In May 2018, the EU General Data Protection Regulation (GDPR) replaced the existing 1995 EU Data Protection Directive (European Directive 95/46/EC).
RBR Active Limited currently complies with applicable data protection regulations and is committed to GDPR compliance across its relevant services. RBR Active Limited has a dedicated internal team made up of cross-functional stakeholders overseeing RBR Active Limited’s GDPR on-going compliance efforts, which include:
RBR Active Limited has reviewed where and how our relevant services collect, use, store and dispose of personal data and has updated policies, standards, governance and documentation where needed. RBR Active Limited is dedicated to keeping such due diligence current and carrying out re-assessments periodically and/or as required by changed circumstances.
Working in conjunction with our partners and customers, RBR Active Limited is reviewing our contractual commitments and updating as needed to directly address GDPR requirements. RBR Active Limited has reviewed its existing supplier contracts to ensure GDPR compliance throughout its supply chain and will continue to conduct due diligence as new suppliers are on boarded.
CROSS-BORDER DATA TRANSFER
In addition to ensuring RBR Active Limited’s contractual commitments meet the requirements to legally transfer data from the EU to the rest of the world under applicable law, RBR Active Limited plans to certify under the EU-US Privacy Shield Framework.
EMPLOYEE TRAINING AND AWARENESS
All RBR Active Limited employees must complete data privacy and security training. RBR Active Limited has supplemented existing training modules with GDPR-specific content. In addition to these training requirements, RBR Active Limited conducts on-going awareness initiatives on a variety of topics, including data protection, security and privacy.
RBR Active Limited Partners and Customers
Compliance with the GDPR requires a partnership between RBR Active Limited and our partners and customers in their use of applicable RBR Active Limited products and services. In this context, RBR Active Limited generally will act as a data processor and our partners and customers generally will act as data controllers. Working together, we hope to explore opportunities within our relevant service offerings to assist our partners and customers meet their GDPR obligations. In the meantime, RBR Active Limited encourages partners and customers to independently familiarise themselves with the GDPR.