance in the near future, I am thrilled to help Wrangu take a leading position in that transition.”</p>



<h2 class="wp-block-heading" id="h-victor-lemmens-ceo"><strong>Victor Lemmens CEO</strong></h2>



<p class="wp-block-paragraph">The new appointment aligns with the company’s accelerated growth strengthening the transition from a start-up to a scale-up. Victor Lemmens: “Wrangu is well-positioned to take a leading role in transforming value delivery of IRM software solutions with the power of low code. Actual implementation effort is moving ever closer to business owners. The loop between software developers and business owners is cut short.” Former CEO Lee Grant will assume the position of Chief of Sales, wherewith his extensive background he will help drive the company’s growth ambitions.</p>



<h2 class="wp-block-heading"><strong>About</strong> <strong>Victor</strong></h2>





<p class="wp-block-paragraph">Victor’s career of accelerating growth within SaaS companies spans over 20 years. With a relentless focus on customer value delivery, Victor has continuously focused on the effectiveness of technology for customers. After starting a career at Philips leading global software projects and shaping Value Engineering at SAP in the EMEA region, Victor joined BWise, a Gartner first quadrant leader in IRM software at that moment in time and contributed to the acquisition of BWise by Nasdaq in 2014. After that, Victor committed to low code software propositions to close the gap between software development and customer value delivery. During the last year, Victor gave back to European society and supported the efforts to extend Europe&#8217;s contribution to global digital transformation at EIT Digital.</p>



<p class="wp-block-paragraph">Victor holds a master&#8217;s degree in Mechanical Engineering from Aachen Technical University in Germany and a master&#8217;s degree in Business Administration from Nyenrode Business University in the Netherlands. As a convinced European, Victor speaks Dutch, English, German and French.</p>



<h2 class="wp-block-heading"><strong>About Wrangu</strong></h2>



<p class="wp-block-paragraph">Flexible software solutions. For people.</p>



<p class="wp-block-paragraph">Founded in 2016, our mission is that we enable our clients to maximize the value from their ServiceNow investment, through world-class implementation and services, and the creation of intelligent apps helping to solve localization needs and address the industry-specific challenges that our clients have in their business.</p>
<p>The post <a href="https://www.wrangu.com/news/victor-lemmens-appointed-new-ceo-of-wrangu-bv/">Victor Lemmens appointed new CEO of Wrangu BV</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/victor-lemmens-appointed-new-ceo-of-wrangu-bv/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>We have been awarded ISO 27001 Certification!</title>
		<link>https://www.wrangu.com/news/we-have-been-awarded-iso-27001-certification/</link>
					<comments>https://www.wrangu.com/news/we-have-been-awarded-iso-27001-certification/#respond</comments>
		
		<dc:creator><![CDATA[Wrangu]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 12:34:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=8927</guid>

					<description><![CDATA[<p>Individuals are increasingly becoming aware of the ownership and security of their data. Due to this increased sense of securing data and working in a secured manner, Wrangu has decided to undergo the process of securing the ISO 27001 certification. After a period of rigorous testing, we are very excited to announce Wrangu has been awarded the ISO 27001 certification!</p>
<p>The post <a href="https://www.wrangu.com/news/we-have-been-awarded-iso-27001-certification/">We have been awarded ISO 27001 Certification!</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Individuals are increasingly becoming aware of the ownership and security of their data.</p>



<p class="wp-block-paragraph">Due to this increased sense of securing data and working in a secured manner, Wrangu has decided to undergo the process of securing the ISO 27001 certification.</p>



<p class="wp-block-paragraph">After a period of rigorous testing, we are very excited to announce Wrangu has been awarded the ISO 27001 certification!</p>



<p class="wp-block-paragraph">Certificate of Information Security Management System according to ISO 27001 is a globally recognised standard on how to manage a business. It confirms that data privacy in <a href="https://www.wrangu.com/">Wrangu</a> meets the highest security standards and requirements.</p>



<h3 class="wp-block-heading" id="h-what-is-information-security-and-why-is-it-important-now-more-than-ever">What is Information Security and why is it important now more than ever?</h3>



<p class="wp-block-paragraph">Information Security is keeping information assets secure against internal and external threats, by mitigating information risk and ensuring <a href="https://www.wrangu.com/solutions/servicenow-business-continuity-management/">business continuity</a>, minimising business risk, and maximising return on investments.</p>



<p class="wp-block-paragraph">Keeping this in mind Wrangu will continue working hard to maintain the highest security standards.</p>
<p>The post <a href="https://www.wrangu.com/news/we-have-been-awarded-iso-27001-certification/">We have been awarded ISO 27001 Certification!</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/we-have-been-awarded-iso-27001-certification/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>On the Concepts of Controller, Joint Controllers, and Processor</title>
		<link>https://www.wrangu.com/news/on-the-concepts-of-controller-joint-controllers-and-processor-gdpr-assigns-roles-responsibilities/</link>
					<comments>https://www.wrangu.com/news/on-the-concepts-of-controller-joint-controllers-and-processor-gdpr-assigns-roles-responsibilities/#respond</comments>
		
		<dc:creator><![CDATA[Stephen Ragan]]></dc:creator>
		<pubDate>Fri, 20 Aug 2021 08:15:52 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[uk adequacy]]></category>
		<category><![CDATA[uk gdpr]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=5487</guid>

