The EU General Data Protection Regulation (GDPR) comes into effect on May 25, 2018. PkgFlow is ready.
If you’re based in the EU or do business in the EU, yeah! GDPR has a long reach. If you have any EU personal data in your PkgFlow account, such as names, email addresses, ID numbers, or… anything personally identifiable, then GDPR applies. You are a Controller of personal data under GDPR, so you need to enter into GDPR-compliant data processing agreements with any online services and third party vendors you rely on, including PkgFlow. These agreements are commonly called a Data Processing Addendum, or DPA.
PkgFlow participates in the EU-US and Swiss-US Privacy Shield Framework to safeguard the transfer of personal data to the US, meeting the GDPR requirement for adequate data protection laws.
PkgFlow uses third party subprocessors, such as cloud computing providers and customer support software, to provide our services. We enter into GDPR-compliant data processing agreements with each subprocessor, and require the same of them. List of PkgFlow subprocessors.