What are you looking for ?
Infinidat
Articles_top

OwnBackup Includes GDPR Support for SaaS Backups

Gives SaaS data controllers General Data Protection Regulation capabilities, exceeding regulation requirements.

OwnBackup Ltd. announced the availability of its General Data Protection Regulation (GDPR) readiness solution for Software as a Service (SaaS) backups-filling a void in both understanding and complying with the nuances of the GDPR in the periphery of backed-up data.

Privacy and data protection are now a global concern. Any company that controls the data of EU customers is subject to the GDPR and there is similar legislation on the table in the United States. Unfortunately, there is still much uncertainty about how to manage privacy risks associated with backed-up data,” noted Carl Gottlieb, data protection officer, Cognition Secure. “Being able to effectively meet rising regulatory demands within one backup protection platform like OwnBackup is essential.

Built on the company’s backup and recovery service, the GDPR features help customers easily respond to EU Data Subject rights requests, such as Right to Rectification, Right to Erasure, and Right to Data Portability, as they apply to personal data within backups and archives.

We have seen a lot of confusion and little guidance in the marketplace about backed-up data and GDPR compliance, leaving many SaaS users with questions,” said Sam Gutmann, CEO, OwnBackup. “OwnBackup has been designed with privacy in mind from the onset. As a Data Processor under GDPR, it’s our job to ease the path to GDPR compliance. As a continued pioneer in SaaS backup, recovery and replication, we have extended our platform to support clients in meeting, and even exceeding, GDPR requirements as they relate to backed-up data.

The company’s GDPR solution helps customers meet their GDPR requirements for SaaS backups in balance with company processes and operations through customized GDPR tools.

Highlights of release include:

  • Rectification requests: To support Data Subjects’ GDPR right to have their personal data updated, Data Controllers can now submit rectification requests directly through the independent OwnBackup application.

  • Erasure requests: To support Data Subjects’ GDPR right to be forgotten, Data Controllers can now submit erasure requests directly through the company’s application.

  • Full audit logs and notifications: After a Rectification Request or Erasure Request is processed, a notification is sent to the Controller’s administrators confirming that processing has completed.

  • Configure retention period: SaaS system administrators can implement customized backup retention policies to match their organization’s corporate risk tolerance for retention of EU Subject Data. The firm’s users may set custom backup expiration dates, whether days, weeks, months or years.

  • Advanced find: Users can quickly search for Data Subject information across backups, including archived data and within attachments.

  • Export data: Users can also export or transfer a Data Subject’s personal data, in .CSV file or SQL database format, to support GDPR Right to Data Portability.

Click to enlarge

Blog: Insights about GDPR and best practices for backed-up data

Articles_bottom
AIC
ATTO
OPEN-E