FR

Events

Discover Visual planning 10

Contact

Have a question or project?
Our team is here to help.

Customer Stories & Case Studies

See how organizations improve scheduling, streamline operations, and gain better visibility across teams and workloads.

SNCF

Manage 12,000 employees with real time scheduling

Airbus

Centralize field operations across teams and sites

User Community

Connect, share and learn with the Visual Planning community

Exclusive Events

Webinars, workshops and community sessions

Knowledge Sharing

Best practices and operational feedback

Early Access

Preview upcoming features and product updates

Visual Planning Complying with the GDPR

The GDPR, or General Data Protection Regulation, must be implemented by May 25, 2018. It contains rules regarding the protection of natural persons in the processing of personal data and the free movement of such data.The full text […]

6 May 2018

}
Reading time 8 min
RGPD-logo

The GDPR, or General Data Protection Regulation, must be implemented by May 25, 2018. It contains rules regarding the protection of natural persons in the processing of personal data and the free movement of such data.
The full text of the GDPR: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32016R0679

WHY THE GDPR? REPLACING OUTDATED EU REGULATION

Currently, EU businesses comply with the Data Protection Directive. This European legislation on privacy and data protection dates to 1995. As a directive, it allowed for a margin of interpretation by each EU country to account for national specificities. As a result, privacy protection laws currently vary across EU countries, making management more difficult and complex for international businesses.

The GDPR aims to harmonize the collection and processing of personal data within the EU and strengthen its protection by considering the changes brought about by digital transformations in recent years, particularly the rise of cloud computing and social networks. With the GDPR coming into effect on May 25, 2018, all European countries must comply with the same privacy protection rules. The new GDPR is a regulation, meaning it is a binding legislative act that must be fully applied across the EU.

To enhance compliance with consent and information processing, the GDPR was reinforced in March 2024 with “Consent Mode V2.” The goal was to limit the impact of advertising campaigns and the processing of data by any third-party companies or services. For compliance purposes, it is necessary to delegate this to one of the cookie managers declared compliant by Google (list of cookie managers).

WHAT IS CONSIDERED “PERSONAL DATA” UNDER THE GPDR?

Personal data includes any information related to an identified or identifiable natural person. The following elements, among others, are considered personal data:

  • First and last name,
  • Phone number,
  • Home address,
  • Gender and nationality,
  • Bank details,
  • Medical information,
  • Any data related to personal interests or orientations,
  • An email address in the format: firstname.lastname@company.com,
  • Behaviour on a website,
  • Etc.

A specific category of data has been identified: so-called sensitive data. This includes, for example, medical information, data on a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or genetic and biometric data (e.g., fingerprints).

When using contact information (phone number or email), everything must be clearly outlined in the company's privacy policy. If such data is processed through third-party services, it must also be specified while ensuring the anonymization of user data.

HOW DOES STILOG COMPLIES WITH REQUIREMENTS OF THE GDPR?

These campaigns aim to inform users about product updates, events, or other relevant information. We have appointed a Data Protection Officer (DPO) to oversee our strategy and ensure GDPR compliance. You can contact them at any time: +33 1 47 29 99 69 – sales@stilog.com

His/Her Main Responsibilities Include:

  • Informing, advising, and supporting employees to ensure compliance with the European regulation and national laws on personal data protection.
  • Raising awareness among teams about data protection issues, whether concerning clients or employees.
  • Assisting data controllers in their responsibilities.
  • Overseeing internal audits related to data protection compliance.
  • Addressing questions and complaints regarding personal data protection.
  • Cooperating with the supervisory authority (in France, the CNIL) and acting as the main point of contact within the organization.

We have thoroughly identified all personal data in our possession and determined: the purpose of its retention, how it is processed, who has access to it, and its retention period, etc.

TRANSPARENCY

Personal data is processed lawfully, fairly, and transparently. This means that we inform our clients, partners, and prospects about the personal data we collect and how we intend to use it.

PURPOSE LIMITATION

We only collect personal data for specific, explicit, and legitimate purposes, and we inform our clients, partners, and prospects about these purposes. For example, we may collect your contact details to reach out to you regarding your Visual Planning implementation project, conduct satisfaction surveys, or keep you informed about the release of a new version.

Other examples are outlined on the "Privacy Policy" page and in the section "How Stilog I.S.T. Complies with GDPR Requirements."

