Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RGPD] inform that UTC is a subcontractor AND is responsible of Actualités-UTC #75

Open
r0one opened this issue Aug 24, 2019 · 4 comments
Assignees

Comments

@r0one
Copy link
Contributor

r0one commented Aug 24, 2019

Currently, the Conditions Générales d'Utilisation point out that the UTC is responsible of the DB. If we want to stick to that, we must sign an agreement with the UTC where we put ourselves as a processor (sous-traitant) in the meaning of the GDPR.

Another possibility would be to be directly responsible of the treatment, but we should update the CGU, and I think it's more dangerous ^^

And anyways, we must also indicate that some treatments are done by Actualités UTC, which has its own database (but these treatments are done internally to the Environnement Numérique de Travail and the terms and conditions are already documented in the Règlement Intérieur).

@r0one
Copy link
Contributor Author

r0one commented Aug 24, 2019

@NastuzziSamy @MercierCorentin if you agree with me, could one of you contact the DSI in order to get the declaration number?

@r0one
Copy link
Contributor Author

r0one commented Sep 17, 2020

Hello, vu que ceci et cela traîne toujours, je me dis que je devrais écrire un peu de texte.

Dans les faits, l'UTC s'occupe des actualités UTC, et le SiMDE utilise des infras de l'UTC pour faire les autres traitements.
Je propose donc d'attribuer les responsabilités ainsi:

  • collecte et modération de réactions (commentaires et éventuels likes pour des màj ultérieures): UTC
  • le reste: SiMDE avec sous-traitant UTC

Il va aussi falloir être en mesure de tenir un registre.

@noeamiot @Cathaiste @cesar-richard je peux commencer à bosser ou vous avez des contre-indications?

@Cathaiste
Copy link

De mon côté et de mes faibles connaissances sur le sujet, y a pas de problème tu peux go ! Est-ce que tu sais si on avait finalement signé un accord avec l'UTC ou est-ce que c'est donc toujours à prévoir ?

@r0one
Copy link
Contributor Author

r0one commented Sep 19, 2020 via email

@r0one r0one self-assigned this Sep 28, 2020
@r0one r0one changed the title We must decide who's responsible of the app DB, and that person must make the CNIL declaration. [RGPD] inform that we have a subcontractor Oct 27, 2020
@r0one r0one changed the title [RGPD] inform that we have a subcontractor [RGPD] inform that UTC is a subcontractor AND is responsible of Actualités-UTC Oct 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants