General Data Protection Regulation (GDPR) FAQs
What is GDPR?
GDPR is a data protection law that applies in the European Union. It governs how personal data of data subjects in the EU/EEA is collected, processed, and stored. It grants data subjects rights over their data and imposes data protection obligations on any organization that processes the personal data of those located in the EU/EEA.
To assist you in your GDPR compliance practices, listed below are the steps we have taken to comply with GDPR.
What has Bioz done to comply with GDPR?
As a controller, to comply with GDPR, we:
· Only collect the minimum amount of personal data necessary (scientists’ name, email address, affiliation (academic or industry), institution/company, country, and funds received through grants) to provide Bioz Next. As described in our Privacy Notice, this information is necessary to enable Bioz Next users to more easily contact scientists about science-related opportunities.
· Provide a clear, accessible privacy notice that explains what we collect, why we collect it, who we share it with, and how long we keep it, as well as informs data subjects of their privacy rights along with instructions on how to exercise those rights.
· Have a dedicated procedure in place for purposes of intaking and fulfilling data subject requests. If you are a scientist and do not want to be included in the Bioz Next database, please email us at optout@bioz.com.
· We implement appropriate technical and organizational security measures, such as access controls and encryption, to protect the personal data that we collect and maintain from unauthorized access, destruction, use, modification, or disclosure.
· Have an incident response procedure in place to ensure we contain and eradicate threats while meeting our notification obligations to data subjects and Supervisory Authorities in the event of a personal data breach.
· Conduct legitimate interest analyses whenever our legitimate interest serves as the lawful basis for the processing, including when we process the personal data (name and email) of scientists in connection with Bioz Next.
· Enter into data processing agreements with our processors pursuant to Article 28.
· We have instituted a policy informing and obligating our employees to maintain the confidentiality of your information.
What about cross-border transfers of personal data?
As a US-based entity, we collect personal data directly from the United States, meaning there is no cross-border transfer of personal data. However, we still apply reasonable safeguards to protect such personal information from unauthorized access or use, including by implementing the technical and organizational measures as explained above.
Questions?
If you have any questions regarding our GDPR compliance, please email us at gdpr@bioz.com.