DATA MINIMIZATION

We only collect data that is adequate, relevant, and limited to what is necessary for the intended purposes: we only ask for information required to process these purposes.

RETENTION PERIOD

Stilog I.S.T. retains personal data only for the period necessary to fulfil the processing purposes and in accordance with national legislation.

ACCURACY

Personal data must be accurate and kept up to date: you have the option to request modifications to your data at any time (01 47 29 99 69 – dpo@stilog.com).

DATA DELETION

You can request the deletion of your data at any time (01 47 29 99 69 – dpo@stilog.com). Your data is only retained for as long as necessary to fulfil the intended purpose.

SECURITY

We are required to implement organizational and technical security measures to protect your personal data.

For example: the databases where your data is stored have restricted access to a limited number of staff members, access to our premises is secure, all data we handle (whether under the scope of the GDPR or not) is regularly backed up, etc. Additionally, we have established a crisis management procedure that outlines the measures we take to ensure the security of your data and the actions we would take if that security were compromised.

ACCOUNTABILITY

To ensure that all measures have been implemented for the personal data we process to comply with the principles of the GDPR, we publish this document on our website, have drafted a crisis management procedure, updated our contractual templates, and modified our contact information collection forms on our website. We make all this information available to you at any time.
As part of any changes to or our GDPR policy, we commit to informing all our clients or anyone who may be impacted.

RECIPIENTS OF THE DATA

In line with our commitments to our clients, we implement enhanced measures to ensure the protection of personal data. These measures are designed to restrict access to data to the strict minimum, ensuring that only those who are expressly authorized and whose roles require it can access the data.

AS A VISUAL PLANNING USER: ARE YOU GDPR READY?

If you are using Visual Planning to store personal data from your clients, suppliers, or staff (for instance, you are using Visual Planning for contact management, store customer listings, manage service calls, project management, etc.), the GDPR applies to you as a “data controller”. This may be the case even if you are located outside the EU, but collect data from EU individuals.

The European Commission has published guidelines, explanations and examples for businesses on the GDPR. Most European countries have issued resources, guidelines and recommendations on how to comply:

  • A great 12-step PDF guide and full breakdown from the ICO in the UK
  • A summary PDF from the Data Protection Commissioner in Ireland
  • In France, CNIL’s 4 steps process to get started: https://www.cnil.fr/fr/rgpd-par-ou-commencer

Here are examples of steps that you may want to take to ensure compliance in your company:

1. Designate a Data Protection Officer (DPO) who will be in charge of supervising data privacy questions

2. Create a data processing registry:

a. Include a list of business activities that requires personal data to be processed

b. For each of those activities: assess what the final purpose is, which data are being collected, who is given access, and how long they need to be stored

3. Take the time to sort out existing data and confirm you only collect what is needed

4. Respect the rights of individuals

a. Inform them that you are collecting personal data

b. Make sure that they can easily exercise their rights

5. Secure your data by reviewing and implementing safeguards

In Visual Planning, here are simple best practices that you can follow:

- Make sure that you implement sufficient levels of security for passwords when accessing Visual Planning (you may customize the required complexity of user passwords in our Admin Center)

- Create a unique login for each user

- Obtain and track consent from your clients, suppliers, personnel… for their personal data to be stored in your planners (for instance, by creating specific headings in dimensions or forms to store consent)

- Ensure that you do not store personal data for individuals with which you have not perform any activity in several years: we recommend that you make use of filtering based on History options that exists in Visual Planning to identify such data.

- Review existing personal data headings for contacts, customers, suppliers, personnel… in your planner to make sure that they are all necessary for your business activity.

Download the full GDPR document

 

IF YOU HAVE QUESTIONS

Please feel free to reach out to us for any question related to the GDPR, or if you think you may need to modify an existing configuration of Visual Planning to comply.

By phone: Europe +33 (0)1 47 29 99 69 | United States +1 (855) 589-9800

By e-mail: sales@stilog.com or dpo@stilog.com

Recommended Articles

Categories

5

Project

26
5

Production

7
5

H.R.

18
5

Fleet Management

5
5

Field Service

15
5

C.R.M.

4
5

Construction

4

Free Guide

Download our complete project planning guide

Ready to get started ?

See our project management solution in action.

`

This method has transformed the way we manage projects. We've increased productivity by 30% in three months.

Marie Chevallier

Project Manager, TechCorp