What are the core definitions under GDPR?
GDPR: General Data Protection Regulation (2016/679), an EU regulation harmonizing personal data processing rules across the EU/EEA, defining business requirements and individual rights.
Personal Data: Any information relating to a living person used to directly or indirectly identify them (e.g., names, photographs, phone numbers, email addresses, vehicle registration plates, and GPS coordinates).
Data Subject: The individual to whom the personal data relates.
Data Controller: The individual or organization determining the purposes and means of processing personal data.
Data Processor: The person or entity processing personal data on behalf of the data controller.
What is the scope and key compliance rules of GDPR?
Geographic Applicability: Applies to all companies processing personal data of EU/EEA residents, regardless of the company's physical location.
Article 5 Compliance Requirements: Personal data must be processed lawfully, fairly, and transparently; collected for specified, legitimate purposes; sufficient, relevant, and limited to what is necessary; accurate, kept up to date, and stored only as long as necessary; and processed securely.
What are the legal basis and consent requirements?
Processing Requirements: Companies must have a legal basis to process personal data.
Valid Legal Bases: Contractual necessity with the data subject, compliance with legal obligations, or explicit consent from the data subject.
Consent & Information: Data subjects must be informed about how data is processed, and consent must be obtained when legally required.
How does EasyPark handle security and internal policies?
Detailed Processing Info: Full descriptions of processing and legal grounds are located in the EasyPark Privacy Policy.
Security Measures: Implemented an Information Security Management System (ISMS) compliant with ISO 27001, appointed a Head of Information and IT Security, and established internal controls via the ISMS.
Third-Party Vendors: EasyPark has executed Data Processing Agreements (DPAs) with all vendors processing personal data on its behalf.
How do I submit privacy requests or contact the DPO?
Verification Policy: All privacy requests undergo a manual verification process before any account information is processed or released.
Data Protection Officer (DPO) Email:
dpo@easypark.net.
)