Technical and organizational security measures (TOM)

Last update: 21.06.2018

I. Confidentiality

  • Physical access control of the Supplier
    • wservices does not have physical access to servers (computers) which are located in a data center.
    • The disks of all office computers, laptops and flash drives which contains Personal Data are encrypted.
  • Physical access control of Sub-processors
    • Physical entry control system with log
    • Documented distribution of keys to employees
    • Policies for accompanying and designating guests in the building
    • Data center staff present 24/7
    • Video monitoring at entrances and exits
    • Security door interlocking systems and server rooms
  • Electronic access control
    • E-Mail-Account and SSH user passwords are not known to the Supplier.
    • The Customer's password for the administration interface is determined by the Customer himself; the password must comply with predefined guidelines.
  • Internal access control
    • The Supplier shall prevent unauthorized access by:
      • Applying security updates regularly
      • By using state of the art technology
      • A revision-proof, compulsory process for allocating authorization for supplier employees
    • The Customer is responsible for transferred data/software with regard to security and updates.
  • Isolation control
    • For the Supplier's internal administration systems
      • Data shall be physically or logically isolated and saved separately from other data.
      • Backups of data shall also be performed using a similar system of physical or logical isolation.
  • Pseudonymization
    • The Customer is responsible for pseudonymization.

II. Integrity (Art. 32 Para.1 Clause b GDPR)

  • Data transfer control
    • All employees are trained in accordance with Art. 32 Para. 4 GDPR and are obliged to ensure that personal data is handled in accordance with data protection regulations.
    • Deletion of data in accordance with data protection regulations after termination of the contract.
    • Encrypted data transmission options are provided
  • Data entry control
    • For the Supplier's administration systems and for the web hosting services, data is entered or collected by the Customer.

III. Availability and Resilience (Art. 32 Para. 1 Clause b GDPR)

  • Availability control
    • Backup and recovery concept with daily backups of all relevant data depending upon the services booked by the Customer.
    • Professional employment of security programs (virus scanners, firewalls, encryption programs, spam filters)
    • Employment of disk mirroring on all relevant servers
    • Monitoring of all relevant servers
    • Employment of an uninterruptible power supply system or emergency power supply system
  • Rapid recovery measures (Art. 32 Para. 1 Clause c GDPR)
    • For all internal systems, there is a defined escalation chain which specifies who is to be informed in the event of an error in order to restore the system as quickly as possible.