What is GDPR?

GDPR is an EU-wide privacy and data protection law that regulates how EU residents' data is protected by companies and enhances the control the EU residents have, over their personal data. 

The GDPR is relevant to any globally operating company and not just the EU-based businesses and EU residents. Our customers’ data is important irrespective of where they are located, which is why we have implemented GDPR controls as our baseline standard for all our operations worldwide. GDPR has taken effect from 25th May 2018.

What is personal data?

Any data that relates to an identifiable or identified individual. GDPR covers a broad spectrum of information that could be used on its own, or in combination with other pieces of information, to identify a person. Personal data extends beyond a person’s name or email address. Some examples include financial information, political opinions, genetic data, biometric data, IP addresses, physical address, sexual orientation, and ethnicity.

How prepared is Zoho for GDPR?

We have acted on many fronts to adhere to this new regulation.

  •   We have raised awareness across the organization through frequent discussions in our internal channels, and trained employees to handle data appropriately. They now understand the importance of information security and the high standards set by GDPR.
  •   We have assessed all Zoho products, individually, against the requirements of the GDPR and have implemented new features that will give you more control over your data and ease your burden of achieving GDPR compliance.
  • Take a look at what some our products have done to be GDPR-ready.

  •   We have constituted an Information Asset Register(IAR), which includes information on all the roles Zoho assumes, such as a data controller and processor. It details on various categories of personal data processed by our organization and which department is getting access to which data and for what purpose. It has a comprehensive coverage of all our processes and procedures.
  •   We have assessed our sub-processors (third party service providers, partners) and streamlined the contract process with them to ensure that they have addressed the pressing needs of the current security and privacy world.
  •   We have appointed internal privacy champions for all our teams. We have also appointed a Data Protection Officer (DPO).
  •   Our application teams have embraced the concept of privacy by design and have provided you more control over the data you store in our systems. These provisions may vary based on a product’s characteristics and domain. We constantly endeavour to provide you with more enhancements, which shall be rolled out in phases.
  •   We have amended our Data Processing Addendum (based on Model Contractual Clauses) to be compliant with the data processing requirements of GDPR.

    If you are the organization administrator and would like to sign a DPA with us, we’ve made it available to be signed electronically in a few easy steps.

    •  If you've signed up in our US datacenter, click here to view the DPA. To initiate the signing process, click here.
    •  If you've signed up in our EU datacenter, click here to view the DPA. To initiate the signing process, click here.

      Note: Make sure that you have logged into your Zoho account before clicking on the link. You can also drop an email to legal@zohocorp.com to request a copy of the Data Processing Addendum.

  •   We conducted Data Protection Impact Assessments (DPIA). Based on the results, we have put in place appropriate controls on data processing and management.
  •   We conducted internal audits of our products, processes, operations, and management. The findings were communicated to our teams, who have worked out the solutions to the identified problems.
  •   Based on the DPIAs and internal audits, we have improved our data security methods and processes. This includes encrypting data at rest, based on the level of sensitivity and likelihood of risks. We have developed in-house tools for better governance and discovery of data.
  •   We have cleaned up our databases to ensure that we have only the latest and most accurate information. This cleanup process includes removing terminated and dormant accounts as per our Terms of Service.
  •   When needed, breach notifications will be done according to our internal Privacy Incident Response policy. Customers will be notified of a breach within 72 hours after Zoho becomes aware of it. For general incidents, we will notify users through our blogs, forums, and social media. For incidents specific to an individual user or an organization, we will notify the concerned party through email (using their primary email address).
  •   We have revised our Privacy Policy to incorporate the requirements of the applicable privacy laws based on our data inventory, data flows, and data handling practices.

Join the live forum-based Q & A session and get answers to your questions on Zoho's updated Privacy Policy in keeping with GDPR. Ask now!

FAQs:

1. What is GDPR?

  • The EU's General Data Protection Regulation (GDPR) is a game changer in data protection and privacy laws. The EU has realized that while technology has evolved drastically in the last few decades, privacy laws have not. In 2016, EU regulatory bodies decided to update the current Data Protection Directive to suit the changing times. This law creates a comprehensive list of regulations that govern the processing of EU residents' personal data.

2. Who does it apply to?

    3. Where does the GDPR apply?

      4. What are the penalties for non-compliance?

        5. Who are the key stakeholders?

          6. What is personal data or Personally Identifiable Information (PII)?

            7. What are the key changes from the previous regulations?

              8. What are the lawful bases the data controller can use to process customer data?

                9. What is LIA?

                  10. Does the GDPR require EU personal data to stay in the EU?

                    11. Where can I find additional resources on GDPR? 

                      Resources:

                      Our Continuing Commitment to Your Privacy - Sridhar Vembu, CEO Zoho Corp.

                      GDPR - The Essentials

                      Please feel free to ask questions and share concerns with us at privacy@zohocorp.com.

                      Choose Privacy. Choose Zoho.

                      • bsi-assurance
                      • TRUSTe
                      • SOC

                      Disclaimer: The information presented herein should not be taken as legal advice. We recommend that you seek legal advise on what you need to do to comply with the requirements of GDPR.