Is the process GDPR-compliant?
Yes, the Photo Collect process is GDPR-compliant. Processing is carried out exclusively on behalf of the customer, with clearly regulated responsibilities, documented instructions, strict TOMs, encrypted transmission, data minimization, pseudonymization, role and access control, logging, backup and deletion concept and regulated incident management. Data processing on behalf of the customer and sub-processors are contractually secured.