					<description><![CDATA[<p>The European Data Protection Board (EDPB) issued guidance on the Concepts of Controller, Joint Controllers, and Processor following public consultation on 7 July 2021. The different concepts are important under the General Data Protection Regulation (GDPR) because the regulation assigns distinct roles and responsibilities based on an organisation’s classification. </p>
<p>The post <a href="https://www.wrangu.com/news/on-the-concepts-of-controller-joint-controllers-and-processor-gdpr-assigns-roles-responsibilities/">On the Concepts of Controller, Joint Controllers, and Processor</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The European Data Protection Board (EDPB) issued <a href="https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-072020-concepts-controller-and-processor-gdpr_en" target="_blank" rel="noreferrer noopener">guidance</a> on the Concepts of Controller, Joint Controllers, and Processor following public consultation on 7 July 2021. The different concepts are important under the General Data Protection Regulation (GDPR) because the regulation assigns distinct roles and responsibilities based on an organisation’s classification. </p>
<p>Wrangu’s<a href="https://www.wrangu.com/solutions/data-privacy/"> Privacy Hub</a> can help with your privacy and data protection concerns and assist your organization with GDPR.</p>



<h2 class="wp-block-heading"><strong>Controller </strong> </h2>



<p class="wp-block-paragraph">A controller can take the form of an individual such as a CEO or CPO or a group of individuals, but in practice is usually an organisation. The key aspect of a controller is <em>determining </em>the “purposes and means” of processing. This is the decision making over key elements of data processing that answers the questions of the <em>why</em> and <em>how</em> of the processing.  </p>



<p class="wp-block-paragraph">A controller can be self-designated or arise out of the factual elements or circumstances. This includes the distinction between a controller and subsidiaries of the controlling corporation. While a specific person may be appointed to ensure compliance with data protection rules, they are serving on behalf of the organisation, which will ultimately be responsible in the case of violations. </p>



<p class="wp-block-paragraph">Where the “purposes and means” of the processing is determined is also crucial for determining an organisation’s “main establishment,” and the lead supervisory authority. </p>



<p class="wp-block-paragraph">The key terms the EDPB defined were what it means to determine the “purposes and means” of the data processing.  </p>



<p class="wp-block-paragraph"><strong>“Determines” </strong> </p>



<p class="wp-block-paragraph">Control of processing relates to exercising decision-making power. This can arise in two ways, from legal provisions such as a contractual designation of controller or from an assessment of the factual situation. This means the role of controller does not stem from the nature of the entity but its concrete activities in determining the purposes and means of the processing.  </p>



<p class="wp-block-paragraph"><strong>“Purposes and means”</strong> </p>



<p class="wp-block-paragraph">The EDPB cites unnamed dictionaries to define “purpose” as “an anticipated outcome that is intended or that guides your planned actions” and “means” as “how a result is obtained or an end is achieved.” Determining these factors is important to conform to the principles that data be collected for “specified, explicit and legitimate purposes.” This amounts to answering the questions of why processing takes place and how those objectives will be achieved.  </p>



<p class="wp-block-paragraph">The controller must decide both the purposes and means. It cannot leave the goal defined without specifying the way to get there. This does not mean the processor has no leeway to make certain decisions. The EDPB delineated essential v. non-essential means. What is essential must be done by the controller. The “means” are closely linked to the purpose and the scope of the processing. For example, determining the type of personal data processed, for how long, and who has access to the data. Non-essential means concern more practical aspects of implementation like what type of software is used.  </p>



<p class="wp-block-paragraph"><strong>Controller Obligations</strong> </p>



<p class="wp-block-paragraph">The controller is responsible for compliance with the GDPR, in particular the requirements under Articles 24 and 25. These include implementing and being able to <strong>demonstrate technical and organisational measures</strong> <strong>designed to effectuate the principles of the GDPR including</strong> <strong>data minimisation, purpose limitation, and storage limitation</strong>. This requires considering the nature scope, context, and purposes for the processing as well as the risks to the rights and freedoms of individuals.  </p>



<p class="wp-block-paragraph">Additionally, the controller is obligated to keep Records of Processing Activities with the requirements of information to be kept listed under Article 30. Where processing may present a risk to the “rights and freedoms” of data subjects, a Data Protection Impact Assessment must be carried out according to Article 35. Controllers are also obligated to notify the supervisory authority within 72 hours of becoming aware of a data breach unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. In situations where there is a “high risk to the rights and freedoms” of individuals, the controller must also communicate the data breach to the data subject “without undue delay.” </p>



<p class="wp-block-paragraph">The GDPR explicitly includes the accountability principle (Art. 5(2)). This means the controller is responsible for compliance with the other principles set out in Article 5(1), and the controller must be able to demonstrate that compliance. While the accountability principle is directly addressed to the controller, there are obligations that apply to both controllers and processors and open both parties up to fines for noncompliance </p>



<p class="wp-block-paragraph">In the choice of a processor, the controller has the duty to use “only processors providing sufficient guarantees to implement appropriate technical and organisation measures.” The responsibility is placed on controllers to assess the sufficiency of a processor’s guarantees and capabilities. This assessment is like a DPIA (Data Protection Impact Assessments), often called a “vendor risk assessment,” and depends on a variety of factors including the nature, scope, and context of the processing as well as the risks to the rights and freedoms of natural persons (Recital 81). In assessing the guarantees of the processor, controllers should consider the processor’s expert knowledge, reliability, and available resources.  </p>



<h2 class="wp-block-heading"><strong>Joint Controller</strong> </h2>



<p class="wp-block-paragraph">The assessment of joint controllers also requires a determination over what organisation determines “the means and purposes” of the processing and should follow the above assessment for a single controller. Article 4(7) and provides that “where two or more controllers jointly determine the purposes and means of processing, they shall be joint controllers.”  </p>



<p class="wp-block-paragraph">The most important criterion for determining the existence of joint controllership is joint participation in determining the means and purposes of processing. Joint participation can arise from a <em>common decision</em> made by two or organisations or arise out of a <em>converging decision </em>where decisions complement each other. Case law from the Court of Justice of the European Union suggests that decisions converge “if they complement each other and are necessary for the processing to take place.” An important question to ask in determining convergence is “whether the processing would not be possible without both parties’ participation” for a particular processing activity. </p>



