A.5.34 Privacy and Protection of Personally Identifiable Information (PII)
Control Objective
The organisation shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements.
Policy Statement
anDREa identifies and strictly complies with all legal, regulatory, and contractual requirements governing privacy and the protection of Personally Identifiable Information (PII). Our primary regulatory framework is the General Data Protection Regulation (GDPR), supplemented by the strict availability and confidentiality mandates of NIS 2.
Privacy Governance Framework
To protect data subjects and ensure continuous compliance, anDREa maintains a comprehensive privacy management architecture:
-
Record of Processing Activities (ROPA): anDREa maintains a centralized Record of Processing Activities (ROPA) that maps all organizational data workflows. For each information system, the registry systematically documents:
- Impacted categories of data subjects:
- Specific types of PII collected and processed.
- The defined lawful basis for processing (e.g., contractual necessity, legitimate interest, consent).
- The explicit business and technical purpose of the processing activity.
- Data Minimization & Encryption: Technical enforcement parameters for anonymization, pseudonymization, and storage limitations are detailed across:
- Impacted categories of data subjects:
-
Proactive Risk Management: Before introducing new technologies, features, or workflows that process PII, anDREa evaluates privacy implications through formal risk assessment processes.
-
Governance Documentation: Deep operational insight into our privacy controls, data flows, and risk handling mechanisms are documented in the following internal compliance assets: