1. Who is CIS – Certification & Information Security Services GmbH?
CIS – Certification & Information Security Services GmbH (briefly refered to CIS) is leading partner for system certifications, verifications and validations, assessments, trainings and individuals’ certifications (following also referred to as "CIS services"). The basis is formed by accreditations at BMDW (“Bundesministerium für Digitalisierung und Wirtschaftsstandort” - “Federal Ministry for Digital and Economic Affairs”).
Its key asset is its competence as a national market leader for information security management and IT service management for secure and increased business excellence. Thus CIS is an important driver and trendsetter for the economic site of Austria and for "securing your business".
2. Who is responsible for data processing, and whom can I contact?
CIS – Certification & Information Security Services GmbH
1010 Vienna, Austria
Tel.: (+43 1) 532 9890
Fax: (+43 1) 532 9890 89
3. What sources and data do we use?
When providing our services in the fields of system certification, verification and validation as well as individuals’ certification and training and further training, we process personal data that the customer (the party ordering the CIS service, including its contact person, or a person participating in a CIS service) makes available to us just as much as data that we acquire ourselves when providing the CIS services (e.g. in the course of an audit or an examination). As a rule, CIS cannot provide the desired services without this data.
Relevant personal data includes particulars (e.g. name, address and other contact data, day and place of birth), legitimization data, contract data (e.g. audit documentation, documentation of events, data about Certificates, accounting data, bank data).
4. What do we process your data for (purpose of data processing)? And on what legal basis?
The personal data that we acquire on the occasion of the CIS service will be processed for purposes of performing contracts according to the most important contractual documents and our Terms and Conditions as well as for the required documentation in conformity to the normative requirements (above all ISO/IEC 17021-1, ISO/IEC 17024, and possible additional requirements from models to be audited by order of the customer), for bookkeeping and accounting, for establishing and defending legal claims as well as for Customer Relationship Management, including drawing up of offers for further CIS services (e.g. re-certifications and add-on certifications or relevant trainings). The legal basis for these types of processing is formed by Art. 6 (1) lit. b of the General Data Protection Regulation (GDPR) (performance of a contract and steps prior to entering into a contract) (as far as the person concerned is a contracting party himself or herself) and Art. 6 (1) lit. f of the GDPR (legitimate interests in the provision of the agreed CIS services serving to increase business excellence, which are pursued by CIS and the customer) and Art. 9 (2) lit. f of the GDPR (establishment, exercise or defence of legal claims). Partly processing also is prescribed by law (e.g. fiscal rules, bookkeeping and accounting; legal requirements placed by the Accreditation Act).
For maintaining our legitimate interests in direct advertising for our range of services, we use the customer’s personal data (name, title, address, contact data, details of the order, past orders) for our own advertising and marketing purposes in order to send the customer information and advertisements about their services and products, news and other customer information that might be interesting for the customer as long as the customer has not objected to processing for purposes of direct advertising.
If you have given us a consent to our processing personal data for definite purposes (e.g. participation in events, passing on of information), the lawfulness of this processing will be given on the basis of your consent. Consent that has been given can be revoked, at any time. This also applies to the revocation of declarations of consent that were made before the GDPR entered into force.
5. Who will receive my data?
Within CIS, only Departments and Divisions that need your data for fulfilling the contractual and legal obligations or for processing due to legitimate interest will be granted access to your data.
It is for purposes of providing the CIS service desired by the customer that CIS will pass data on to the external CIS auditors, trainers, assessors and technical experts acting as CIS’s contract processors. Moreover, CIS avails of services provided by external IT providers.
Acc. to the Accreditation Act and the relevant Standards (in particular ISO/IEC 17021-1 and ISO/IEC 17024), CIS shall be obliged to provide a publicly accessible list of certifications conducted. In the list, which is accessible on the CIS website, the respectively applicable Certificates and their holders are listed.
Based on normative requirements, CIS shall further be obliged to make information on the CIS services available to the Accreditation and Certification Bodies and/or grant these bodies access upon their request. In this process, it also is personal data that can be passed on to the Accreditation and Certification Bodies. Furthermore, CIS can transmit personal data to additional recipients (e.g. public authorities) in order to fulfil legal reporting duties.
When booking cooperation products that are identified as such, the personal data is passed on to the partners.
6. Is data transmitted into a third country or to an international organization?
Data will be transmitted into countries outside the European Union to the extent as this is necessary for CIS carrying out the orders (e.g. if the auditee is based in a third country), prescribed by law or you have given an explicit consent.
7. How long will my data be saved?
The data will be saved for the period in which this is necessary for enabling CIS to fulfil its contractual and legal obligations. Master data about the customer (including organs that have general powers of representation and contact persons at the customer’s) as well as the order history will be archived until the end of the business relationship and, beyond this, until the expiration of the warranty periods, limitation periods and legal retention periods. Application documents, audit and verification reports as well as other documents relating to certification will basically be retained for 12 years as far as normative or legal requirements do not require a longer retention period. Civil-law limitation periods can, in the single case, amount to up to 30 years.
8. What data protection rights do I have?
Acc. to the General Data Protection Regulation (GDPR), each person concerned shall have the right to be informed of the personal data that we process about him or her as well as the rights to rectification, to erasure, to restriction of processing and to data portability. Furthermore, persons concerned can, for reasons resulting from their special situation, object to our processing of personal data that refer to them for the future on the basis of a legitimate interest, at any time. Moreover, they can, at any time, object to future use of their personal data for purposes of direct advertising free of charge and without giving reasons. If you object to processing for purposes of direct advertising, we will thus no longer use your personal data for these purposes.
Besides, there is a right to lodge a complaint with the competent data protection authority. A consent that has been given can be revoked, at any time.
For exercising their rights as persons concerned and in case of questions about data protection guaranteed by CIS, persons concerned can contact firstname.lastname@example.org
9. To what extent are decisions taken in an automated manner?
Not at all!
10. Does profiling take place?
No, CIS does not use profiling software on this website.
11. Is the user behaviour on the website analyzed?
The information generated by such a cookie about your user activities on this website (including your IP address and the URLs of the visited pages and the attributes of the website) is transferred to Google servers in the USA and is stored there. We do not store any of your data collected in connection with Google Analytics.
Our website uses the option of IP anonymization offered by Google Analytics. This means that your IP address is shortened and anonymized by Google as soon as Google receives your IP address. On our behalf, Google uses this information for evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage. Google does not merge the IP address transmitted by your browser within the framework of Google Analytics with any other data.
|_ga||Google Tag Manager||Registers a randomly generated unique ID that is used to generate statistical data about user behavior on the website.||2 years||http Cookie|
|_gat||Used by Google Analytics to limit the request rate.||1 minute||http Cookie|
|_gld||Google Tag Manager||Registers a randomly generated unique ID that is used to generate statistical data about user behavior on the website.||1 day||http Cookie|
|ASP.NET_SessionId||Cookie-bot||Retains the user's states for all page requests within a session.||end of session||http Cookie|
For more information regarding Google's data usage: https://support.google.com/analytics/
© 2021 CIS: All contents, in particular texts, photographs and graphics are protected by copyright. All rights, including reproduction, publication, editing and translation, are reserved by CIS - Certification & Information Security Services GmbH.
All gender-specific expressions always apply equally to all genders.