Form cover
Page 1 of 1

Campus check - GDPR

Your Campus Name

Does the campus have set up a generic address for data protection: dpo@campus.extension / dpo@campus.42.tech?

A
B

Rights of data subjects

General: Does the campus have an internal policy for managing the rights of data subjects (right of access, deletion, etc.)?

A
B

Data deletion: In order to delete data outside of 42 tools when a request for data deletion is received from the intranet, does the campus use the webhook provided by 42 Central?

A
B

Security measures

Can the campus confirm that the security measures listed below, in particular, have been implemented:

Data retention periods

Does the campus have implemented a data retention policy?

A
B

Does the campus have established processes to comply with the retention periods defined in Article 9.2 concerning candidates/students data when necessary?

A
B

Subcontracting in the context of joint processings

Does the campus use third-party service providers/platforms in the context of joint processings activities?

A
B

Independent data processing

Does the campus inform the data subjects about how the data is processed for independent data processing (as defined in article 6.2. of the GDPR annex)?

A
B

Data breaches

Does the campus have a data breach register in place? (French reference here)

A
B

Have you been victim to a data breach involving joint processings data and activities?

A
B

Controls & reporting

Has the campus been controlled by a supervisory authority in relation to joint processing activities?

A
B

Has the campus communicated with a supervisory authority in relation to joint processings activities?

A
B

Has the campus been the subject of a complaint and/or report to a supervisory authority involving joint processings activities or likely to concern 42?

A
B