# Welcome to the World of # GDPR ๐ โThe thrilling adventure where data has rights, and lawyers have fun.โ Weโll explore GDPR and how QFieldCloudโs DPA makes sure your data behaves like a polite Swiss tourist โ tidy, on time, and respectful of local laws. --- # Warm-up: Letโs Talk Data ๐ค Before we dive into GDPR and DPAs, a few quick questions. --- # What is a data breach? ๐ต๏ธโโ๏ธ - โค๏ธ A hacker steals data - ๐ My password is on a Post-it stuck to my monitor - ๐ Someone loses a USB stick on the train --- # What does DPA stand for? ๐งฉ - โค๏ธ Data Protection Alliance - ๐ Data Processing Agreement - ๐ Double Pizza Agreement --- # What do you do when a data breach happens? โก - โค๏ธ Report it immediately - ๐ Take a deep breath first - ๐ Say nothing, maybe no one will notice --- # When ๐ฉ Hits the Fan ๐คฏ - Data breach is detected - Systems might be compromised - Customers may be affected - Clock starts ticking โ GDPR gives you 72h to act --- # The user perspective ๐ท ### Imagine you upload personal photos for a photo book - ๐๏ธ Concern 1: Data loss โ all photos are gone ๐ฑ - ๐ Concern 2: Unauthorized access โ someone sees very personal photos ๐ --- # What do I want as a user? ๐ฏ - ๐ก๏ธ Protection against loss and misuse - ๐ Information on where my data is stored - โ Certainty that my data is completely deleted if I request it --- # What is a DPA? ๐ค ### A Data Processing Agreement defines - ๐ค Who can do what with the data - โณ How long the data is stored - ๐ What happens to the data when the contract ends - ๐ Which security measures are mandatory --- # Origin of the DPA ๐ ### The Mailman and the โPostal Secretโ
--- # Legal Basis for the DPA? ๐ ### Based on government regulations - ๐ช๐บ EU: GDPR - ๐จ๐ญ Switzerland: revDSG (revised Swiss Data Protection Act) - ๐ฏ Goal: unified rules and clear responsibilities --- # GDPR in One Sentence ๐ ### Donโt be creepy with peopleโs data. --- # Personal Data: Itโs Not Just Names ๐งโ๐ป Sure, names and emails count. But so do GPS tracks, selfies, device IDsโฆ If it can point to you, GDPR wants a word. --- # Personal vs. Non-Personal Data? ๐ - ๐ณ Tree height measurements? - ๐ Tree height + โcollected by Bobโ? - ๐ Tree height + โcollected by Bob at his houseโ? --- # Assume Itโs Personal Data Anyway ๐ซ Itโs safer. Like always bringing a rain jacket in the Alps โ you might not need it, but when you do, you really do. Our DPA is built on this assumption: we process everything under GDPR-grade protections. --- # Retention: Not Forever ๐ฐ๏ธ GDPR says: Keep it only as long as needed. Our DPA says: When the partyโs over, we delete your data unless Swiss or EU law says otherwise. Plus: we certify that deletion to you โ pinky swear. --- # Notification Requirements for Data Breaches ๐ข - ๐ช๐บ EU GDPR: Notify supervisory authority within 72h (Art. 33 GDPR) - ๐จ๐ญ Switzerland (revFADP): No fixed limit โ report โas soon as possibleโ - ๐บ๐ธ USA: Depends on state, often 30 days or less - ๐ Organization-dependent: Internal policies or DPAs can set shorter deadlines than the law ๐ก Key takeaway: Law = minimum standard, but a DPA or internal policy can require stricter timelines. --- # OPENGIS.ch / QFieldCloudโs DPA Promise ๐ค - ๐จ๐ญ Swiss hosting in ISO 27001 datacenters - ๐ Access is controlled by roles & permissions - ๐ Subprocessors vetted & listed transparently - ๐๏ธ Delete data at contract end - ๐ ๏ธ Assist with GDPR rights and DPIAs - ๐จ Notify you of data breaches within 48h --- # 3 Takeaways ๐ก - ๐ก๏ธ We take data protection at QFC very seriously โ we can confidently show this to customers, especially for OnPrem requests - ๐ React quickly if a breach is found โ we have deadlines (48h) - ๐ Donโt panic โ take a breath, then contact the QFC team --- # Closing ๐ GDPR and a DPA are not just paperwork. Theyโre our safety net, our customer guarantee, and our trust promise. With QFieldCloud, youโre on the safe side of data protection.