{"id":2452,"date":"2021-01-19T18:56:48","date_gmt":"2021-01-19T18:56:48","guid":{"rendered":"https:\/\/www.whistlelink.com\/?page_id=2452"},"modified":"2022-02-01T14:37:11","modified_gmt":"2022-02-01T14:37:11","slug":"measures","status":"publish","type":"page","link":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/","title":{"rendered":"Organisational and technical measures for data protection"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"2452\" class=\"elementor elementor-2452\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8e5d0e0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8e5d0e0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7f34473\" data-id=\"7f34473\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-eaa2723 elementor-widget elementor-widget-heading\" data-id=\"eaa2723\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Organisational and technical measures for data protection<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-194b483 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"194b483\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3e6ef9a\" data-id=\"3e6ef9a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7ca422b elementor-widget elementor-widget-text-editor\" data-id=\"7ca422b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em><span style=\"color: #212529; font-size: 1.125rem;\">Whistleblowing Solutions AB handles large amounts of data for itself and on behalf of others. This applies, among other things, to personal data. Whistleblowing Solutions\u2019 activities are regulated by various laws, and internal guidelines which can be found in company documents such as plans, policies and procedures. Whistleblowing Solutions is certified according to ISO 27001.<\/span><\/em><\/p><p><em>This summary outlines how Whistleblowing Solutions acts to fulfill its obligations and to minimize the risks associated with the processing of data. It also\u00a0refers to the current minimum security levels. However, Whistleblowing Solutions is committed to continuously improving its data security, whereby it will adapt measures to safeguard from new outside threats and utilize newly available data protection tools.<\/em><\/p><p><em>In cases where Whistleblowing Solutions AB uses subcontractors, it will ensure the subcontractors implement the required security controls to comply with the organizational and technical measures.<\/em><\/p><h5><strong>Organisation <\/strong><\/h5><p>Whistleblowing Solutions data security activities are based on current legislation and the company&#8217;s governing documents which are determined by the Company&#8217;s CEO or Board of Directors. The company&#8217;s Information Security Officer is responsible for leading and coordinating data security within the business, which includes the following:<\/p><ul><li>Responsibility for policies and procedures relating to data security and its compliancy<\/li><li>Conducting risk analysis and management in relation to data security<\/li><li>Coordinating activities to ensure data security compliancy<\/li><li>The overall requirements of various security controls<\/li><li>Spreading knowledge about data security throughout the organisation<\/li><li>Documenting and coordinating non-conformances<\/li><\/ul><p>Whistleblowing Solutions maintains guidelines on how all employees, including subcontractors, should act to minimise data security threats. These guidelines are well circulated, understood and implemented by all concerned.<\/p><h5><strong>General information on technical security measures<\/strong><\/h5><p>The basic principle of technical security measures at Whistleblowing Solutions is that the level of confidentiality determines the requirements of the security controls (e.g., type of authentication, cryptographic protection, etc.). The levels of confidentiality are:<\/p><ul><li>Open &#8211; data accessible by all, inside and outside the company<\/li><li>Internal &#8211; data accessible by employees only<\/li><li>Confidential &#8211; Sensitive data (such as personal data) accessible by a limited number of employees only<\/li><\/ul><h5><strong>Continuity planning<\/strong><\/h5><p>In the event of a serious incident, such as an office or data centre fire, Whistleblowing Solutions has a data processing crisis and contingency plan in place, to minimize disruption to operations and commitments to customers.<\/p><h5><strong>Access \/ Authorization<\/strong><\/h5><p>Data is protected from all forms of unauthorized processing, such as unauthorized access, unauthorized distribution and unintentional or intentional destruction.<\/p><p>Access to confidential data is restricted to persons working at Whistleblowing Solutions. Each individual\u2019s access is limited to only the data and permissions needed to carry out the task.<\/p><p>Whistleblowing Solutions has control systems in place to prevent unauthorized access to confidential data. Access is through personal user-IDs, and access to secret information, such as sensitive personal data, requires specific authorization. Two-factor authentication is used when logging in to all systems that contain personal data.<\/p><p>There are designated functions for approving, amending, or withdrawing authorizations. Authorizations that are not used will be deactivated.<\/p><h5><strong>Physical and environmental protection<\/strong><\/h5><p>Whistleblowing Solutions restricts access to physical premises and facilities, which contain systems processing data, to authorized persons only. The premises are protected against fire and theft.<\/p><h5><strong>Technical security<\/strong><\/h5><p>Whistleblowing Solutions has security measures in place to reduce the risk of harmful software being executed in the IT environment. These include firewalls, layered networks, and the latest antivirus software, with updated versions on all workstations. A combination of antivirus software and other measures are applied to servers.<\/p><h5><strong>Backup and recovery<\/strong><\/h5><p>Whistleblowing Solutions AB makes regular backups of data, i.e., daily.<br \/><span style=\"font-size: 1.125rem;\">The backup and data recovery procedures are stored in a secure location separate from the primary IT equipment that processes the data.<\/span><strong style=\"font-size: 1.125rem;\">\u00a0<\/strong><\/p><h5><strong>Compliance with other GDPR requirements<\/strong><\/h5><p>Whistleblowing Solutions AB will, upon request, assist the Data Controller to amend\/update personal data for which they are responsible.