<p class="wp-block-paragraph"><strong>Jointly Determined Purpose(s)</strong> </p>



<p class="wp-block-paragraph">Joint controllers exist when the organisations involved process the data for the same, or common, purposes. Even when the purposes are not the same a joint controllership may exist if the purposes are closely linked. For example, in the case <em>Fashion ID</em>, the Court of Justice of the European Union (CJEU) clarified that a website operator and the provider of a social plug-in (FB like button) embedded on the website were joint controllers as the operations were in the economic interests of both parties. The website operator was able to increase the visibility of its products while Facebook acquired more data on browsing habits. </p>



<p class="wp-block-paragraph">However, the existence of joint goal is not the only situation where jointly determined purpose exists. See for example the case <em>Wirtschaftsakademie</em>. In this case the CJEU held that administrators of a Facebook fan page and Facebook were joint controllers as both parties were involved in determining the purposes and means of the processing of the associated personal data even when they were pursuing different interests. Facebook was able to optimize its system of advertisements while the administrator of the fan page obtained statistics to manage the promotion of its activity. </p>



<p class="wp-block-paragraph"><strong>Jointly Determined Means</strong> </p>



<p class="wp-block-paragraph">Joint controllership requires two or more entities exert influence over the means of the processing. It may be the case that one organisation provides the means of the processing and makes it available to the other organisation. Again, as an example is <em>Wirtschaftsakademie </em>where the administrator of a Facebook page used target audience and other tools provided by Facebook. </p>



<p class="wp-block-paragraph">The use of a common data processing system or infrastructure does not automatically qualify as a joint controllership. The relevant analysis must determine whether the processing could be carried out alone by one party without intervention from another. The shared use of data alone will not give rise to a joint controllership. </p>



<p class="wp-block-paragraph"><strong>Joint Controller Obligations</strong> </p>



<p class="wp-block-paragraph">Joint controllerships can be made up of two or more organisations. The joint controllers must determine their respective responsibilities to comply with the GDPR including how data subjects exercise their rights and the responsibility to provide information in Articles 13 and 14 (Art. 26). The distribution of responsibilities should also cover the legal basis for processing with each joint controller ensuring they have one. Other considerations include response and notification obligations in the case of a data breach, conducting data protection impact assessments, using processors, transferring data abroad, and communication with the supervisory authority. </p>



<p class="wp-block-paragraph">The legal form of the arrangement is not specified by the GDPR. To comply with the principles of transparency and accountability, the EDPB recommends such arrangements be formalised in a binding agreement reflecting the roles, responsibilities, and liability between controllers.  </p>



<h2 class="wp-block-heading"><strong>Processor</strong> </h2>



<p class="wp-block-paragraph">A processor is defined under Article 4(8) and processes personal data on behalf of the controller. There are two basic criteria for a processor. It exists separately from the controller and processes personal data on behalf of the controller.  <br /> </p>



<p class="wp-block-paragraph">A processor can be a person, public authority, agency, or organisation that processes data in accordance with the controller’s instructions. These instructions generally take the form of a data processing addendum that may still leave discretion for the processor to determine certain aspects of the processing. The agreement must set out the “subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.” At the end of the contract, the processor is often obligated to delete and return all the personal data to the controller. The processor must also be able to demonstrate compliance with the <a href="https://www.wrangu.com/blog/data-privacy-management-software-the-ultimate-buyers-guide-for-gdpr-compliance-software/">GDPR</a> to the Controller. </p>



<p class="wp-block-paragraph">When a processor goes beyond those instructions to determine its own “purposes and means” it is then considered a controller and may be subject to sanctions for beyond the controller’s instructions.  </p>



<p class="wp-block-paragraph">Processors have a host of limitations on their processing activities and Article 28 lays out a processor’s responsibilities. These include implementing appropriate technical and organisational measures and limitations on engaging with further processors without prior approval from the controller. The obligation to process data only on the instructions of the controller has an exception if processing is required by Union or Member State law.  </p>



<p class="wp-block-paragraph"><strong>Processor Obligations</strong> </p>



<p class="wp-block-paragraph">A new feature of the GDPR applies obligations to Processors. Processors must ensure the individual authorised to process the data has committed themselves to confidentiality (Art. 28(3)(b)), maintain a ROPA (Records of Processing Activities) (Art. 30(2)) and has a duty to assist the controller in ensuring compliance, for example, conducting a DPIA. In the case of a data breach, the processor has an obligation to notify the controller “without undue delay after becoming aware of it.”  </p>



<h2 class="wp-block-heading"><strong>What to Include in the Controller/Processor Data Processing Agreement</strong> </h2>



<p class="wp-block-paragraph">Any processing by a processor must be governed by a contract or other legal act in writing or electronic form (Art. 28(3) and (9)). The contractual requirements to be included are laid out in Article 28(3) and all elements must be covered. The standard contractual clauses (SCCs) may be used and provide helpful guidance. These SCCs are distinct from the SCCs used for data transfers under Article 46(2).  </p>



<p class="wp-block-paragraph">The EDPB guidance notes that the processing agreement should not merely restate the provisions of the GDPR but should include “more specific, concrete information as to how the requirements will be met and which level of security is required for the personal data processing.” The processor is then limited to processing data pursuant to the documented instructions (Art. 28(3)(a)). When a processing processes data beyond the controller’s instructions this amounts to a determining the purposes and means of processing, the processor is in breach of its obligations, and will then be considered a controller. This includes <a href="https://www.wrangu.com/blog/the-debate-over-data-transfers-data-localisation-or-the-free-flow-of-data-debate-over-data-transfers/">data transfers</a> to other divisions of the processor that may be in third countries. If the controller has not acceded to these transfers they are not allowed.  </p>



