<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Legal &#8211; foxondo</title>
	<atom:link href="https://foxondo.com/en/category/legal/feed/" rel="self" type="application/rss+xml" />
	<link>https://foxondo.com</link>
	<description>Die Datenschutz-Dokumentations-Software</description>
	<lastBuildDate>Wed, 29 Apr 2026 07:04:39 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://foxondo.com/wp-content/uploads/2025/12/cropped-favicon-32x32-1-32x32.png</url>
	<title>Legal &#8211; foxondo</title>
	<link>https://foxondo.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>ChatGPT, DeepL, and friends in foxondo: How to document AI software in existing IT processes.</title>
		<link>https://foxondo.com/en/document-ai-software-in-foxondo/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Wed, 29 Apr 2026 07:02:47 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://foxondo.com/?p=30114</guid>

					<description><![CDATA[Everyone is talking about artificial intelligence, but in data protection documentation there is a lot of uncertainty around its usage. With foxondo, the solution is simple, and you do not need to reinvent the wheel. Today we will show you how to integrate AI applications into your existing IT infrastructure and processes while staying compliant with all privacy requirements – from DPAs to third country transfers.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="30114" class="elementor elementor-30114">
				<div class="elementor-element elementor-element-1b6f648 e-flex e-con-boxed e-con e-parent" data-id="1b6f648" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-cb67d37 elementor-widget elementor-widget-text-editor" data-id="cb67d37" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p><strong>Everyone is talking about artificial intelligence, but in data protection documentation there is a lot of uncertainty around its usage. With foxondo, the solution is simple, and you do not need to reinvent the wheel. Today we will show you how to integrate AI software into your existing IT infrastructure and processes while staying compliant with all privacy requirements – from DPAs to third country transfers.</strong></p>								</div>
				<div class="elementor-element elementor-element-14edd56 elementor-widget elementor-widget-heading" data-id="14edd56" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="heading.default">
					<h2 class="elementor-heading-title elementor-size-default">Where in foxondo should AI services be documented?</h2>				</div>
				<div class="elementor-element elementor-element-e88ce24 elementor-widget elementor-widget-text-editor" data-id="e88ce24" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p>In most companies, AI tools are provided as general working tools. That’s why we think they are best documented in the process <strong>“Provision of operational IT infrastructure&#8221;</strong>. Instead of creating a new process, you can simply add this building block in your record of processing activities (RoPA, i.e. the “Processes” module in foxondo). This applies to all AI tools intended for general use, such as ChatGPT and CoPilot, which are used across various company departments.</p><p><strong>There are exceptions:</strong></p><p>If the AI tool is only used in a very specific process (for example, e.g. a chatbot that assists HR with shortlisting candidates for vacant position), then the documentation of this tool should be added to that specific process.</p>								</div>
				<div class="elementor-element elementor-element-0bb3a05 elementor-widget elementor-widget-heading" data-id="0bb3a05" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="heading.default">
					<h3 class="elementor-heading-title elementor-size-default">You should describe the usage of the AI tool in the following foxondo questions:</h3>				</div>
				<div class="elementor-element elementor-element-afcc797 elementor-position-inline-start elementor-view-default elementor-mobile-position-block-start elementor-widget elementor-widget-icon-box" data-id="afcc797" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="icon-box.default">
							<div class="elementor-icon-box-wrapper">

						<div class="elementor-icon-box-icon">
				<span  class="elementor-icon">
				<i aria-hidden="true" class="fas fa-laptop"></i>				</span>
			</div>
			
						<div class="elementor-icon-box-content">

									<h3 class="elementor-icon-box-title">
						<span  >
							Systems and software						</span>
					</h3>
				
									<p class="elementor-icon-box-description">
						List the AI applications you use (for example ChatGPT or Microsoft Copilot) in the text field. Ideally, you would also add a short description of the intended purpose.					</p>
				
