Berichte für den Datenschutz/en: Unterschied zwischen den Versionen
Weitere Optionen
Isan (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
Isan (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
Zeile 103: | Zeile 103: | ||
Here, you find the report for the data protection impact assessment that contains the relevant information for the consultation of the authority. | Here, you find the report for the data protection impact assessment that contains the relevant information for the consultation of the authority. | ||
<big><b>Generate consultation report for the authority:</b></big> | |||
<big><b>Generate | |||
<div class="mw-translate-fuzzy"> | <div class="mw-translate-fuzzy"> |
Version vom 10. August 2022, 06:54 Uhr
Under "Data Protection → Reports", it's possible to generate a number of reports for data protection.

To generate a report, first decide which type of report it should be. After choosing the desired type, add which data the report is to be generated for (e.g. processing activity or DPIA).
Formats:
Reports are available for download as PDF or DOCX files. To generate a report and download it, click on the pink button. Then, you can choose whether to download the report as PDF or DOCX.
Licenses:
If no valid license for HITGuard is available, this will be displayed in the footer of the report! To change this, an expert or administrator has to request/upload a license under "Administration → Licensing".
The following reports are offered in the data protection section of HITGuard:
Processing registers
Under "Data protection → Reports → Processing registers", it's possible to choose from a number of reports for processing activities.

=Own processing activity
Here, you find the report for one or more processing activities your company is responsible for.
Pre-filtered in the system are those most recent versions of processing activities with the status "Editing completed". This restriction can be adjusted as needed or removed with the "clear filter" button.
If a DPIA exists for a processing activity, its results will be added to the report.
Generate report for own processing activities:
To generate a report about your own processing activities, choose the desired processing activities here.
To generate and download the report, click the pink button.

Joint responsibilities
Here, you find the report for one or more processing activities that have more than one responsible party assigned to them. (Joint responsibility must be activated in the processing activity.)
Pre-filtered in the system are those most recent versions of processing activities with the status "Editing completed". This restriction can be adjusted as needed or removed with the "clear filter" button.
Generate reports for joint responsibilities:
To generate a report for joint responsibilities, choose the desired processing activities here.
In the report options, it's possible to configure the processing activities to be downloaded as a ZIP file.
To generate and download the report, click the pink button.

On behalf of others
Here, you find the report on processing activities carried out by your organization on behalf of others.
You can either generate a report containing processing activities performed by the selected organizational area, or you can generate a report for the external organization for which you perform the processing.
Note that the selection is limited to the last completed version of the respective processing activity.
Generate report for processing activities on behalf of others:
Organizational units that carry out processings:
- Here, you can choose the organizational units that handle processing activities on behalf of others.
- The report contains all current information on the processing activities the selected organizational units handle on behalf of others.
External responsible parties on whose behalf processing is carried out:
- Here, you can choose an external responsible party your organization performs processing activities for.
- The report contains all information for all processing activities that are performed for this responsible party.

External processors
Here, you find the report for processing activities that other companies perform on behalf of your organization.
Note that the selection is limited to the last completed version of the respective processing activity.
Generate report for external processors:
Here, choose the desired external processor. The report contains all information on processing activities they perform for your organization.
To generate and download the report, click the pink button.

DPIA
Under "Data protection → Reports → DPIA" you can choose whether to generate a report for the consultation of the authority or a general report on a data protection impact assessment.

Consultation of the authority
Here, you find the report for the data protection impact assessment that contains the relevant information for the consultation of the authority.
Generate consultation report for the authority:
Here, first select the desired data protection impact assessment. If the DPIA contains multiple PA-responsibilities, also choose the desired PA-responsibility.
In the report options, it's possible to configure the processing activities to be downloaded as a ZIP file.
To generate and download the report, click the pink button.
General report
Here, you find the general report about the data protection impact assessments.
Generate data protection impact assessment report:
Here, select the desired data protection impact assessment. The report contains all relevant information on the chosen DPIA.
In the report options, it's possible to configure the processing activities to be downloaded as a ZIP file.
To generate and download the report, click the pink button.

TOMs
Here, you find the report on the technical and organizational measures and controls.
By default, the report is generated for the general TOMs. The selection can also be limited to PA-responsibles (internal or external organizational units, e.g. clients) or to company or organization registers. PA-responsibles, company registers, and organization registers can be combined freely. Then, also the specific TOMs for those PAs are added into the report.
Specific TOMs are added for the latest completed versions of a processing activity. Not yet completed PAs are not taken into account.
Generate TOMs report:
To generate and download the report, click the pink button.
A list for the selection of PAs is added for additional configuration if the option "Specific TOMs" is activated.
Report options:
- Specific TOMs
- If this option is active, PA-responsibles, company registers, and organization registers can be selected. This adds specific TOMs in addition to the general TOMs for the selected PA-responsibilities.
- Only completed measures and active controls:
- If this option is active, only completed measures and active controls are added into the report. If it's deactivated, suspended or inactive controls as well as non-completed measures will be added.
- Description:
- If the descriptions of measures and controls is not needed in the report, they can be removed from the report with this option.

Data subject categories
Here, you find the report for data subject categories. This report can be used to issue information.
Caution: Only visible for experts in data protection!
Generate informative report:
Here, first select the desired data subject category. The report contains all information (e.g. time limit for erasure) for all processing activities is is part of. Therefore, it can be used to issue information to inquirers.
To generate and download the report, click the pink button.