<p class="wp-block-paragraph">The contract must state the processor ensures that anyone it allows to access personal data is committed to confidentiality. This may occur as a specific contractual agreement, or due to statutory obligations (Art. 28(3)(b)). </p>



<p class="wp-block-paragraph">Article 32 requires the implementation of appropriate technical and organisational security measures. This must be reflected in the contract and the level of detail must enable the controller to assess the appropriateness of the measures according to Article 32(1).  </p>



<p class="wp-block-paragraph">The agreement must specify the limitations on the processor to engage another processor with the controller’s prior written authorisation. It is recommended the process for this authorisation be included in the contractual provisions. This authorisation can be either specific, referring to a specific sub-processor at a specific time, or general. General authorisation should include guidance on criteria for choosing sub-processors. The difference is based on interpreting a controller’s silence. Under general authorisation, the controller’s failure to object within a certain time frame can be interpreted as authorisation. When the processor engages another processor, a contract must be put in place between them imposing the same data protection obligations as those imposed on the original processor. The processor is then liable to the controller for the sub-processors’ compliance with the obligations.  </p>



<p class="wp-block-paragraph">Ensuring data subject requests and how they are dealt with is up to the controller. However, the contract must stipulate that the processor has an obligation to provide assistance. The assistance may simply consist of forwarding requests received to the controller or may include more detailed processes. While the practical management of <a href="https://www.wrangu.com/blog/gdpr-ccpa-what-you-need-to-know-about-data-subject-access-requests/">data subject requests</a> can be outsourced to processors, the controller bears the responsibility for complying with such requests.  </p>



<p class="wp-block-paragraph">The processor must also assist the controller in responding to data breaches. The processor must notify the controller whenever it discovers a personal data breach “without undue delay” and help the controller in obtaining the information to include in its report to the supervisory authority (Art. 33(3)). Notification of the supervisory authority and data subjects can be delegated to the processor, but the controller still maintains the responsibility to conform with obligations under the GDPR.  </p>



<p class="wp-block-paragraph">When the processing period has ended, contractual terms dictating how and when the processor must delete or return the data should be stipulated (Art. 28(3)(g)). The processor must then comply unless EU or Member State law requires further storage. </p>



<p class="wp-block-paragraph">The contract should also include details on how often and how the flow of information between the processor and the controller should take place so that the controller is fully informed of the processing details ensuring compliance with Article 28 processor obligations. For example, the relevant portions of the ROPA may be shared with the controller.  </p>



<h2 class="wp-block-heading"><strong>What to Include in the Joint Controller Data Processing Agreement</strong> </h2>



<p class="wp-block-paragraph">Article 26(1) states that joint controller must in a transparent manner determine and agree on their respective responsibilities for compliance. This relates to the duty to provide information to the data subjects under Articles 13 and 14 and responding to data subject requests. Including the obligations laid out in Article 26, the EDPB also suggests clauses that consider: </p>



<ul class="wp-block-list">
<li>Implementation of general data protection principles (Article 5)  </li>
<li>Legal basis of the processing (Article 6) </li>
<li>Security measures (Article 32)  </li>
<li>Notification of a personal data breach to the supervisory authority and to the data subject74 (Articles 33 and 34)  </li>
<li>Data Protection Impact Assessments (Articles 35 and 36)75 </li>
<li>The use of a processor (Article 28)  </li>
<li><a href="https://www.wrangu.com/blog/cross-border-data-transfer-requirements-brazil-lgpd-turkey-lppd/">Transfers of data</a> to third countries (Chapter V)  </li>
<li>Organisation of contact with data subjects and supervisory authorities  </li>
</ul>



<p class="wp-block-paragraph">The obligations do not need to be evenly distributed, but all joint controllers have an obligation to ensure compliance with the GDPR. Article 26(1) staters that joint controllers should determine their responsibilities “by means of an arrangement between them.” There is no obligation on joint controllers to engage in a contract allocating responsibilities though, “for the sake of legal certainty,” the EDPB recommends such an arrangement be laid out in writing to provide certainty, transparency, and accountability.  </p>



<p class="wp-block-paragraph">The “essence of the arrangement” must be made available to <a href="https://www.wrangu.com/blog/gdpr-ccpa-what-you-need-to-know-about-data-subject-access-requests/">data subjects</a>. The details of the “essence of the arrangement” are not specified by the GDPR giving joint controllers some flexibility. The EDPB recommends describing the contact point for data subjects as well as the elements of Article 13 and 14 along with which joint controller is responsible for ensuring compliance with these elements. It is up to the joint controller how they will make this arrangement available to the data subject. The suggestions are to include in the privacy policy or upon request to the Data Protection Officer. Irrespective of the terms of the arrangement, data subjects may exercise their rights against each of the joint controllers. </p>
<p>The post <a href="https://www.wrangu.com/news/on-the-concepts-of-controller-joint-controllers-and-processor-gdpr-assigns-roles-responsibilities/">On the Concepts of Controller, Joint Controllers, and Processor</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/on-the-concepts-of-controller-joint-controllers-and-processor-gdpr-assigns-roles-responsibilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Threat to Human Rights: Vaccine Passports and more</title>
		<link>https://www.wrangu.com/news/vaccine-passports-covid-19-digital-certificates-threat-to-human-rights/</link>
					<comments>https://www.wrangu.com/news/vaccine-passports-covid-19-digital-certificates-threat-to-human-rights/#respond</comments>
		