			</div>
			
		</div>
						</div>
				<div class="elementor-element elementor-element-4e053ab elementor-position-inline-start elementor-view-default elementor-mobile-position-block-start elementor-widget elementor-widget-icon-box" data-id="4e053ab" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="icon-box.default">
							<div class="elementor-icon-box-wrapper">

						<div class="elementor-icon-box-icon">
				<span  class="elementor-icon">
				<i aria-hidden="true" class="fas fa-book"></i>				</span>
			</div>
			
						<div class="elementor-icon-box-content">

									<h3 class="elementor-icon-box-title">
						<span  >
							Legal basis and purpose						</span>
					</h3>
				
									<p class="elementor-icon-box-description">
						Check if the original purpose of the process also includes AI usage or if this needs to be added.					</p>
				
			</div>
			
		</div>
						</div>
				<div class="elementor-element elementor-element-2dce3c1 elementor-position-inline-start elementor-view-default elementor-mobile-position-block-start elementor-widget elementor-widget-icon-box" data-id="2dce3c1" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="icon-box.default">
							<div class="elementor-icon-box-wrapper">

						<div class="elementor-icon-box-icon">
				<span  class="elementor-icon">
				<i aria-hidden="true" class="fas fa-globe-americas"></i>				</span>
			</div>
			
						<div class="elementor-icon-box-content">

									<h3 class="elementor-icon-box-title">
						<span  >
							Data transfer to third countries						</span>
					</h3>
				
									<p class="elementor-icon-box-description">
						Many AI service providers are not located in the EU. Use the corresponding questions in foxondo to document the data transfer (keyword: data privacy framework or standard contractual clauses).					</p>
				
			</div>
			
		</div>
						</div>
				<div class="elementor-element elementor-element-8133393 elementor-position-inline-start elementor-view-default elementor-mobile-position-block-start elementor-widget elementor-widget-icon-box" data-id="8133393" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="icon-box.default">
							<div class="elementor-icon-box-wrapper">

						<div class="elementor-icon-box-icon">
				<span  class="elementor-icon">
				<i aria-hidden="true" class="fas fa-file-contract"></i>				</span>
			</div>
			
						<div class="elementor-icon-box-content">

									<h3 class="elementor-icon-box-title">
						<span  >
							Data processing agreements						</span>
					</h3>
				
									<p class="elementor-icon-box-description">
						Indicate whether a data processing agreement exists for each tool. This is usually the case, especially in enterprise software. This must be documented in foxondo.					</p>
				
			</div>
			
		</div>
						</div>
				<div class="elementor-element elementor-element-edf7f36 elementor-widget elementor-widget-heading" data-id="edf7f36" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="heading.default">
					<h3 class="elementor-heading-title elementor-size-default">What else is important?</h3>				</div>
				<div class="elementor-element elementor-element-e6090df elementor-widget elementor-widget-text-editor" data-id="e6090df" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p>Depending on the application of the AI tool, a new data protection impact assessment may be required, or the existing one may need to be updated.</p><p>If you have any questions on the documentation of AI tools in foxondo, we would be happy to help. Contact us at <a href="mailto:info@foxondo.com">info@foxondo.com</a>.</p>								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Update on ‘Storage and deletion’ in the personnel management process</title>
		<link>https://foxondo.com/en/storage-and-deletion-in-the-personnel-management/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Mon, 24 Nov 2025 14:19:12 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28426</guid>

					<description><![CDATA[The personnel management process in foxondo has been revised: we have replaced the questions about former employees, retention periods and the implementation of deletion requests with a clearer and more practical structure.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28426" class="elementor elementor-28426">
				<div class="elementor-element elementor-element-7c8b4aa4 e-flex e-con-boxed e-con e-parent" data-id="7c8b4aa4" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-5fa64332 elementor-widget elementor-widget-text-editor" data-id="5fa64332" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">Why was this process changed?</p>
								</div>
				<div class="elementor-element elementor-element-0dab1c6 elementor-widget elementor-widget-text-editor" data-id="0dab1c6" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p><strong></strong></p>
<p class="wp-block-paragraph">In the Process of personnel management, the requirements for storage and deletion differ significantly depending on whether a person is currently employed or has already left the company. What can or even must be stored about whom, and for how long?</p>