<br \/><span style=\"font-size: 1.125rem;\">Unless agreed otherwise (or it is prevented due to legal reasons), Whistleblowing Solutions will delete all related data following cancellation of an agreement<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fb208a9 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"fb208a9\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0d322b7\" data-id=\"0d322b7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Whistleblowing Solutions AB handles large amounts of data for itself and on behalf of others. This applies, among other things, to personal data. Whistleblowing Solutions\u2019 activities are regulated by various laws, and internal guidelines which can be found in company documents such as plans, policies and procedures. Whistleblowing Solutions is certified according to ISO 27001. [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-2452","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Organisational and technical measures for data protection - Whistlelink<\/title>\n<meta name=\"description\" content=\"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.whistlelink.com\/pt-pt\/measures\/\" \/>\n<meta property=\"og:locale\" content=\"pt_PT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Organisational and technical measures for data protection\" \/>\n<meta property=\"og:description\" content=\"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.whistlelink.com\/pt-pt\/measures\/\" \/>\n<meta property=\"og:site_name\" content=\"Whistlelink\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/whistlelink\/\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-01T14:37:11+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Tempo estimado de leitura\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/measures\\\/\",\"url\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/measures\\\/\",\"name\":\"Organisational and technical measures for data protection - Whistlelink\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#website\"},\"datePublished\":\"2021-01-19T18:56:48+00:00\",\"dateModified\":\"2022-02-01T14:37:11+00:00\",\"description\":\"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/measures\\\/#breadcrumb\"},\"inLanguage\":\"pt-PT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/measures\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/measures\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Organisational and technical measures for data protection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#website\",\"url\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/\",\"name\":\"Whistlelink\",\"description\":\"A trusted provider of secure whistleblowing solutions.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-PT\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#organization\",\"name\":\"Whistlelink\",\"url\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-PT\",\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.whistlelink.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/WhistlelinkLogoEmail.png\",\"contentUrl\":\"https:\\\/\\\/www.whistlelink.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/WhistlelinkLogoEmail.png\",\"width\":704,\"height\":75,\"caption\":\"Whistlelink\"},\"image\":{\"@id\":\"https:\\\/\\\/www.whistlelink.com\\\/pt-pt\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/whistlelink\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/whistlelink\\\/\",\"https:\\\/\\\/vimeo.com\\\/user152082481\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Organisational and technical measures for data protection - Whistlelink","description":"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/","og_locale":"pt_PT","og_type":"article","og_title":"Organisational and technical measures for data protection","og_description":"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.","og_url":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/","og_site_name":"Whistlelink","article_publisher":"https:\/\/www.facebook.com\/whistlelink\/","article_modified_time":"2022-02-01T14:37:11+00:00","twitter_card":"summary_large_image","twitter_misc":{"Tempo estimado de leitura":"3 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/","url":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/","name":"Organisational and technical measures for data protection - Whistlelink","isPartOf":{"@id":"https:\/\/www.whistlelink.com\/pt-pt\/#website"},"datePublished":"2021-01-19T18:56:48+00:00","dateModified":"2022-02-01T14:37:11+00:00","description":"Whistlelink is committed to protecting your personal integrity and want you to feel safe when using our products and services.","breadcrumb":{"@id":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/#breadcrumb"},"inLanguage":"pt-PT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.whistlelink.com\/pt-pt\/measures\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.whistlelink.com\/pt-pt\/measures\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.whistlelink.com\/pt-pt\/"},{"@type":"ListItem","position":2,"name":"Organisational and technical measures for data protection"}]},{"@type":"WebSite","@id":"https:\/\/www.whistlelink.com\/pt-pt\/#website","url":"https:\/\/www.whistlelink.com\/pt-pt\/","name":"Whistlelink","description":"A trusted provider of secure whistleblowing solutions.","publisher":{"@id":"https:\/\/www.whistlelink.com\/pt-pt\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.whistlelink.com\/pt-pt\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-PT"},{"@type":"Organization","@id":"https:\/\/www.whistlelink.com\/pt-pt\/#organization","name":"Whistlelink","url":"https:\/\/www.whistlelink.com\/pt-pt\/","logo":{"@type":"ImageObject","inLanguage":"pt-PT","@id":"https:\/\/www.whistlelink.com\/pt-pt\/#\/schema\/logo\/image\/","url":"https:\/\/www.whistlelink.com\/wp-content\/uploads\/2021\/07\/WhistlelinkLogoEmail.png","contentUrl":"https:\/\/www.whistlelink.com\/wp-content\/uploads\/2021\/07\/WhistlelinkLogoEmail.png","width":704,"height":75,"caption":"Whistlelink"},"image":{"@id":"https:\/\/www.whistlelink.com\/pt-pt\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/whistlelink\/","https:\/\/www.linkedin.com\/company\/whistlelink\/","https:\/\/vimeo.com\/user152082481"]}]}},"_links":{"self":[{"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/pages\/2452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/comments?post=2452"}],"version-history":[{"count":0,"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/pages\/2452\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.whistlelink.com\/pt-pt\/wp-json\/wp\/v2\/media?parent=2452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}