		<dc:creator><![CDATA[Wrangu]]></dc:creator>
		<pubDate>Thu, 03 Jun 2021 08:45:58 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[covid vaccine]]></category>
		<category><![CDATA[human rights privacy]]></category>
		<category><![CDATA[threat to human rights]]></category>
		<category><![CDATA[vaccine passports]]></category>
		<category><![CDATA[vaccine passports privacy concern]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=5210</guid>

					<description><![CDATA[<p>As digital vaccine certificates emerge, governments and private organisations will restrict access to services and shared spaces based on an individual’s status, excluding those who have not received the vaccine. These initiatives will require large-scale data collection and processing of sensitive health data creating the infrastructure for new forms of surveillance.</p>
<p>The post <a href="https://www.wrangu.com/news/vaccine-passports-covid-19-digital-certificates-threat-to-human-rights/">Threat to Human Rights: Vaccine Passports and more</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-what-is-new"><strong>What is New</strong> </h2>



<p class="wp-block-paragraph">After a long fight with the COVID-19 virus, we seem to be slowly emerging from the long winter of our discontent. Governments are slowly working to approve, distribute, and administer vaccines while reducing restrictions imposed on citizens. Along with this, there are a growing number of proposals for digital vaccine certificates. Often these proposals link the vaccination status of an individual with a government-provided digital identifier to record and authenticate an individual’s vaccination status.  </p>



<p class="wp-block-paragraph">As digital vaccine certificates emerge, governments and private organisations will restrict access to services and shared spaces based on an individual’s status, excluding those who have not received the vaccine. These initiatives will <a href="https://www.wrangu.com/blog/cross-border-data-transfer-requirements-brazil-lgpd-turkey-lppd/">require large-scale data</a> collection and processing of sensitive health data creating the infrastructure for new forms of surveillance.  </p>



<p class="wp-block-paragraph">Public health authorities have a history of issuing vaccine certificates and maintaining vaccine records. Yellow fever vaccination certificates are used in international travel under International Health Regulations and administered by the World Health Organization. Beyond serving as proof of an individual’s vaccine status, it also contributes to avoiding duplicate vaccinations and facilitating proper administration of multiple doses. Similar systems are widely used around the world. When access to travel or public services is made contingent on having a vaccine, clear legal policies ensure equitable access to the required vaccines.  </p>



<p class="wp-block-paragraph">Proponents of digital vaccine certificates argue the need to prevent the creation of fraudulent records as well as making the certificates available to organisations ranging from custom and borders control to small business owners. These apps also offer a contact point for other services such as reminders about appointments, when the next dose is due, tracking side effects, and offering medical follow up. </p>



<p class="wp-block-paragraph">What is different about COVID-19 is the digitised response. This ranged from the initial push to create contact tracing applications to developing systems for digital vaccine certificates that record and track individuals using information technology and digital records. Making access to places and services contingent on vaccine status raises concerns about exclusion and discrimination while the digitised response raises corresponding risks associated with mass data collection like data breaches while creating an infrastructure for the proliferation of centralised digital identity systems.  </p>



<h2 class="wp-block-heading" id="h-risk-of-exclusion-and-discrimination"><strong>Risk of Exclusion and Discrimination</strong> </h2>



<p class="wp-block-paragraph">Digital certificate proposals raise concerns about discrimination towards those who have not received the vaccine for one reason or another. On the one hand, many people around the world are still waiting for access to COVID-19 vaccines. Some governments lack the resources for first access to the vaccines while others face challenges related to distribution. This often means that marginalised and vulnerable populations will be the last to receive vaccines, if they get them at all.  </p>



<p class="wp-block-paragraph">If the primary use of digital certificates is to grant or deny access to travel, work, social services, and public places, these programs may push those already facing exclusion and discrimination further to the margins of society. If digital vaccine certificates are mandatory for travel, this would severely restrict individuals crossing borders out of necessity like refugees and migrants.  </p>



<p class="wp-block-paragraph">And what happens for individuals who have other health-imposed restrictions or lack access to the internet and internet-connected devices and cannot make an appointment? Even if they do have the vaccine, how would they share that information digitally? Others in communities with access may be excluded from vaccinations because of existing medical conditions or religious objections. These individuals will then be systematically excluded from participating in a vaccinated society without access to services and public spaces. </p>



<h2 class="wp-block-heading" id="h-privacy-and-security-concerns"><strong>Privacy and Security Concerns</strong> </h2>



<p class="wp-block-paragraph">The rollout of the vaccine and proposed vaccine passports also raises privacy concerns. Member States in the EU must take the General Data Protection Regulation (GDPR) into consideration when rolling out vaccine passports. What would be the legal basis for data collection and <a href="https://www.wrangu.com/blog/the-debate-over-data-transfers-data-localisation-or-the-free-flow-of-data-debate-over-data-transfers/">transfer</a>? How long would the data be stored? A person’s agency to give consent is severely limited if a digital vaccine passport is the only way to participate fully in daily life. Other concerns relate to the mass collection of information by government and corresponding surveillance concerns while centralised data centres serve as a valuable target for cybercriminals. </p>



<p class="wp-block-paragraph">Digital vaccine certificates would significantly expand the amount of data collected about vaccination status while generating ongoing data collection about where and when a digital vaccine certificate has been used. This creates inevitable concerns related to mistakes while creating a target for cyber-attacks. These concerns are exacerbated by the creation of a centralised digital identity system serving as a new health identity infrastructure.  </p>



<p class="wp-block-paragraph">In 2020, Jamaica released the JamCOVID app and website, a centralised platform showing information about the COVID status of individuals in the country with tools to self-report symptoms and obtain pre-approval to visit the country. Visitors upload their travel information and a negative test result to obtain approval. In February 2021, journalist Zack Whittaker <a href="https://techcrunch.com/2021/02/17/jamaica-immigration-travelers-data-exposed/" target="_blank" rel="noreferrer noopener">broke the news</a> that the cloud storage server containing travellers&#8217; information had been left unprotected without a password. More than 70,000 negative COVID results, 425,000 immigration documents, travellers&#8217; signatures, and more than 1.1 million check-in videos were open to exposure.  </p>