<p class="wp-block-paragraph">In the past structure of foxondo, we queried individual data categories of employees and former employees. The answers to these questions should have been different, (as a company should usually store less data on former employees than their employees). However, in practice answers did not differ significantly and the same data categories were chosen twice.</p>

<p class="wp-block-paragraph">We started considering how we could improve the question of retention periods and deletion requirements in personnel management.</p>
<p><strong></strong></p>								</div>
				<div class="elementor-element elementor-element-6c255a1 elementor-widget elementor-widget-text-editor" data-id="6c255a1" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">What have we changed?</p>
								</div>
				<div class="elementor-element elementor-element-0ae147f elementor-widget elementor-widget-text-editor" data-id="0ae147f" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p><strong></strong></p>
<p class="wp-block-paragraph">We have replaced the questions about data categories for former employees, questions about retention periods and questions about the implementation of deletion requirements with new, clearly defined questions.</p>

<p class="wp-block-paragraph">We now focus on two areas:</p>

<p class="wp-block-paragraph"><em>Which data is continuously deleted <span style="text-decoration: underline;">during</span> the employment relationship?</em></p>

<p class="wp-block-paragraph">and</p>

<p class="wp-block-paragraph"><em>What data is deleted <span style="text-decoration: underline;">after the end</span> of the employment relationship?</em></p>

<p class="wp-block-paragraph">Here you can specify, as an example, the different types of data and documents that are subject to a statutory deletion period.</p>
<p><strong></strong></p>								</div>
				<div class="elementor-element elementor-element-a8ee990 elementor-widget elementor-widget-text-editor" data-id="a8ee990" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">Transfer of previous content</p>
								</div>
				<div class="elementor-element elementor-element-616827a elementor-widget elementor-widget-text-editor" data-id="616827a" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									<p><strong></strong></p>
<p class="wp-block-paragraph">We have automatically transferred the content from the previous questions to the new questions (PHR-300 &amp; PHR-305), where technically possible and appropriate. If content has been transferred, the questions have been given the status ‘changed’ (blue).</p>

<p class="wp-block-paragraph">The new questions now cover the content in much more detail: please take a look and add any information where necessary.</p>

<p class="wp-block-paragraph">As always, we welcome your feedback!</p>
<p><strong></strong></p>								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cooperation with external parties is now easier to document</title>
		<link>https://foxondo.com/en/cooperation-with-external-parties-is-now-easier/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Fri, 14 Nov 2025 14:18:24 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28423</guid>

					<description><![CDATA[In foxondo, we have combined two questions in the processes relating to external access options and cooperation with other organizations. This makes documenting cooperation with external parties easier and clearer for you – and eliminates redundant information. Here you can find out what has changed and why this is beneficial for your documentation.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28423" class="elementor elementor-28423">
				<div class="elementor-element elementor-element-620bce9a e-flex e-con-boxed e-con e-parent" data-id="620bce9a" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-33023c49 elementor-widget elementor-widget-text-editor" data-id="33023c49" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">Why was this change made?</p>
								</div>
				<div class="elementor-element elementor-element-d243ec7 elementor-widget elementor-widget-text-editor" data-id="d243ec7" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">In the previous structure, the same information was required in more than one questions – for example, which external bodies have access to data and which external parties are involved in process. This occasionally led to similar answers and overlap.</p>

<p class="wp-block-paragraph">By combining the two questions, we have standardized and simplified this area. Now you will provide all relevant information on cooperation with other organizations in one question on<strong> ‘</strong>Cooperation with external parties’ (PG-360 | PHR-360).</p>
								</div>
				<div class="elementor-element elementor-element-1022d72 elementor-widget elementor-widget-text-editor" data-id="1022d72" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">What exactly is changing?</p>
								</div>
				<div class="elementor-element elementor-element-1fd4427 elementor-widget elementor-widget-text-editor" data-id="1fd4427" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">We have removed the previous question ‘External access possibilities’ and incorporated its content into the question on ‘Cooperation with external parties’. You will find any previous content there and, if applicable, in the applicable follow-up questions.</p>

