Data Security Services

Our strong data-centric security services offer an understanding of data protection requirements and regulations, strategy development, comprehensive data defense, unified visibility, and monitoring against unapproved access, disclosure, or data theft across your organization’s data environment. Moreover, we play a vital role in spreading data protection awareness and regulatory/legal policies implementation.

Our wide-ranging services include:

AUDITS / VERIFICATIONS

GAP ANALYSIS AS PER THE EUROPEAN GENERAL DATA PROTECTION REGULATION (GDPR) AND THE SWISS DATA PROTECTION ACT (DSG) Firstly, we perform a thorough gap analysis to assess the degree of your organization’s data categories and its compliance with either DSG or GDPR.

With our Data Protection Gap Analysis, our clients get useful information such as:

• A Summarized overview of the organization’s data protection maturity
• An evaluation of the implemented protective measures and actions
• A full report with recommendations for better compliance and security

GDPR WEB APPLICATION AUDIT

Our external GDPR Web Audit provides a comprehensive appraisal that facilitates ascertaining their GDPR compliance and fulfillment of any legal obligations.

Our clients are provided the following support with our Data Protection Gap Analysis:

• GDPR-based Analysis and evaluation of the confidential information
• Recognition of discrepancies as per GDPR recommendation
• Tracking software identification
• Assessment by an independent Cybersecurity Expert for GDPR-based IT security features

AWARENESS

RAISING AWARENESS OF DATA PROTECTION WITH STAFF MEMBERS

CIA Magnifier provides educational services to raise Data Protection Awareness in organizations and their staff because compliance begins from within, the more aware employees are, the more vigilantly they implement data security policies. Following are the e-learning courses for raising valuable data protection awareness:

Data Protection Principles for Employees DSG E-Learning Course:

The Swiss Federal Data Protection Act (DSG) outlines provisions for processing personal data in Switzerland. This e-learning course equips your employees with the basic practical knowledge of DSG legal regulations and demonstrates effective internal implementation for them.

Course Outline:

• The meaning of data protection
• The Data Protection Act (CH-DSG and VDSG)
• Personal data and sensitive personal data
• Right to information on data protection
• Data Protection Officer
• Laws and regulations
• Disclosure of information
• Company monitoring objectives
• Classification of data and information Data security
• Data protection principles
• Quiz

The EU General Data Protection Regulation (GDPR) E-learning Course

The EU General Data Protection Regulation (GDPR) has instituted a steady data protection law enforced in the European Union concerning how organizations should and should not process the personal data of EU citizens. The GDPR online course educates employees with legal and effective ways of processing and protecting data, and models effective implementation for them.

The outline of this E-learning course is as follows:

Introduction to Data Protection

• The EU General Data Protection Regulation
• The marketplace principle
• Examples of address lists
• Personal data
• Special categories of personal data
• Data protection stakeholders
• Principles for processing personal data
• Rights of the data subject and obligations of the data controller
• Data transmission to non-EU countries
• Data Protection Officer
• Quiz

CONSULTING

DEVELOPING A DATA PROTECTION STRATEGY PER THE DSG/GDPR

CIA Magnifier offers you extensive consultation and advisory services aimed at designing DSG/GDPR compliant Data Protection Strategies, also in aligning business processes and operations with defined rules of securing personal data. We offer:

• Consultations for development/implementation of data protection framework and compliance strategies/ business processes/ technical or organizational risk management measures
• Services regarding CH-DSG / GDPR compliant documents
• Data Protection Impact Assessment (DSFA)

DATA PROTECTION IMPACT ASSESSMENT (DSFA)

We always insist our clients carry out this vital data protection impact assessment (DSFA) before personal data gets processed, as it ensures compliance with GDPR (Article.35).

The GDPR enlists the subsequent good examples of obligatory implementation:

• Systematic and detailed assessment of personal characteristics of natural persons
• Large-scale processing of sensitive data or personal data on criminal convictions or offenses
• Systematic monitoring of areas with public access
• Implementation of the Data Protection Impact Assessment (DSFA)
• Establishment of regular and ongoing data protection impact assessment (DSFA)

DATA PROTECTION ON THE INTERNET AND ONLINE STORES

The GDPR/ DSG regulates the process of obtaining new customers, public availability of personal, products/services promotion, personalized advertisements, and much more. We assist you in understanding the defined requirements for systems and processes ordained by the regulatory bodies, so all Data systems/processes are designed as per the compliance principles, so no additional expenses incur with the introduction of any new legislation in the future.

Our experts will support you in the following areas, such as:

• Personal data management in online marketing campaigns as per GDPR/ DSG.
• Developing a DSG/ GDPR conforming Online Data Protection Disclaimer or Statement, Analytics, cookies, tracking, and more.
• Establishing CRM systems, Social Media Marketing, and Email Marketing under the guidelines of GDPR/DSG

E-PRIVACY CERTIFICATION ASSISTANCE

CIA Magnifier creates trust by assisting you in acquiring Data protection certifications. The most trusted data protection certification is ePrivacy Label, which communicates that all personal and public data is extremely secure and is following data protection laws/bodies.

Our services cover:

• Aid and advisory with ePrivacy Seal (TM) ce*rtification
• Technical evaluation, analysis, and successful implementation of defined security measures as per ePrivacy criteria.

IMPLEMENTATION

DPO AS A SERVICE

For ensuring smooth implementation, we outsource our experts as Data Protection Officers to Companies for successful digitalization and compliance with regulatory bodies. The DPO as an external service supports:

• Implementing Key Data protection/ processing decisions
• Enforces legal and regulatory Compliance as per Data Protection governing policies
• Exercises Verification processes/ protocols for personal data and registration
• Ensures Full Cooperation with data protection authorities

DATA MANAGEMENT SYSTEM TOOL

We provide support for the HiScout GRC Suite's data protection management module which generates GDPR compliant documentation and fulfills systematic data management obligations efficiently, such as:

• Data protection impact assessment, administering activity directory, authorization, and deletion concepts
• A complete data model for Governance, Risk Management, and Compliance ecosystem
• Adapting work views to satisfy individual requirements
• Data evaluation and using GI technology for integrating additional systems

AUDITING EXTERNAL OF CONTRACT DATA PROCESSING

With Multifaceted and complex data processes, contractual outsourcing has become a trending choice for organizations, but this has also increased the risk factor because service provider selection and verification is not an easy pill to swallow. Here is CIA Magnifier simplifies this task for you, by extending Auditing services inclusive of:

• Defining guidelines for contractual outsourcing of data processing
• Registration and documentation of existing service providers, relationships, and appraisal of contracts
• Risk assessment for individual service providers
• Risk Audit of service level agreement