On this page, you will find quick answers to the most frequently asked questions on how Mynewsdesk is handling the General Data Protection Regulation (GDPR) and related security topics.
1) Does our contract with Mynewsdesk comply with GDPR?
Yes. Our General Terms and Conditions are related to our Data Protection Terms (DPT), which in turn include Mynewsdesk’s Data Processing Agreement (DPA). This way our Data Processing Agreement (DPA) is incorporated into and forms part of the contract via our DPT. For further information in this context, you may also see our Privacy Policy and Security Policy.
2) In which way is the Data Controller responsibility split between the client and Mynewsdesk?
When uploading, downloading, storing or manually updating contact information within the Contacts feature of an account, the responsibility as Data Controller lies with the client, while Mynewsdesk acts as the Data Controller with regard to user accounts and follower accounts.
3) Who is responsible for the data that I upload in Contacts?
As our client, you are responsible that the data you upload or add to Contacts is being handled legitimately according to GDPR. You need to determine yourself which legal ground you apply, and define routines with regard to e.g. why and how you store and handle contact lists.
4) How is GDPR compliance being put in place?
All emails that are sent from Mynewsdesk to any of your contacts include a link to our Privacy Policy for Contacts, and there is also always a link for the contact to opt out from receiving emails from your newsroom. Furthermore, we recommend you to always have your lists updated, so that they do not include any contacts you are not using. Please see our Data Protection Terms (DPT) for more detailed information on the processing of personal data in the Contacts feature.
5) Who is responsible for contacts that are followers of my newsroom?
Mynewsdesk ensures that followers are being handled according to GDPR. Those who follow a newsroom always need to create a user account on Mynewsdesk, which means that they accept our Terms of Use, including the Mynewsdesk Privacy Policy and our Privacy Policy for Contacts.
6) Is relevant information shared with individuals at the time of direct data collection?
When signing up, the user is presented with our General Terms and Conditions and Privacy Policy that provides information about the purposes and legal bases for the data processing.
7) Are controls in place to ensure that collection of personal information is limited to the minimum necessary?
Yes. We have internal routines ensuring that processing of personal data is limited to specific purposes. Furthermore, we have defined routines to ensure that our subcontractors fulfill the GDPR requirements.
8) What is your policy on data transfer to external data controllers?
Routines for transferring personal data are established and documented. Transfers are only made where necessary for service delivery and under appropriate contractual and legal safeguards. More detailed specifications can be found in our Data Protection Terms (DPT).
9) In which countries are you processing personal data?
We are processing data within the EU/EEA and in some cases in the USA. For transfer of personal data to the USA, EU Standard Contractual Clauses (SCC) and a TIA (Transfer Impact Assessment) apply along with other supplementary measures of organizational or technical kind – see also our Data Protection Terms (DPT).
10) Which are your main data processing subcontractors?
Our principal subcontractors, administering our hosting and storing data from Mynewsdesk on their servers, are Hetzner Online GmbH and Amazon Web Services (AWS). These subcontractors are processing data within the EU. A complete and updated list of Mynewsdesk’s subcontractors can be requested from Mynewsdesk Support.
11) Can you supply information on which specific addresses your data is stored?
For security reasons, we provide region/country-level information rather than exact street addresses of data centers.
12) Is there physical and electronic protection for stored personal data? Do you use data encryption and how is your intrusion protection?
Security is implemented through a combination of Mynewsdesk’s controls and those of our hosting partners, including technical and organizational measures. For more detailed information, please see Mynewsdesk’s Security Policy.
13) Is there a process for data erasure?
As outlined in our Privacy Policy, we have defined a process to ensure that data is deleted when its further storage is not required anymore, or in case it has to be deleted for legal reasons.
14) Do you support removal of personal data upon request by the person concerned?
We have defined processes and routines in place for removal requests. All kinds of Data Subject’s Rights requests may be directed to Mynewsdesk by email as defined in our Privacy Policy or Privacy Policy for Contacts.
15) Are there backup copies of stored personal data, and do you have routines in place for deletion of those copies?
We are storing backup copies of our production database via our hosting partner, as described in our Security Policy, with routines for data deletion in place.
16) Is there a process for detecting and reporting security risks and incidents?
As depicted in Mynewsdesk’s Security Policy, we are conducting a partly automated, continuous identification, evaluation and follow-up in order to fix any security risks or incidents. Moreover, we have defined a routine for reporting to all persons concerned and the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) within 72 hours.
17) Can I have our Data Processing Agreement signed by Mynewsdesk?
Mynewsdesk does not sign individual agreements since we, being a SaaS Company, have elaborated a DPA (Data Processing Agreement) that is adjusted to our specific services.
Our Data Processing Agreement (DPA) forms part of our Data Protection Terms (DPT) which in turn are related to our General Terms and Conditions that were agreed upon original contract signature.
18) Who is the Data Controller and is there a Data Protection Officer?
NHST Media Group is the Data Controller with an appointed Data Protection Officer (DPO) for the corporate group and all affiliates. In addition, all businesses within the corporate group have their own Data Controller with delegated responsibility for their respective business. The Data Controller for Mynewsdesk is the CEO of Mynewsdesk.
19) Which personal data is being processed by Mynewsdesk?
For detailed information about the categories of personal data processed by Mynewsdesk, please see our Privacy Policy (2.1) with regard to user accounts, and our Privacy Policy for Contacts (2.3) with regard to contacts used in Mynewsdesk’s Contacts feature.