The General Data Protection Regulation 2016 (GDPR) is one of the most significant pieces of legislation affecting the way that Telemore AI LLC carries out its information processing activities. Significant fines are applicable if a breach is deemed to have occurred under the GDPR, which is designed to protect the personal data of citizens of the European Union. It is Telemore’s policy to ensure that our compliance with the GDPR, The California Consumer Privacy Act (CCPA), and other relevant legislation is clear and demonstrable at all times.
There are a total of 26 definitions listed within Article 4 – Definitions of the GDPR, and it is not appropriate to reproduce them all here. However, the most fundamental definitions with respect to this policy are as follows:
Personal data shall be:
Telemore AI LLC must ensure that it complies with all these principles both in the processing it currently carries out and as part of the introduction of new methods of processing such as new IT systems. The operation of an information security management system (ISMS) that conforms to the ISO/IEC 27001 international standard is a key part of that commitment.
The data subject also has rights. These consist of:
“To protect the integrity and security of our internal systems, we may limit access to specific details about how your data is processed, where such disclosure would compromise proprietary methods or allow for system manipulation. We are committed to balancing transparency with the need to maintain secure and reliable services.”
Each of these rights must be supported by appropriate procedures within Telemore AI LLC that allow the required action to be taken within the timescales stated in the regulations.
Unless it is necessary for a reason allowable in the regulations, consent must be obtained from a data subject to collect and process their data. In the case of children below the age of 16 (Note – this age may be lower in individual EU member states), parental consent must be obtained. Transparent information about our usage of their personal data must be provided to data subjects at the time that consent is obtained, and their rights regarding their data explained, such as the right to withdraw consent. This information must be provided in an accessible form, written in clear language, and free of charge.
If the personal data are not obtained directly from the data subject, then this information must be provided within a reasonable period after the data are obtained and definitely within one month.
Telemore AI LLC has adopted the principle of privacy by design and will ensure that the definition and planning of all new or significantly changed systems that collect or process personal data will be subject to due consideration of privacy issues, including the completion of one or more privacy (also known as data protection) impact assessments.
The privacy impact assessment will include:
Use of techniques such as data minimization and pseudo-anonymization will be considered where applicable and appropriate.
Transfers of personal data outside the European Union/USA must be carefully reviewed prior to the transfer taking place to ensure that they fall within the limits imposed by the GDPR. This depends partly on the European Commission’s judgment as to the adequacy of the safeguards for personal data applicable in the receiving country, and this may change over time.
A defined role of Data Protection Officer (DPO) is required under the GDPR if an organization is a public authority, if it performs large-scale monitoring, or if it processes particularly sensitive types of data on a large scale. Based on these criteria, Telemore AI LLC does not require a Data Protection Officer to be appointed.
It is Telemore’s policy to be fair and proportionate when considering the actions to be taken to inform affected parties regarding breaches of personal data. In line with the GDPR, where a breach is known to have occurred which is likely to result in a risk to the rights and freedoms of individuals, the relevant supervisory authority will be informed within 72 hours.
The following actions are undertaken to ensure that Telemore AI LLC complies at all times with the accountability principle of the GDPR:
These actions are reviewed regularly as part of the information security management process.