<p class="wp-block-paragraph">One of the most worrying aspects of digital identity systems is the interlinking of various aspects of a person’s life linking tax records, mobile numbers, health data, financial record, and other registrations under one centralised identity system. The collection and use of health data should be grounded in the principles of necessity and proportionality in accordance with prescribed laws. This would seek to avoid situations like in Singapore where law enforcement officials <a href="https://fortune.com/2021/02/01/singapore-covid-data-tracetogether-use-law-criminal/" target="_blank" rel="noreferrer noopener">were able to access data</a> gathered through the TraceTogether and SafeEntry contact tracing applications for criminal investigations. This is not what the data was supposed to be used for.  </p>



<p class="wp-block-paragraph">Centralised digital identity systems are susceptible to mission creep, growing far beyond the uses and limitations that were first envisioned. In India, the Aaroygya Setu contact tracing application was promoted as a one-stop solution for everything related to COVID-19 asking for personal information including habits and current symptoms. The government later used that <a href="https://www.wrangu.com/blog/privacy-hub-by-wrangu-introduces-intelligent-integrated-data-mapping-and-data-life-cycle-management-powered-by-indica/">data to create databases managed</a> by different ministries. For the distribution of vaccines, the government of India rolled out the Co-WIN 2.0 platform using that information to populate the database for the Digital Health ID and forcing individuals to use a system <a href="https://www.accessnow.org/india-cowin-app/" target="_blank" rel="noreferrer noopener">used to populate India’s digital identity program</a>. </p>



<p class="wp-block-paragraph">Another lingering concern relates to retention periods and how long this sensitive data would be stored. Outside of Europe, many countries are only at the stage of proposing data protection legislation creating a worrying situation about misuses of health data. No one wants to create a situation where individuals would be forced to compromise their fundamental right to privacy to maintain or gain access to essential services and the freedom of movement.  </p>



<p class="wp-block-paragraph">A digital vaccine certificate will require the collection of sensitive personal data. The use and collection of this information should be bolstered by comprehensive data protection laws leveraging the GDPR and the protection of data subject rights including the right to access and correct data and, when the time comes, limiting collection and use of this personal data and eventually deleting the data.  </p>



<h2 class="wp-block-heading" id="h-recommendations-on-the-use-of-digital-vaccine-certificates-from-access-now"><strong>Recommendations </strong><strong>on the Use of Digital Vaccine Certificates </strong><strong>from Access Now</strong> </h2>



<h4 class="wp-block-heading" id="h-do-what-is-effective-not-what-is-trending"><strong><em>Do What is Effective, Not What is Trending</em> </strong></h4>



<p class="wp-block-paragraph">Existing vaccine certificate systems work and do not carry dangers of expansive digital vaccine passport programs and infrastructure. </p>



<h4 class="wp-block-heading" id="h-prioritize-data-protection"><em>Prioritize Data Protection</em> </h4>



<p class="wp-block-paragraph">Minimize data collection and retention following privacy-by-design principles </p>



<h4 class="wp-block-heading" id="h-be-transparent-in-both-design-and-implementation"><em>Be Transparent in both Design and Implementation</em> </h4>



<p class="wp-block-paragraph">Keep in mind uncertainties about the landscape of vaccines and their long-term efficacy including unintended consequences of new digital vaccine passports.  </p>



<h4 class="wp-block-heading" id="h-be-equitable-and-inclusive"><em>Be Equitable and Inclusive</em> </h4>



<p class="wp-block-paragraph">Access to digital vaccine certificates should be free, accessible, and paired with easily accessible paper-based forms as an interchangeable alternative.  </p>



<h4 class="wp-block-heading" id="h-limit-use-of-certificates"><em>Limit Use of Certificates</em> </h4>



<p class="wp-block-paragraph">Digital vaccine certificates should not be treated as another tool for accelerating digital transformation and must not be used to advance adoption of centralised and mandatory digital identity systems.  </p>



<h4 class="wp-block-heading" id="h-prevent-abuse"><em>Prevent Abuse</em> </h4>



<p class="wp-block-paragraph">Governments should include sunset clauses and strict data retention periods to avoid expanded surveillance, silencing dissent, and restricting freedoms of expression, assembly, and movement.  </p>



<h4 class="wp-block-heading" id="h-don-t-create-division"><em>Don’t Create Division</em> </h4>



<p class="wp-block-paragraph">Digital vaccine certificates should not be mandatory for exercising fundamental rights and freedoms. Systems that make digital vaccine certificates a requirement will divide and exclude.  </p>
<p>The post <a href="https://www.wrangu.com/news/vaccine-passports-covid-19-digital-certificates-threat-to-human-rights/">Threat to Human Rights: Vaccine Passports and more</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/vaccine-passports-covid-19-digital-certificates-threat-to-human-rights/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Wrangu Advances to an Elite Partner in ServiceNow’s Partner Program</title>
		<link>https://www.wrangu.com/news/wrangu-advances-to-an-elite-partner-in-servicenows-partner-program/</link>
					<comments>https://www.wrangu.com/news/wrangu-advances-to-an-elite-partner-in-servicenows-partner-program/#respond</comments>
		
		<dc:creator><![CDATA[Thomas Van Hellemondt]]></dc:creator>
		<pubDate>Thu, 22 Apr 2021 11:11:44 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[servicenow partners]]></category>
		<category><![CDATA[servicenow wrangu]]></category>
		<category><![CDATA[servicenow]]></category>
		<category><![CDATA[servicenow partner]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=4815</guid>

