GDPR compliance & Deloitte as DPO

Given the nature of geo location data, we have to deal with GDPR in a very strict manner. Having started in 2019 we have build our company from a privacy by design point of view. We provide maximum privacy & security for panel members via different efforts. 

  • GDPR-focused consent flow limits data tracking to dual optin users referencing our SDK privacy policy. There are two integrations possible (as outlined technically in the SDK documentation - see attachment):
    • A default consent flow is triggered when required in the app and optimized for different operating systems
    • An app owner can decide to connect our SDK via a custom implementation to integrate it in its own consent framework (such as IABโ€™s TCF 2.2 framework).
  • An extensive DPIA documents all efforts in terms of privacy.
  • We conduct yearly pen tests to validate & improve security.
  • Technical measures are outlined in detail on our Privacy center.
  • We have processor agreements (DPAs) with both partners and subcontractors that stipulate how to deal with user rights, privacy and security (see attachment).
  • We work with an objective, external partner Deloitte that acts as our DPO office.

Was this article helpful?