GDPR Compliance
How complybox.eu ensures the security and privacy of personal data in accordance with the General Data Protection Regulation.
1. Data Protection by Design and by Default
The General Data Protection Regulation (GDPR) mandates that systems processing personal data must be designed with privacy at their core. complybox.eu embraces "Privacy by Design" through strict architectural decisions. Our end-to-end encryption (E2EE) guarantees that neither complybox.eu nor any unauthorized third party can access the contents of whistleblowing reports.
2. Data Controller vs. Data Processor
Under the GDPR framework:
- Data Controller: The organization (our client) using complybox.eu to receive whistleblowing reports acts as the Data Controller. They determine the purposes and means of processing personal data within the reports.
- Data Processor: complybox.eu acts as the Data Processor. We provide the technical infrastructure and process the encrypted data strictly on behalf of and according to the instructions of the Data Controller.
3. Encryption and Anonymization
When a whistleblower submits a report, the data is encrypted directly in their browser using a public key provided by the organization. The data remains encrypted while in transit and at rest on our servers. Only the designated administrators within the organization possess the corresponding private key required to decrypt and read the report.
Furthermore, we do not log IP addresses, browser fingerprints, or metadata that could potentially identify an anonymous whistleblower.
4. Data Minimization and Retention
complybox.eu strictly adheres to the principle of data minimization. We only collect the technical data necessary to provide the service. Organizations have full control over data retention periods and can securely delete reports and associated personal data once a case is closed, in alignment with their national legislation and internal policies.
5. Sub-processors and EU Hosting
All data processed by complybox.eu is hosted on highly secure, ISO 27001-certified servers located exclusively within the European Union. We do not transfer personal data related to whistleblowing reports outside the European Economic Area (EEA), ensuring compliance with Schrems II and stringent EU data sovereignty requirements.
6. Data Subject Rights
We provide the necessary tools for Data Controllers to respond to Data Subject Access Requests (DSARs). If a whistleblower or a person named in a report wishes to exercise their rights (e.g., right to access, right to be forgotten), the organization can seamlessly manage these requests using our platform's case management tools.