Overview
Jive is committed to helping our customers comply with the GDPR through privacy and security protections in our products and services.
This article details the product capabilities and enhancements implemented by Jive to comply with GDPR.
Information
On 25 May 2018, the General Data Protection Regulation (GDPR) took effect in the European Union (EU). The new regulation imposes broad new data privacy protections for EU individuals and applies to any company that collects or handles EU personal data, regardless of the company’s location.
Level 1
Addressing core infrastructure requirements around encryption, backups, and data retention.
KEY GDPR REQUIREMENT |
JIVE PRODUCT CAPABILITIES AND ENHANCEMENTS |
Encryption-at-rest of Personal Data |
CLOUD AND HOSTED COMMUNITIES
Amazon Web Services Cloud
|
Encryption-in-transit of Personal Data |
Jive already encrypts all traffic between cloud/hosted/on-premise servers and users’ web browsers, as well as between Jive servers and third party services/ software. |
Individual’s Right - Data Retention |
Jive customers can already remove data when necessary using the existing APIs or existing user interface. |
Data Backups |
Jive performs backups on the following schedule: daily for 7 days, weekly for 5 weeks, and monthly for 3 months. |
Privacy by Design |
Jive will update its development processes to include data privacy reviews during architecture, design, implementation, and testing. |
Data Mapping / Data Inventory |
As part of our privacy-by-design measures, Jive will internally document where personal data is used within different Jive components. |
Level 2
Addressing additional GDPR requirements through updates to existing APIs.
KEY GDPR REQUIREMENT |
JIVE PRODUCT CAPABILITIES AND ENHANCEMENTS |
Individual’s Right to Access and Review |
Jive provides an existing API to download a profile in JSON. |
Individual’s Right to Update Data |
Jive provides an existing API to update user profiles. Jive will update the existing API in the upcoming versions to handle certain fields that cannot be updated via the API today and can only be updated through the user interface (e.g., username). Furthermore, the existing API will leverage the data mapping of personal data to ensure that all subsystems properly reflect the changes to personal data. |
Individual’s Right - Data Portability |
Jive provides an existing API to download a user profile as well as any associated user content into a JSON format with additional links to any uploaded files. |
Individual’s Right - Commonly Used Format |
Jive uses JSON as a common format, which is standard across the software industry as well as human-readable. |
Individual’s Right to Erasure |
Jive provides an existing API to delete a user.
|
Individual’s Right - Consent |
Jive provides an API to allow an individual’s consent to be automated. |
Level 3
Addressing remaining GDPR product requirements through the user interface (UI) updates.
KEY GDPR REQUIREMENT |
JIVE PRODUCT CAPABILITIES & ENHANCEMENTS |
Consent to use Cookies |
Jive will create a new cookie banner to notify users that Jive uses cookies. |
Comments
0 comments
Article is closed for comments.