<p class="wp-block-paragraph">This allows you to record the following in one place:</p>

<ul class="wp-block-list">
<li>Whether data is processed by others on your behalf (commissioned data processing),</li>

<li>Whether a joint controllership exists, and</li>

<li>Which other external parties are involved.</li>
</ul>

<p class="wp-block-paragraph">You can now see at a glance who is involved in the processing, without having to enter the information twice<strong>.</strong></p>
								</div>
				<div class="elementor-element elementor-element-d03a268 elementor-widget elementor-widget-text-editor" data-id="d03a268" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">What should you do now?</p>
								</div>
				<div class="elementor-element elementor-element-9a08f2d elementor-widget elementor-widget-text-editor" data-id="9a08f2d" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">The good news is most users do not need to do anything; we have transferred the information for you.</p>

<p class="wp-block-paragraph">We simply recommend taking a quick look at the merged question (PG-360 | PHR-360) and any applicable follow-up questions to ensure that all information has been transferred correctly and to add or clarify it if necessary.</p>

<p class="wp-block-paragraph">This adjustment makes foxondo even easier to use – without any loss of information, but with greater clarity and efficiency in your documentation.</p>
								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New question in the module “Processes”</title>
		<link>https://foxondo.com/en/new-question-in-the-module-processes/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Thu, 06 Nov 2025 14:17:30 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28420</guid>

					<description><![CDATA[There is a new question regarding protection of data: Whether the technical and organizational measures (TOMs) taken are suited to protect the personal data in the process adequately. The new question replaces previous questions on additional TOMs and pseudonymization. Of course, we have already transferred the content of these questions for you. ]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28420" class="elementor elementor-28420">
				<div class="elementor-element elementor-element-4e81fee6 e-flex e-con-boxed e-con e-parent" data-id="4e81fee6" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-43dba55c elementor-widget elementor-widget-text-editor" data-id="43dba55c" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">The <strong>general measures applicable within the company</strong> for the protection of personal data are documented in the <strong>Data Security Module (TOMs)</strong>.</p>

<p class="wp-block-paragraph">Previously, foxondo had a question in each process on whether “only” the information in the data security module applied, or if additional measures had been implemented to protect the personal data.</p>

<p class="wp-block-paragraph">Additionally, each process had a question about the pseudonymization of data.</p>

<p class="wp-block-paragraph">The <strong>new question</strong> combines this information and directly asks: Are the <strong>existing protective measures appropriate for the level of protection</strong> which the personal data in the specific process requires?<br />For example, the more sensitive the data processed is, the higher the protection requirements are.</p>

<p class="wp-block-paragraph">In the new question, you can <strong>document directly in the text field</strong> whether there are any additional measures – and whether <strong>the measures overall are appropriate</strong>, considering the protection requirements the personal data requires.</p>
								</div>
				<div class="elementor-element elementor-element-007fbe7 elementor-widget elementor-widget-text-editor" data-id="007fbe7" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-heading">What does this mean for working in foxondo?</p>
								</div>
				<div class="elementor-element elementor-element-1060b76 elementor-widget elementor-widget-text-editor" data-id="1060b76" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<ul class="wp-block-list">
<li>Any information documented in the pervious questions has been moved to the new question. Its status is now “changed” (blue).</li>

<li>If the two questions have not yet been answered, the new question is still ‘not yet answered’ (grey).</li>
</ul>

<p class="wp-block-paragraph">Have a look at foxondo when you get the chance: you know your own processes best and our best guess is you can answer the new question with ease.</p>
								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Update for processors</title>
		<link>https://foxondo.com/en/update-for-processors/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Thu, 11 Sep 2025 13:15:00 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28414</guid>

