{"id":1355,"date":"2023-07-14T08:51:07","date_gmt":"2023-07-14T06:51:07","guid":{"rendered":"https:\/\/moorlaw.digicube.dev\/rechtsgebiet\/what-should-smes-do\/inventory\/"},"modified":"2023-11-18T12:29:40","modified_gmt":"2023-11-18T11:29:40","slug":"inventory","status":"publish","type":"rechtsgebiet","link":"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/inventory\/","title":{"rendered":"Inventory"},"content":{"rendered":"\n<p>The inventory aims to understand which data is processed in the company and what measures have already been taken. The inventory is the basis for identifying the necessary measures.<\/p>\n\n<p>Personal Data<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Where and how is personal data collected and for what purpose?<\/li>\n\n\n\n<li>What personal data is processed and for what purpose?<\/li>\n\n\n\n<li>Are particularly sensitive data processed?<\/li>\n\n\n\n<li>Is profiling or high-risk profiling conducted?<\/li>\n\n\n\n<li>How are the data processed and by what means?<\/li>\n<\/ul>\n\n<p>Data security<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Where are the data stored (paper) or stored (digital)?<\/li>\n\n\n\n<li>Who has access to the data or can access the data?<\/li>\n\n\n\n<li>How are the data already protected (physically, digitally)?<\/li>\n<\/ul>\n\n<p>Data Disclosure<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Are data disclosed to third parties? To whom?<\/li>\n\n\n\n<li>Are data disclosed to data processors?<\/li>\n\n\n\n<li>Are data disclosed to contractual partners?<\/li>\n\n\n\n<li>Are data transmitted only within the country or also abroad (secure and insecure countries)?<\/li>\n<\/ul>\n\n<p>Documents and Contracts<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Is there already a privacy policy for your website?<\/li>\n\n\n\n<li>Is there already a privacy policy for customer relationships and employees?<\/li>\n\n\n\n<li>Are there already contracts with data processors?<\/li>\n\n\n\n<li>Are there already clauses on data protection in contracts with contractual partners, customers, etc.?<\/li>\n<\/ul>\n\n<p>Rights of Data Subjects<\/p>\n\n<ul class=\"wp-block-list\">\n<li>How are data subjects informed about data collection and processing?<\/li>\n\n\n\n<li>How are requests for information from data subjects handled?<\/li>\n\n\n\n<li>How are requests from data subjects for the release of their data handled?<\/li>\n<\/ul>\n\n<p>Information Technology and Telephony (ICT)<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Which IT applications are used? In which applications are personal data processed?<\/li>\n\n\n\n<li>How is communication conducted (telephony, email, video calls, etc.)? How is personal data processed in these communications?<\/li>\n\n\n\n<li>How is the ICT organized?<\/li>\n\n\n\n<li>Are cloud services used? Which ones? Are data transmitted to the USA? Or can companies in the USA access the data?<\/li>\n\n\n\n<li>Do you engage in online marketing? If yes, through which platforms? Are personal data transmitted to or collected by these platforms?<\/li>\n<\/ul>\n\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background\"\/>\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\"><div class=\"gb-container gb-container-98a7c598\">\n<div class=\"gb-container gb-container-11a0998e\">\n\n<p><strong>Services<\/strong><\/p>\n\n\n\r\n<section id=\"digicube-block-653b8880876e9\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/service\/legal-services-for-corporates\/\">Legal Services for Corporates<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n\n<div class=\"gb-container gb-container-25f5bccc\">\n\n<p><strong><strong>Further reading<\/strong><\/strong><\/p>\n\n\n\r\n<section id=\"digicube-block-653b888087772\"  class=\"chooseposttype-wrap\" >\r\n    <ul class=\"cpt-posts\">\r\n                   <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/what-should-smes-do\/\">What should SMEs do?<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/new-swiss-data-protection-law\/\">New Swiss Data Protection Law<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/documentation-obligations\/\">Data protection Documentation Obligations<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/data-protection-register-of-processing-activities\/\">Data Protection Register of Processing Activities<\/a>\r\n                <\/li>\r\n                              <li class=\"custom-block-post\">\r\n                  <a href=\"https:\/\/moor-law.ch\/en\/law-field\/data-protection-law\/data-protection-representation-in-switzerland\/\">Data protection representation in Switzerland<\/a>\r\n                <\/li>\r\n                   <\/ul>\r\n<\/section> \n<\/div>\n<\/div><\/div><\/div>\n\n<hr class=\"wp-block-separator has-text-color has-accent-color has-alpha-channel-opacity has-accent-background-color has-background\"\/>\n","protected":false},"excerpt":{"rendered":"<p>Take a data protection inventory to evaluate the necessary measures<\/p>\n","protected":false},"featured_media":0,"parent":1359,"menu_order":19,"template":"","rechtsgebiet-kategorie":[41],"class_list":["post-1355","rechtsgebiet","type-rechtsgebiet","status-publish","hentry","rechtsgebiet-kategorie-data-protection-law"],"acf":[],"_links":{"self":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet\/1355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet"}],"about":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/types\/rechtsgebiet"}],"up":[{"embeddable":true,"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet\/1359"}],"wp:attachment":[{"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/media?parent=1355"}],"wp:term":[{"taxonomy":"rechtsgebiet-kategorie","embeddable":true,"href":"https:\/\/moor-law.ch\/en\/wp-json\/wp\/v2\/rechtsgebiet-kategorie?post=1355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}