Ensuring the compliance with GDPR standards | All for One Poland

Ensuring the compliance with GDPR standards

Offering of services and solutions from All for One Poland

Adapt your organization to GDPR (in Polish - RODO)

New EU regulations regarding the personal data processing, effective as of 25 May 2018, pose an organizational and technical challenge even for those entities that have been so far proficient with applicable laws.

All for One Poland offers a range of services and solutions that support the adaptation of an organization to GDPR (in Polish – RODO) and subsequent maintaining of that compliance with existing standards. These are both information security services and applications that can be used at each of the data processing and protection stages – from collection, through access management, use, storage, transfer, to erasure of data.

GDPR vs. IT systems

The EU regulation changes the approach to ensuring the security of personal data processing. In contrast to the current national requirements,  the selection of measures to ensure security will be the responsibility of a data processor. This means that it is necessary to carry out the process of risk analysis and assessment, and to build a risk management plan. These activities should be carried out from the point of view of the person whose data is processed, and as a result, solutions should be implemented to achieve the objectives of data protection. Processors must also be ready to meet functional requirements, such as the right to forget, strict control of access to data, encryption or pseudonymization of data. In the case of a breach of personal data protection, the data controller is obliged to immediately report this fact to the supervisory body.

Most data sets are processed in electronic form. Therefore, these requirements translate directly into the necessary functionalities of IT systems, which in many cases requires their adaptation – expansion, modification or addition of new elements of the IT infrastructure.

GDPR audit, risk analysis, pentests

In order for the modernization to be adequate to the needs of a particular organization, it is necessary to prepare a change project first. Based on its own expert competence, All for One Poland offers comprehensive support in adapting data controllers and processors to meet the requirements of GDPR (in Polish – RODO).

The first stage of the project is a gap analysis that provides answers to questions about the scope of the discrepancies between the current state and  required GDPR criteria that have to be met.

The next stages include a risk analysis and the resulting implementation of controls, adaptation of  processes and procedures (or development of new ones), as well as parallel designing and implementation of changes in IT systems.

The cyclical review of the IT environment security by an external auditor is an effective method of minimizing the risk of personal data leakage. It is a good practice to include such a requirement in the information security policy of each organization, with particular emphasis on the personal data processing area. All for One Poland has been supporting clients in ensuring information security in the organizational and technical area for many years by providing penetration testing services, among other things.

Adjustment of IT infrastructure

The guarantee that a particular user has access only to strictly defined IT systems at the appropriate level of permissions, combined with the forced complexity of passwords and the central repository is the basis for safe functioning of any extensive IT environment. All for One Poland recommends to its clients the best solutions, i.e. Thycotic Secret Server.

Encryption of data, especially that processed on mobile devices, significantly minimizes the risk of its physical theft. Comprehensive and centrally managed anti-virus and anti-malware protection prevents data leakage or unauthorized modification of data (also by crypto-lockers). All for One Poland implements server and workstation protection systems based i.a. on Intel Security (McAfee) products.

A complement to the protection of systems is network security – both where the Internet comes into play as well as in inter-branch connections and in the LAN. Intrusion prevention systems, protection against DDoS attacks, transmission encryption, application firewalls, anti-virus protection at the network level, web-filtering and other UTM functionalities, as well as authorization of access to the local network (wired and WiFi) and access to network resources based on user roles are only some of the options of data protection in the network. All for One Poland recommends the implementation and maintenance of network environments based on products such as FortiNet, Juniper Networks, Cisco, Checkpoint, DELL EMC, HPE, Extreme Networks.

According to the definition of GDPR (in Polish – RODO), even the storage of personal, also in the form of backup, is its processing. Some elements of the IT infrastructure may fail to meet the requirements of the Regulation and thus even make it impossible for the organization to achieve compliance with the law – one of the practical examples is the exercise of the “right to forget” when using tape drives for backup purposes in the organization. All for One Poland recommends modern backup and storage systems from leading manufacturers, i.e. DELL EMC, HPE, NetApp, IBM.

Security Operations Center offered by All for One in the “as a Service” model (SECaaS), built on the basis of a number of analytical and monitoring tools (e.g. Splunk Enterprise, agileSI, Nagios, Zabbix, Graylog) provides functions of proactive defense against external and internal cyberthreats. By centralizing, analyzing and correlating events from multiple sources, it is possible to react immediately to the first symptoms of potential data security incidents.

Anonymization of HR test data

How to anonymize data?

It is particularly urgent to ensure information security in non-production application systems. Test systems are usually fed with data similar to the data of a production system. “Production” personal data can be used in test systems only if it is properly secured. The method of securing personal data is anonymization or pseudonymization.

All for One HR Cloner for data anonymization in SAP HR

All for One HR Cloner allows you to minimize the risk associated with testing HR data in SAP systems, while providing a number of additional benefits, including saving time for administrators and users, speeding up tests and migration projects.

Write us Call us Send email

    1. Personal data is processed pursuant to Article 6 (1) (a) of the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016 – the General Data Protection Regulation
    2. The data controller is All for One Poland sp. z o.o. with its registered office in Złotniki, ul. Krzemowa 1 62-002 Suchy Las. Contact data of the Data Protection Supervisor: iod@all-for-one.com.
    3. Consent to data processing is voluntary, but necessary for contact. Consent may be withdrawn at any time without prejudice to the lawfulness of the processing carried out on the basis of consent prior to its withdrawal.
    4. The data will be processed for the purposes stated above and until this consent is withdrawn, and access to the data will be granted only to selected persons who are duly authorised to process it.
    5. Any person providing personal data shall have the right of access to and rectification, erasure, restriction of processing, the right to object to the processing and to the transfer of data, the right to restriction of processing and the right to object to the processing, the right to data transfer.
    6. Every person whose data is processed has the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).
    7. Personal data may be made available to other entities from the group that All for One Poland sp. z o.o. is part of – also located outside the European Economic Area, for marketing purposes. All for One Poland ensures that the data provided to these entities is properly secured, and the person whose data is processed has the right to obtain a copy of the data provided and information on the location of the data provision.

    +48 61 827 70 00

    The office is open
    Monday to Friday
    from 8am to 5pm

    General contact for the company

    Question about products and services

    Question about work and internships