					<description><![CDATA[Is your company a data processor, i.e. does it provide services on behalf of other companies? In addition to documenting your own internal processes, you must also document the processes you provide to other companies, insofar as personal data is processed. ]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28414" class="elementor elementor-28414">
				<div class="elementor-element elementor-element-e6bd9e5 e-flex e-con-boxed e-con e-parent" data-id="e6bd9e5" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-7c7b6125 elementor-widget elementor-widget-text-editor" data-id="7c7b6125" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">If you are familiar with this topic, you have probably already documented the <strong>services you provide as a processor</strong> in a clear and orderly manner. These could be found in foxondo under the module ‘Contractual agreements’.</p>



<p class="wp-block-paragraph">We have now moved them to the <strong>top navigation level</strong>, so you need fewer clicks to get there.</p>



<p class="wp-block-paragraph">And if you are only realizing now that that you may be a data processor and have not yet documented these processes, then this is a good opportunity to do so.</p>



<p class="wp-block-paragraph">By the way: In the <a href="https://www.cnil.fr/sites/default/files/atoms/files/gdpr_guide-for-processors_en.pdf" target="_blank" rel="noreferrer noopener nofollow">CNIL’s guide</a> for processors, the obligation to maintain a record of the clients and to describe the processing carried out on their behalf is one of the first obligations mentioned.</p>



<p class="wp-block-paragraph">So it&#8217;s best to take care of this before anyone asks – fortunately, foxondo makes it easy and requires little effort.</p>



<p class="wp-block-paragraph"></p>
								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Will the EU-U.S. Data Privacy Framework soon be cancelled?</title>
		<link>https://foxondo.com/en/will-the-eu-u-s-data-privacy-framework-soon-be-cancelled/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Fri, 14 Mar 2025 14:00:00 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28380</guid>

					<description><![CDATA[The Trans-Atlantic Data Privacy Framework (TADPF) is a legal basis for data transfers to the USA. US President Trump is currently having numerous executive orders from his predecessor reviewed, including those on which the EU-U.S. Data Privacy Framework (TADPF) is largely based. What should you do now?]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28380" class="elementor elementor-28380">
				<div class="elementor-element elementor-element-20f205d3 e-flex e-con-boxed e-con e-parent" data-id="20f205d3" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-2f2af076 elementor-widget elementor-widget-text-editor" data-id="2f2af076" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<p class="wp-block-paragraph">Transatlantic data protection may be facing a new challenge: under US President Trump, the existing legal framework is being weakened rather than strengthened. This can be seen, among other things, from the fact that he has initiated a review of executive orders issued by his predecessor in office and has dismissed members of a supervisory body that is jointly responsible for compliance with the TADPF.</p>



<h2 class="wp-block-heading">What does it mean if the TADPF is cancelled as a legal basis?</h2>



<p class="wp-block-paragraph">To date, there are two main ways of transferring personal data to the USA in a legally compliant manner:</p>



<ul class="wp-block-list">
<li><strong>Conclusion of EU standard contractual clauses (SCC)</strong>: A tried and tested method of agreeing an appropriate level of data protection between contractual partners.</li>



<li><strong>Self-certification in accordance with the TADPF</strong>: Data exchange with US companies that declare themselves to be compliant with EU data protection standards also fulfils the requirements.</li>
</ul>



<p class="wp-block-paragraph">Should the TADPF become invalid, all data transfers based on it would be unlawful (as was already the case with its predecessors Privacy Shield and Safe Harbour). This means that companies would then have to act quickly in order to remain GDPR-compliant.</p>



<p class="wp-block-paragraph">It is unclear how likely this case is. However, companies could already consider the possible consequences and prepare alternative solutions.</p>



<h2 class="wp-block-heading">How can well-maintained data protection documentation support you in this?</h2>



<p class="wp-block-paragraph">With foxondo you can prepare this case quickly and efficiently:</p>



<p class="wp-block-paragraph"><strong>1. Identification of affected contracts</strong></p>



