EDACCO’s data-protection framework is designed around accountability, transparency, data minimisation and practical controls across website, network, project and platform workflows.
LEGAL FRAMEWORK
Regulation (EU) 2016/679
The GDPR applies within its territorial scope and has applied since 25 May 2018. EDACCO should operate its data-processing activities consistently with the GDPR and applicable Belgian data-protection rules.
PRINCIPLES
Seven operational principles
Processing should follow lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity/confidentiality; and accountability.
01
Lawful & transparent
Define purpose, basis and information given to individuals.
02
Minimal
Collect only data genuinely needed.
03
Controlled
Restrict access, manage vendors and retention.
04
Accountable
Maintain evidence of safeguards and decisions.
ROLES
Controller, processor and joint-controller analysis
For every connected service, EDACCO should document who determines purposes and means. Processor relationships require Article 28 terms; joint arrangements require transparent allocation of responsibilities.
GLOBELINE
Secretariat data flow
For Globeline-enabled workflows, define which fields transfer, who accesses them, the authoritative record, retention and whether Globeline acts on EDACCO instructions or for independent purposes.
RIGHTS WORKFLOW
Data-subject request procedure
EDACCO should maintain a documented process for receiving, authenticating, logging and answering requests.
01
ReceiveRoute to the privacy contact.
02
VerifyConfirm identity proportionately.
03
AssessIdentify systems and legal limits.
04
RespondProvide the lawful response on time.
05
RecordKeep evidence of handling.
DPIA
High-risk processing
Where new technology or processing is likely to result in high risk to individuals, EDACCO should assess whether a Data Protection Impact Assessment is required before deployment.
BREACH MANAGEMENT
Incident response
EDACCO should maintain an incident process that determines scope, risk, containment, evidence, processor notifications and whether notification to the supervisory authority or affected individuals is required.
INTERNATIONAL TRANSFERS
Cross-border safeguards
Transfers outside the EEA should be mapped and governed through the relevant Chapter V GDPR mechanism, supported by documented vendor and transfer assessments.
DATA PROTECTION
Need to exercise a data-protection right?
Use the dedicated privacy contact published on the live website.