					<description><![CDATA[<p>Wrangu today announced its transition to an ElitePartner in the ServiceNow ProgramProgram. Wrangu supports ServiceNow customers with Integrated Risk, Security and Privacy Management.</p>
<p>The post <a href="https://www.wrangu.com/news/wrangu-advances-to-an-elite-partner-in-servicenows-partner-program/">Wrangu Advances to an Elite Partner in ServiceNow’s Partner Program</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Amsterdam — March 2021— Wrangu</strong> today announced its transition to an Elite Partner in the ServiceNow Program. Wrangu supports ServiceNow customers with Integrated Risk, Security and Privacy Management.</p>



<p class="wp-block-paragraph"><a href="https://www.wrangu.com/blog/privacy-hub-by-wrangu-introduces-intelligent-integrated-data-mapping-and-data-life-cycle-management-powered-by-indica/">Wrangu provides flexible software solutions for integrated</a> risk, security and privacy management. Founded in 2016 Wrangu’s mission is to deliver software solutions that enable clients to solve their risk and compliance challenges efficiently and with true transparency.</p>



<p class="wp-block-paragraph">Wrangu’s Chief Sales Officer, Lee Grant said “As a young company dedicated to building client solutions on ServiceNow, I am delighted that all our hard work and client achievements have been recognised by our promotion to Elite status.&#8221;</p>



<p class="wp-block-paragraph">“A welcome acknowledgement of our commitment to the ServiceNow eco-system” Wrangu’s COO Robert John Wilson added.</p>



<p class="wp-block-paragraph">“At ServiceNow our partners play a leading role in accelerating digital transformation for our joint clients by delivering amazing experiences and business value on the ServiceNow Platform” said Sebastian Fitzjohn, Vice President, EMEA Alliances &amp; Channel Ecosystem, ServiceNow. “Wrangu is a great example of the vibrancy, innovation and customer focus within our ecosystem. We are thrilled they are now an Elite Partner in the ServiceNow Partner Program.”</p>



<p class="wp-block-paragraph"><strong>Wrangu</strong>’s transition to <strong>Elite</strong> recognizes achievements in the ServiceNow partner assessment methodology, which identifies the activities, accomplishments, and commitments that demonstrate <strong>Wrangu</strong>’s level of ServiceNow investment and go-to-market maturity.   </p>



<h3 class="wp-block-heading"><strong>About Wrangu</strong></h3>



<p class="wp-block-paragraph"><a href="https://www.wrangu.com/blog/privacy-hub-by-wrangu-introduces-intelligent-integrated-data-mapping-and-data-life-cycle-management-powered-by-indica/">Wrangu provides flexible software solutions for integrated</a> risk, security and privacy management. Founded in 2016, Wrangu’s mission is to deliver software solutions that enable clients to solve their <a href="https://www.wrangu.com/services/governance-risk-compliance/">risk and compliance</a> challenges efficiently and with true transparency.</p>



<p class="wp-block-paragraph">To learn more, visit <a href="https://www.wrangu.com/">https://www.wrangu.com</a> or connect on <a class="rank-math-link" href="http://www.linkedin.com/company/wrangu">LinkedIn</a>.<br />Wrangu and <a href="https://www.wrangu.com/blog/data-privacy-management-software-the-ultimate-buyers-guide-for-gdpr-compliance-software/">Privacy hub</a> by Wrangu are registered trademarks of Wrangu BV.</p>



<h3 class="wp-block-heading"><strong>About ServiceNow</strong><strong> </strong></h3>



<p class="wp-block-paragraph">ServiceNow, the ServiceNow logo, Now, Now Platform, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc. in the United States and/or other countries.</p>



<h4 class="wp-block-heading"><strong>Press Contact Information </strong></h4>



<p class="wp-block-paragraph"><strong>Thomas van Hellemondt, Head of Marketing</strong></p>
<p>Thomas.vanhellemondt@wrangu.com</p>



<p class="wp-block-paragraph"><strong>Lee Grant, </strong><strong>Chief Sales </strong><strong>Officer</strong></p>
<p>Lee.grant@wrangu.com </p>
<p>The post <a href="https://www.wrangu.com/news/wrangu-advances-to-an-elite-partner-in-servicenows-partner-program/">Wrangu Advances to an Elite Partner in ServiceNow’s Partner Program</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/wrangu-advances-to-an-elite-partner-in-servicenows-partner-program/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Schrems II and the Decision of the French Court on SaaS</title>
		<link>https://www.wrangu.com/news/schrems-ii-and-the-decision-of-the-french-court-on-saas/</link>
					<comments>https://www.wrangu.com/news/schrems-ii-and-the-decision-of-the-french-court-on-saas/#respond</comments>
		
		<dc:creator><![CDATA[Stephen Ragan]]></dc:creator>
		<pubDate>Thu, 18 Mar 2021 13:54:00 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=4688</guid>

					<description><![CDATA[<p>The plaintiffs argued that the processor (Amazon) was a company bound by US law and the risk of access by US authorities was incompatible with the requirements of the GDPR and Schrems II decision.</p>
<p>The post <a href="https://www.wrangu.com/news/schrems-ii-and-the-decision-of-the-french-court-on-saas/">Schrems II and the Decision of the French Court on SaaS</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Written by Stephen Ragan, Principal Privacy Consultant at Wrangu</em></p>



<p class="wp-block-paragraph">On 12 March 2021, France’s highest administrative court ruled that personal data on a platform managed by Doctolib and hosted by Amazon Web Services had sufficient safeguards in place to manage access requests from US authorities. This is a key decision following the Court of Justice of the European Union’s Schrems II decision on the suitable safeguards for data hosted on services provided by Amazon, an American company.</p>



