The General Data Protection Regulation is a new set of privacy regulations and guidelines that replaces the Data Protection Directive 95/46/EC and effective May 25, 2018.
The General Data Protection Regulation (GDPR) will require several changes to organizations in the way they collect and process European Union (EU) personal data.
The GDPR contains a number of new protections for EU citizens and threatens penalties for non-compliance. In addition, there are new security, recordkeeping, access rights, and notification procedures that companies must implement to ensure compliance. Issues that are attracting particular focus include increased administrative requirements, and the need to provide the tools necessary to meet the numerous obligations on administrators, controllers, and processors.
ExpiWell offers self-service products to users via an Application Service Provider model delivered via the Internet and using standard web browser software. Customers solely determine what data to collect, from whom and where, for what purpose, and for how long. Therefore, ExpiWell does not and cannot classify or represent any Customer data. All data are processed electronically on the instructions of the Customer as required to provide the software, support, and maintenance.
Administrator Access (Transparency Disclosure)
A limited number of authorized ExpiWell engineers and support staff may access Customer data when strictly necessary to provide technical support, investigate security incidents, debug production issues, or comply with legal obligations. Such access is governed by the following safeguards:
Customers may request a Data Subject Access Request (DSAR) export or audit log review at any time by contacting [email protected].
Since the Customer has full control over its data, it may have special obligations to protect the data outside the scope of the protection ExpiWell provides (for instance, if data were downloaded to the user's local drive or printed). ExpiWell has always agreed to safeguard all Customer data with industry best standards regardless of what that data represents.
ExpiWell enables its Customers to be GDPR compliant. Briefly stated, that means ExpiWell will:
GDPR Article 28, Section 3, requires that a contract be in place between a data controller and a data processor. For years, the ExpiWell Survey Taker and Survey Maker Terms of Service and Privacy Policy have provided the fundamental legal requirements and obligations regarding data ownership, processing behavior, safeguarding data, breach notification, and more.
However, if a ExpiWell Customer desires to have a GDPR-specific contract, it may be electronically downloaded here.
This Contract appends the terms of an existing Agreement to satisfy the requirement of the GDPR Article 28, Section 3, that governs the processing of EU personal data. Once reviewed and signed, please send to [email protected].
Both ExpiWell and its Customers (controllers) are separately and jointly liable for actions or inactions that do not comply with GDPR. Thus, the GDPR requires a shared responsibility to protect an individual's right to privacy. The table below summaries these responsibilities and is included for clarification only.
Legend: E = ExpiWell's responsibility; C = Customer's responsibility; S = Shared responsibility
| Breach Notification Standards | S |
| Data security and processing standards | E |
| Individual "unambiguous" explicit consent before data collection | C |
| Individual withdraws consent, requests data deletion | C |
| Parental consent to collect information on children | C |
| Only transfer data to a country with adequate protection | E |
| Cross-border transfer of PII | C |
| Post public privacy notice | S |
| Follow requests from a DPA | S |
| Allow right to data modification and to be forgotten | C |
| Provide data portability | S |
| Rights of notice, access, and objection | C |
| Clarifying role of controller and processor | S |
| Data breach notification | S |
| Collect data only for "specific, explicit, and legitimate purposes" | C |
Please note: this is not an exhaustive list of responsibilities.
Address: Unit 3D, North Point House, North Point Business Park, New Mallow Road, Cork Ireland,
Tel: 0330 223 2246
Email: [email protected]
Address: Lakeside Offices Thorn Business park Hereford England HR2 6JT
Tel: 0330 223 2246
Email: [email protected]