EDACCO.eu
Close

Contacts

Visit edacco.eu for better experience

Connect-ED Assistance

GDPR & Data Protection

GDPR

Data Protection & GDPR Governance

EDACCO’s data-protection framework is designed around accountability, transparency, data minimisation and practical controls across website, network, project and platform workflows.

LEGAL FRAMEWORK

Regulation (EU) 2016/679

The GDPR applies within its territorial scope and has applied since 25 May 2018. EDACCO should operate its data-processing activities consistently with the GDPR and applicable Belgian data-protection rules.
PRINCIPLES

Seven operational principles

Processing should follow lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity/confidentiality; and accountability.
01

Lawful & transparent

Define purpose, basis and information given to individuals.

02

Minimal

Collect only data genuinely needed.

03

Controlled

Restrict access, manage vendors and retention.

04

Accountable

Maintain evidence of safeguards and decisions.

ROLES

Controller, processor and joint-controller analysis

For every connected service, EDACCO should document who determines purposes and means. Processor relationships require Article 28 terms; joint arrangements require transparent allocation of responsibilities.
GLOBELINE

Secretariat data flow

For Globeline-enabled workflows, define which fields transfer, who accesses them, the authoritative record, retention and whether Globeline acts on EDACCO instructions or for independent purposes.
RIGHTS WORKFLOW

Data-subject request procedure

EDACCO should maintain a documented process for receiving, authenticating, logging and answering requests.
01
ReceiveRoute to the privacy contact.
02
VerifyConfirm identity proportionately.
03
AssessIdentify systems and legal limits.
04
RespondProvide the lawful response on time.
05
RecordKeep evidence of handling.
DPIA

High-risk processing

Where new technology or processing is likely to result in high risk to individuals, EDACCO should assess whether a Data Protection Impact Assessment is required before deployment.
BREACH MANAGEMENT

Incident response

EDACCO should maintain an incident process that determines scope, risk, containment, evidence, processor notifications and whether notification to the supervisory authority or affected individuals is required.
INTERNATIONAL TRANSFERS

Cross-border safeguards

Transfers outside the EEA should be mapped and governed through the relevant Chapter V GDPR mechanism, supported by documented vendor and transfer assessments.