<p class="wp-block-paragraph">The plaintiffs argued that the processor (Amazon) was a company bound by US law and the risk of access by US authorities was incompatible with the requirements of the GDPR and Schrems II decision.</p>



<p class="wp-block-paragraph">Doctolib is a leading e-health <a href="https://www.wrangu.com/blog/recent-rulings-europe-for-managing-data-storage-cloud-service-providers/">service company in Europe</a>. When online users in France searched where to get a vaccine against COVID-19, they could make an appointment on the Doctolib platform. The agreement between the French Ministry of Social Affairs and Health and Doctolib stems from an agreement signed on 11 January 2021. To host its data, Doctolib used AWS Sarl, based in Luxemburg and a subsidiary of Amazon Web Services in the United States.</p>



<p class="wp-block-paragraph">A number of associations and unions asked the Conseil d’Etat to order a suspension of the partnership and an order to the Ministry to use another solution to manage its vaccine campaign. The plaintiffs argued the matter was urgent as it concerned sensitive health data and was hosted by a subsidiary of an American company, subject to US National Security law which meant potential access by US authorities in violation of the Schrems II decision. The plaintiffs also argued that the possibility that sensitive data would be transferred to the US violated Schrems II. Even in absence of a <a href="https://www.wrangu.com/blog/the-debate-over-data-transfers-data-localisation-or-the-free-flow-of-data-debate-over-data-transfers/">data transfer</a>, AWS was subject to data access requests from the US intelligence community.</p>



<h2 class="wp-block-heading">What the Court Said</h2>



<p class="wp-block-paragraph">The court found that there had been no data transfers from the EU to US, but nevertheless concluded that there was a risk of access by US authorities as the EU based processor was a subsidiary of an American company. Thus, the court found it necessary to check the level of protection provided for the processing of personal data and whether it satisfied the requirements of suitable safeguards in the provisions of the contract and the technical safeguards. In concluding in favour of Doctolib, the court found the safeguards sufficient:</p>



<ol class="wp-block-list">
<li>Legal Safeguards: The court reasoned that the contract included specific procedures in the event of an access request and that AWS Sarl guaranteed to Doctolib it would challenge any general access request by public authorities</li>
<li>Technical Safeguards: The court also noted the data hosted by AWS Sarl was encrypted and the key held by a third party in France, not by AWS</li>
</ol>



<p class="wp-block-paragraph">The court was also satisfied that no health data was transferred to Doctolib. Instead, Doctolib only hosted data related to the identification of an individual but not the reason the person was eligible for a vaccine. The court additionally noted the principle of data</p>



<p class="wp-block-paragraph">minimization and retention limitations as the data was deleted three months from the date of the vaccination appointment and individuals could also delete their data directly online.</p>



<p class="wp-block-paragraph">This case provides an interesting development following the CJEU decision in the Schrems II case. The role of precedent is not formally recognised by the civil law tradition of the EU’s founding states, nor by international law. This means decisions of the CJEU are binding only to the case addressed. However, in order to know how to apply laws of the EU, the decisions of the CJEU must be consulted. What has developed is a system in which the CJEU has based much of its reasoning on the principle that its decisions have binding force on all national courts as well as other authorities justifying its jurisdiction under Treaty on the Functioning of the European Union Art. 267 and the need to ensure the uniform application of EU law.</p>



<p class="wp-block-paragraph">In Schrems II, the CJEU was concerned about data transfers from the EU to the US. This case is a little different in that services provided were rendered by a subsidiary of an American company. Again, the court found that the subsidiary was subject to US law, and this made the data potentially subject to access requests by US authorities. But the court found that there were sufficient legal and technical safeguards in place to prevent access requests.</p>



<p class="wp-block-paragraph">Even when there is no data transfer, the ruling underlies the importance of contractual supplementary safeguards, modelled on the draft standard contractual clauses published by the European Commission. Another point of emphasis is on the technical measures taken. In particular, encryption where the processor (AWS) did not have access to the re-identification key and therefore neither did US intelligence authorities.</p>



<p class="wp-block-paragraph">This case leaves a big gap on the question of supplementary measures for instances where the processor processing the data does more than just store the data locally. As we await negotiations between the US and the EU on an update to the Privacy Shield, invalidated as a transfer mechanism in Schrems II, SCCs; BCRs; and Article 49 derogations are being used to solve business and legal challenges. In this new regulatory environment, a little creativity is necessary.</p>



<p class="wp-block-paragraph"><a href="https://www.wrangu.com/">Wrangu</a> will continue to monitor the situation and help you and your organisation stay on top of new privacy regulations.</p>
<p>The post <a href="https://www.wrangu.com/news/schrems-ii-and-the-decision-of-the-french-court-on-saas/">Schrems II and the Decision of the French Court on SaaS</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.wrangu.com/news/schrems-ii-and-the-decision-of-the-french-court-on-saas/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Customer Case Study: French international banking group</title>
		<link>https://www.wrangu.com/news/customer-case-study-french-international-banking-group/</link>
		
		<dc:creator><![CDATA[Wrangu]]></dc:creator>
		<pubDate>Fri, 01 May 2020 14:42:24 +0000</pubDate>
				<category><![CDATA[Customer Stories]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.wrangu.com/?p=2255</guid>

					<description><![CDATA[<p>Find out how one of the largest banks in Europe, achieved consistent privacy processes across the organisation after collaborating with Wrangu.</p>
<p>The post <a href="https://www.wrangu.com/news/customer-case-study-french-international-banking-group/">Customer Case Study: French international banking group</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The post <a href="https://www.wrangu.com/news/customer-case-study-french-international-banking-group/">Customer Case Study: French international banking group</a> appeared first on <a href="https://www.wrangu.com">Wrangu</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
