What is the GDPR?
The General Data Protection Regulation (GDPR) is a regulation in the European Union (EU) designed to strengthen and unify privacy and personal data protections for all individuals within the EU.
Who does the GDPR affect?
The GDPR applies to organizations located within the EU, as well as organizations located outside of the EU that offer goods or services to, or monitor the behaviour of, individuals within the EU. It applies to all companies processing and holding the personal data of individuals residing in the EU regardless of the company’s location.
‘Personal data’ is any information that can be used to directly or indirectly identify a person. It can be anything from a name, photo, email address or bank details to posts on social networking websites, medical information or a computer IP address.
Duda platform & the GDPR
Duda takes personal data protection and the right to online privacy seriously. Duda has completed a thorough review of the legal and technical impacts of the GPDR to and continues to make adjustments to our products, services, and documentation to comply with the GDPR. This includes giving Duda customers more control over their personal data and providing the necessary tools to protect the information of visitors to Duda websites.
How has Duda addressed GDPR compliance?
- We have conducted a security audit in line with the GDPR’s security recommendations.
- Duda’s organizational policies, especially our data security and data privacy policies, are completed in accordance with the GDPR framework. Our staff is fully aware of the need for strong data security and privacy practices across the entire company. This is an ongoing process and we see it as a key factor to our success in this project.
- Duda is documenting and developing all operational procedures required to support an individual’s right to review any of their private data that we store, the right to be forgotten, etc.
- We have updated all our data processing agreements in light of GDPR requirements.
- Commitment to privacy & data security is a long-term commitment, not a one-off project. Duda remains committed to data security and privacy and we will help provide the tools you need in an ever-changing landscape of regulation and real-world threats.
- We have enabled the following new features:
- You can now easily create a Privacy page to enable you to communicate information about processing the personal data of your users in a clear and transparent way.
- Termly Consent Management Platforms (CMP) is available in the App Store. (link to Termly in App Store).
- Your contact forms can now include convenient Opt-in notifications to collect consent from site visitors to process their form responses.
- The right of your users to be forgotten can be realized with the help of the Form responses tab in your site dashboard.
- Minimization of data collections and pseudonymization of analytic data.
Is Duda DPF Certified?
Duda is aware of the DPF. We will be carefully examining the implications of certification, and will update you as and when Duda is DPF certified. We are also tracking the status of our vendors. In the meantime, all transfers of data to Duda in the US are secured by Standard Contractual Clauses, in connection with which we have completed a Transfer Risk Assessment which documents the legality of such transfer. The new DPF empowers the US Civil Liberties Protection Officer and the Data Protection Review Court (DPRC) to review cases of data transferred based on SCCs too; such that the regulatory profile of Duda's transfers is even stronger now that the DPF has been agreed.
How do I submit GDPR-related questions, concerns, or issues to Duda?
If you have questions about Duda and the GDPR, or wish to report a related issue, please contact Duda support as soon as possible by visiting our support portal and clicking Submit a Request in the upper right corner and selecting GDPR from the drop-down.