PROCESSES FOR REGULAR TESTING, ASSESSING AND EVALUATING Clause Samples

PROCESSES FOR REGULAR TESTING, ASSESSING AND EVALUATING. An adequate data protection management process, including regular employee training, has been set up. • An established incident response management process is in place. • Regular audits are carried out to determine whether the level of protection is adequate. • Data protection by default has been implemented in all cases. • Contract control: No processors within the meaning of Article 28 of the GDPR are used without a respective instruction of the Customer, e.g. precise contractual agreement, formalised order management, strict selection criteria for processors (ISO certification, e.g. ISO27001, etc.), obligation to verify suitability in advance, follow-up checks.