General Data Protection Regulation (GDPR)

Enable-IT General Data Protection Regulation (GDPR) Privacy Policy

Enable-IT respects your privacy. The General Data Protection Regulation (GDPR) is a sweeping new European Union (EU) privacy law that comes into effect on May 25, 2018. The GDPR harmonizes data privacy laws across the EU and mandates how companies collect, store, delete, modify and otherwise process personal data of EU citizens. It applies to any company that processes personal data of EU citizens, regardless of whether such company has any physical presence in the EU, or even whether it has any EU customers.

We realize that the exciting growth of the Internet and online services raise questions concerning the nature, use and confidentiality of information collected about consumers. Enable-IT does not share, disclose or sell any personally-identifiable information (such as your name, address, telephone number or e-mail address) collected online with other unaffiliated companies or organizations for non-Enable-IT marketing purposes. In the future, should Enable-IT decide to share such data with third parties for marketing, it will provide notification and the opportunity for its users to indicate whether they would prefer that the Company not provide such information about them to third parties. Because this information is a critical part of our business, it would be treated like our other assets in the context of a merger, sale or other corporate reorganization or legal proceeding.

At Enable-IT, our company mission is to help build a better internet. We believe that the protection of our customers’ and their end users’ data is fundamental to this mission.

Our Commitment

The team at Enable is fully committed to complying with the requirements of the GDPR. We understand that compliance with a new set of privacy laws can be challenging, and we are here to help with your GDPR compliance initiative by providing you with state of the art GDPR compliant services.
Our legal and policy experts have closely analyzed the requirements of the GDPR and continue to monitor new guidance on best practices for implementing the requirements of the GDPR. We have taken these new requirements to heart and made changes to our products, contracts and policies to ensure that we are fully in compliance with the GDPR before May 25, 2018. We are also dedicated to helping you, our customer, succeed in complying with the GDPR.

Enable-IT General Data Protection Regulation (GDPR) FAQs

1. What is GDPR?
The General Data Protection Regulation (GDPR) is a sweeping new EU law which mandates how companies can collect, store, delete, modify and otherwise process personal data of EU citizens. It applies to any company that processes personal data of EU citizens, regardless of whether it has any physical presence in the EU, or even whether it has any EU customers. Companies are also required to pass these obligations down to all of their vendors and suppliers who may also handle personal data of EU citizens anywhere in the world.

2. When will GDPR be the law?
GDPR comes into effect across the European Union on May 25, 2018. It’s a regulation (rather than a directive), meaning that it will instantly become law in all EU Member States on that date. Despite Brexit, the UK is committed to stay compliant with the GDPR.

3. What should I do to get started with the GDPR compliance process?
Inform: review your vendor list and get comfortable with how data flows across your business, what type of personal data you collect and who has access. If Enable-IT is one of your vendors, and you have determined that you need a DPA in place with Enable-IT, our GDPR compliant DPA is available for download and signature at the link above.

Assess: undertake a risk assessment within your business and identify any gaps that need to be filled in order to meet GDPR compliance.

Plan: get in touch with us to understand how our products can help meet your compliance needs, and develop an action plan that is mindful of the May 25, 2018 deadline.

Act: implement your GDPR compliance program and make GDPR compliance an ongoing discipline.

4. What is the definition of “personal data” under GDPR?
The first and most important thing to realize is that the EU concept of “personal data” is much, much broader than the U.S. concept of “PII”. Under EU law, personal data means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. It doesn’t have to be confidential or sensitive to qualify as personal data.

5. Do I Count as a Data Controller or Data Processor?
Enable-IT’s customers will typically act as the data controller for any personal data made available to Enable-IT in connection with their use of Enable-IT’s web optimization and security services. The data controller determines the purposes and means of processing personal data, while the data processor processes data on behalf of the data controller. Enable-IT, as the data processor, will process personal data on behalf of our customers in connection with providing the services to our customers.

6. What Types of Data does Enable-IT Process?
We are generally just a conduit for information controlled by others, it’s our customers and their users who control the content transmitted, routed, switched and cached across our network (e.g. images, written content, graphics etc.). Additionally, we may gather certain information regarding use of our customers’ websites, and process data submitted by our customers or which we are instructed to process on their behalf. While it’s not up to us which data we receive, it typically includes items such as contact information, IP addresses, security fingerprints, DNS log data, and website performance data derived from browser activity. We will process such data in order to provide the service to our customers and in accordance with applicable laws, including the GDPR.