<p class="wp-block-paragraph">By filtering for the tags ‘third country’ + ‘legal basis’, you can easily find the relevant places in foxondo and thus identify those data processing operations in your documentation that are based on the TADPF.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="975" height="378" src="https://neu.foxondo.com/wp-content/uploads/TADPF-Frage_EN.png" alt="TADPF Frage EN" class="wp-image-28381" srcset="https://foxondo.com/wp-content/uploads/TADPF-Frage_EN.png 975w, https://foxondo.com/wp-content/uploads/TADPF-Frage_EN-300x116.png 300w, https://foxondo.com/wp-content/uploads/TADPF-Frage_EN-150x58.png 150w, https://foxondo.com/wp-content/uploads/TADPF-Frage_EN-768x298.png 768w, https://foxondo.com/wp-content/uploads/TADPF-Frage_EN-710x275.png 710w" sizes="(max-width: 975px) 100vw, 975px" /></figure>



<p class="wp-block-paragraph">You could, for example, mark these questions with the status ‘in progress’ or ‘action required’ and enter a comment that a changeover to SCCs is being examined.</p>



<p class="wp-block-paragraph"><strong>2. Checking and adapting contractual bases</strong></p>



<p class="wp-block-paragraph">Check whether you can conclude EU standard contractual clauses with your service providers.</p>



<p class="wp-block-paragraph">Important: Do not forget to document this change in foxondo accordingly.</p>



<p class="wp-block-paragraph"><strong>3. Transfer Impact Assessment (TIA)</strong></p>



<p class="wp-block-paragraph">If a changeover to SCCs is possible, the Transfer Impact Assessment (TIA), in which the risks of data transfers to the USA are to be assessed, must be recreated. This also applies if the TADPF is cancelled.</p>



<p class="wp-block-paragraph">The best way to do this is to contact your data protection officer or get in touch with us: we will be happy to support you.</p>



<h3 class="wp-block-heading">Is there another alternative?</h3>



<p class="wp-block-paragraph">If a change of service provider is an option for you, it is best to choose a provider from the EU. You can find an overview of alternatives for digital services and cloud products here, for example: <a href="https://european-alternatives.eu/de" target="_blank" rel="noreferrer noopener nofollow">https://european-alternatives.eu/de</a></p>



<p class="wp-block-paragraph"><strong>Do you have any questions?</strong><br>Then please get in touch with us at <a href="mailto:info@foxondo.com" target="_blank" rel="noreferrer noopener">info@foxondo.com</a>.</p>
								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Legal basis according to GDPR: Concretisation in foxondo</title>
		<link>https://foxondo.com/en/legal-basis-according-to-gdpr/</link>
		
		<dc:creator><![CDATA[Nora]]></dc:creator>
		<pubDate>Tue, 18 Feb 2025 13:58:11 +0000</pubDate>
				<category><![CDATA[Legal]]></category>
		<guid isPermaLink="false">https://neu.foxondo.com/?p=28374</guid>

					<description><![CDATA[When are you allowed to process personal data? ONLY when you have a specific legal basis which allows it. Otherwise, never.]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="28374" class="elementor elementor-28374">
				<div class="elementor-element elementor-element-5ada1126 e-flex e-con-boxed e-con e-parent" data-id="5ada1126" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-228aea36 elementor-widget elementor-widget-text-editor" data-id="228aea36" data-element_type="widget" data-e-type="widget" data-settings="{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}" data-widget_type="text-editor.default">
									
<h2 class="wp-block-heading">Improvements to the legal basis question in foxondo</h2>

<p class="wp-block-paragraph">We have improved foxondo questions for you! In the data protection context, the question about the legal basis for processing personal data can be answered with even more precision.</p>

<p class="wp-block-paragraph">To make it easier for you to understand why we did this, we would like to take a closer look at the topic of legal basis here.</p>

<h3 class="wp-block-heading">Ground rule Nr. 1: Nothing happens without Art. 6 of the GDPR!</h3>

