GDPR Compliance Policy
Policy Owner: Senior Systems Architect
Effective Date: February 1, 2025
Application
This policy applies to all employees, contractors, and vendors doing business with wowl.io and others who access European Union (EU) and European Economic Area (EEA) data subject information (“personal data”) in connection with wowl.io’s operating activities.
Policy
wowl.io is committed to protecting the security, confidentiality, and privacy of its information resources, including EU and EEA personal data, in accordance with the General Data Protection Regulation (GDPR).
Key principles include:
1. Legal Basis: Personal data will only be processed when legally justified.
2. Data Security: Ensuring confidentiality, integrity, and security of personal data.
3. Responsible Use: Data is only used for authorized purposes.
Roles and Responsibilities
Policy Adoption
wowl.io, in collaboration with stakeholders, adopts GDPR Policies that define safeguards and ensure compliance. These include technical, physical, and administrative controls.
Responsible Persons
Overall Oversight: Jonathan Chuang, Senior Systems Architect (jonathan@wowl.io)
Data Protection Officer (DPO): Oversees daily GDPR compliance, provides guidance, and acts as the contact for supervisory authorities.
Article 27 Representative
• EU Representative: Isaac Fung, Director of Global Strategy (isaac@wowl.io, UK)
• UK Representative: Isaac Fung, Director of Global Strategy
Implementation
Data Protection
• Legal basis required for all processing.
• Encryption for data storage and transmission.
• Secure disposal of paper and electronic media.
Training
Personnel will receive training on GDPR responsibilities, including handling data subject access requests (DSAR).
Third-Party Data Transmission
Data transmission to third parties requires a fully executed Data Protection Addendum.
Breach Notification
Reportable incidents will follow GDPR notification requirements and wowl.io’s Incident Response Policy.
Data Subject Access Requests (DSAR)
Data subjects have rights under GDPR, including access, rectification, erasure, and more. Requests can be made via:
• Email: privacy@wowl.io
Requests will be logged, and responses provided within 25 days.
Enforcement
Failure to comply may result in disciplinary action. Report violations to privacy@wowl.io.
Version History
• Version 1.0 (February 1, 2025): Initial Policy by Jonathan Chuang