GDPR Compliance Survey The information provided through this form is used for creating your profile in Teaching Tools catalog of edtech products. The catalog is a joint operation by Pålogga, Education Alliance Finland and GDPRiS. Please contact us if you have any questions related to this form. Please note that the link to this form is unique to you, and should not be shared. Product Name* Company Name* Company Registered Address General Contact Number Company Email DPO Contact Number Country Privacy Statement URL Cookie Policy URL Terms and Conditions for using the product URL Fair Use Policy URL Data Processing Agreement Are you the data controller, joint controller or data processor?Select valueControllerJoint ControllerProcessor Does your Data Processing Agreement satisfy the requirements of EU GDPR Art 28?Select valueYesNoPartlyDon't know Does your Privacy Statement in the public domain explain how you process data for this product? and does it fulfil the requirements of the EU GDPR (Art 12, 13, 14)Select valueYesNoPartlyDon't know Have you performed a data processing impact assessment (DPIA) as required according to GDPR Article 35?Select valueYes have undertaken DPIA, possibly on behalf of customersOffer helpNo What categories of personal data do you process?First name studentLast name studentAgeGradeName of className of teacherAnswers to quiz, maths etcFree text by studentDrawings by studentSound recording by studentPhoto/video by studentGPS location or other location dataLogin credentialsTechnical data (device, IP-Address, use of device etc)OtherDon't know Do you handle any of the following data (Art 9)?Racial or ethnic originPolitical opinionsReligious or philosophical beliefsTrade union membershipGenetic dataBiometric data (where used for identification purposes)Health dataData concerning a persons sex lifeData concerning a persons sexual orientationNone of the above Do you delete data promptly after it is no longer needed or else as instructed by the data controller?Select valueYesNo In order to provide the service, do you only process personal data which is strictly needed (minimisation of personal data)?Select valueYesNoPartlyDon't know Is the data in your care encrypted (at rest and in transit)?Select valueYesNoPartlyDon't know Which lawful basis for processing is your service design based on?Select valueArt 6(1) a ConsentArt 6(1) b ContractArt 6(1) c Legal ObligationArt 6(1) d Vital InterestArt 6(1) e Legitimate InterestArt 6(1) f Public TaskCan't say Do you and/or the controller allow the data subjects to exercise their rights, eg. to access their personal data, to rectify or delete their data etc. in an easy way?Select valueYesNoPartlyDon't know Do you have measures in place to limit who in your organisation has access to the data?Select valueYesNoPartlyDon't know Have you implemented privacy by design in the service as required by GDPR Article 25?Select valueYesNoPartlyDon't know Do you process the personal data for other purposes, such as advertising, than providing the service for studentsSelect valueYesNoYes, but transparently and in a limited wayDon't know Does any processing happen outside of the EEA or other countries with an adequacy decision? (storage or transfers)Select valueYesNoDon't know If you are located outside the EEA, do you have a representative in the EEA? Select valueYesNoDon't know Do all your sub-processors ensure the same level of protection for processing personal data as you do? Select valueYesNoDon't know Have you undertaken Transfer Impact Assessments (aka Transfer Risk Assessments) for any transfers to outside of the EEA? Select valueDoes not applyYesNoPartly Single Choice*By submitting your answers, you will agree to be contacted by the project partners for clarifications and feedback before publishing the results in the Teaching Tools catalog.SubmitReset