<p class="wp-block-paragraph">If you want to process personal data, you <strong>absolutely must</strong> have a legal basis from <a href="https://gdpr.foxondo.com/#art6" target="_blank" rel="noreferrer noopener">Art. 6 GDPR</a> for each process. These are:</p>

<ul class="wp-block-list">
<li>Consent from the data subject</li>

<li>Performance of a contract or pre-contractual measures to which the data subject is party</li>

<li>Compliance with legal obligations (e.g. based on a law, regulation)</li>

<li>Protection of the data subject’s vital interests</li>

<li>Public interest or the exercise of official authority</li>

<li>Legitimate interests of the controller or a third party (after a legitimate interest assessment)</li>
</ul>

<h3 class="wp-block-heading">Do you process sensitive data?<br />Then Article 9 GDPR is also relevant!</h3>

<p class="wp-block-paragraph">Are you processing special categories of personal data such as health data or trade union membership?</p>

<p class="wp-block-paragraph">Then, <strong>in addition</strong> to a legal basis from Article 6 of the GDPR, you also need a legal basis from <a href="https://gdpr.foxondo.com/#art9" target="_blank" rel="noreferrer noopener">Article 9 GDPR</a>. This might be:</p>

<ul class="wp-block-list">
<li>Regulations in the field of employment and social security and social protection law</li>

<li>Processing of data which the data subject has manifestly made public</li>

<li>Processing data for the establishment, exercise, or defense of legal claims</li>

<li>Processing data for the purposes of preventative or occupational medicine</li>
</ul>

<h3 class="wp-block-heading">Do you process data related to criminal convictions or offences?<br />Art. 10 GDPR sets strict limits!</h3>

<p class="wp-block-paragraph">Do you want to process data on criminal convictions or offenses? In this scenario as well, Art. 6 GDPR alone is not sufficient. You need an <strong>additional</strong> special legal basis (in particular from national law). Without this, the processing is not permitted!</p>

<p class="wp-block-paragraph"><strong>Here is an example:</strong> In the application process, a company wants to check the criminal records of applicants. Even if an employer may have a legitimate interest in hiring someone with no criminal record, this is generally not permissible.</p>

<p class="wp-block-paragraph">But there are exceptions to this: depending on the specific area of responsibility, questions about criminal records relating to property (e.g. in the financial sector), politics (e.g. in the area of the protection of the constitution) or traffic violations (as in the case of professional drivers) may be asked.</p>

<h2 class="wp-block-heading">And what have we improved in foxondo?</h2>

<p class="wp-block-paragraph">Where Art. 6, 9 and <a href="https://gdpr.foxondo.com/#art10" target="_blank" rel="noreferrer noopener">10 GDPR</a> were previously summarized into one question in foxondo there is now an individual question per relevant GDPR article.</p>

<p class="wp-block-paragraph">The European Court of Justice has clarified that the legal bases must be applied all together rather than on or the other. The new structure takes this into account, ensuring that the company will always document a legal basis as per Art. 6 GDPR and can then apply the other legal bases where applicable.</p>

<p class="wp-block-paragraph">Of course, you will be guided through this topic as usual without needing to know all behind-the-scenes details.</p>

<h3 class="wp-block-heading">How does this affect your previous documentation?</h3>

<p class="wp-block-paragraph">Don&#8217;t worry, we have automatically restructured the answers you have already provided! Nothing has been lost.</p>

<p class="wp-block-paragraph">However, if you had previously only documented legal bases as per Art. 9 or 10, you will now notice that the legal basis per Art. 6 is still missing for this processing.</p>

<p class="wp-block-paragraph"><strong>Therefore, we kindly ask you to</strong> check the legal basis for your processing activities or have your DPO check them.</p>

<p class="wp-block-paragraph"><strong>Tip:</strong> The quickest way to find the questions about legal bases in foxondo is to filter for the tag “legal basis”.</p>
								</div>
					</div>
				</div>
				</div>
		]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
