{"id":6701,"date":"2018-02-26T14:19:16","date_gmt":"2018-02-26T13:19:16","guid":{"rendered":"https:\/\/anexia.com\/stagingblog\/?p=6701"},"modified":"2022-04-21T13:45:14","modified_gmt":"2022-04-21T11:45:14","slug":"is-my-service-provider-gdpr-compliant","status":"publish","type":"post","link":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/","title":{"rendered":"Is my service provider GDPR-compliant?"},"content":{"rendered":"<p>The bugbear that is the GDPR is hovering close by.  May 2018 is the date on everyone\u2019s lips: The new EU guidelines on the protection of personal data are about to come into force. A good thing, of course, since, at the end of the day, our data is one of the most valuable commodities of the 21st century. However, the bugbear title is especially apt given the drastically increased penalties that will now be applied in the event of non-compliance. No wonder then that everyone is a little bit apprehensive: In order to comply with the new regulation, what needs to be considered and what can be done to ensure that nothing slips through the cracks?<\/p>\n<p>We get asked the following question over and over: To what extent can the service provider help to ensure compliance with the General Data Protection Regulation and what aspects on the hosting side need to be looked at, especially in the area of virtual systems (clouds)? We asked <a href=\"https:\/\/anexia.com\/en\/software-development\/working-with-anexia\/privacy-and-security\/\">Anexia\u2019s data protection<\/a> expert, Christian Maciossek (Head of Transition &amp; Service Design), to give us some insight into these matters.<\/p>\n<hr \/>\n<p><a href=\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-3332\" src=\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web.jpg\" alt=\"IT Trends 2018 Christian Maciossek\" width=\"599\" height=\"400\" srcset=\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web.jpg 3069w, https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web-325x217.jpg 325w, https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web-300x200.jpg 300w, https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web-768x513.jpg 768w, https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/01\/Christian-Maciossek_01_web-1024x683.jpg 1024w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/a><\/p>\n<p><strong>Christian, what is the GDPR and what changes does it bring with it?<br \/>\n<\/strong>The GDPR is the European Union\u2019s new data protection guideline, which is set to come into force in May 2018 after a two-year transition period. The GDPR aims to protect personal data and ensure consistency of regulation across Europe. Data protection law in Germany and Austria, in particular, is already very strict; not a whole lot is expected to change in these two countries as a result.<\/p>\n<p><strong>What are the challenges facing service providers such as Anexia?<br \/>\n<\/strong>It is incumbent upon service providers such as Anexia to ensure a very high level of security. For us this means that both our own <a href=\"https:\/\/anexia.com\/en\/hosting-it-solutions\/infrastructure\/worldwide\/\">data centers<\/a> and those of our partners must meet the high security requirements that we set. We guarantee this through, among other things, ISO 27001 and 9001 certifications, which have helped lay the foundation for compliance with the GDPR.<br \/>\nIn addition, we\u2019ve added to our security portfolio through the acquisition of SSP Europe. We are now in a position to offer our customers a broad spectrum in order to safeguard their systems. At the same time, we endeavor to identify DDoS attacks and other similar threats to our data centers at an early stage. For this purpose, we\u2019ve greatly expanded our network with the Backbone Europe project.<\/p>\n<p><strong>What does the GDPR mean for our customers?<br \/>\n<\/strong>In unmanaged situations, in particular, our customers need to ensure GDPR compliance themselves. It\u2019s like hiring a car: we ensure that the car has a T\u00dcV certificate, is in safe condition and has been serviced. However, we cannot prevent someone from driving it too fast. And it\u2019s a similar story with personal data, for example, when using virtual machines (VM): Here, we work with a container system. We know that a container exists, but we don\u2019t always know what the content is. That is why it is important that our customers, especially in unmanaged situations, and in some respects also the customers of our customers, familiarize themselves with the current data protection laws.<\/p>\n<p><strong>What information is available on the GDPR?<br \/>\n<\/strong>If you are looking for information on the GDPR, you can find it on the website of the <a href=\"https:\/\/www.bsi.bund.de\/DE\/Themen\/ITGrundschutz\/ITGrundschutzKataloge\/itgrundschutzkataloge_node.html\" target=\"_blank\" rel=\"noopener\">BSI<\/a>, the Federal Office for Information Security. There you can find useful information regarding which rules are to be implemented: What type of hard disk encryption is recommended? How long and how complex should passwords be? And so on.<br \/>\nAs very strict data protection laws have been in place in Germany for some time now, the German BSI has got some excellent tips on protecting personal data.<\/p>\n<p><strong>What does the GDPR mean in terms of cooperation with the USA?<br \/>\n<\/strong>This is a fascinating topic. Indeed, the agreement with the USA will now also change as a result of introducing these new rules: The Safe Harbour Agreement is rendered obsolete by the new GDPR and is now called the <a href=\"https:\/\/www.privacyshield.gov\/welcome\" target=\"_blank\" rel=\"noopener\">Privacy Shield<\/a>. However, the treatment of personal data in the USA and in Europe remains a sensitive issue. This is highlighted, for example, in the decision-making of market leaders such as IBM. There, at the start of the year, it was decided to separate the European and US clouds and to put in place two operating teams. This ensures that no IBM employee in the USA has access to systems of European customers.<br \/>\nThis is also a hot topic for our customers of the <a href=\"https:\/\/anexia.com\/en\/hosting-it-solutions\/infrastructure\/\">Anexia World Wide Cloud (WWC)<\/a>. However, we can guarantee: With our teams of operations, based in Germany and Austria, Anexia ensures that our staff, our Anexians, are fully clued-up on the General Data Protection Regulation and that the personal data is protected to the best of our ability.<\/p>\n<hr \/>\n<p>We are happy to answer any further questions you might have on the GDPR and on the responsibility now assumed by your service provider: <a href=\"mailto:dsgvo@anexia-it.com\">dsgvo@anexia-it.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.<\/p>\n","protected":false},"author":21,"featured_media":3389,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1129],"tags":[1518,1640,1329],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Is my service provider GDPR-compliant? - ANEXIA Blog<\/title>\n<meta name=\"description\" content=\"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Is my service provider GDPR-compliant? - ANEXIA Blog\" \/>\n<meta property=\"og:description\" content=\"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/\" \/>\n<meta property=\"og:site_name\" content=\"ANEXIA Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/anexiagmbh\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-02-26T13:19:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-21T11:45:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png\" \/>\n\t<meta property=\"og:image:width\" content=\"672\" \/>\n\t<meta property=\"og:image:height\" content=\"372\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lucia Sch\u00f6pfer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@_ANEXIA\" \/>\n<meta name=\"twitter:site\" content=\"@_ANEXIA\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lucia Sch\u00f6pfer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"4\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/\",\"url\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/\",\"name\":\"Is my service provider GDPR-compliant? - ANEXIA Blog\",\"isPartOf\":{\"@id\":\"https:\/\/anexia.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png\",\"datePublished\":\"2018-02-26T13:19:16+00:00\",\"dateModified\":\"2022-04-21T11:45:14+00:00\",\"author\":{\"@id\":\"https:\/\/anexia.com\/blog\/#\/schema\/person\/9deea2a33a3e11d08144ff26e442a2f6\"},\"description\":\"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.\",\"breadcrumb\":{\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage\",\"url\":\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png\",\"contentUrl\":\"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png\",\"width\":672,\"height\":372,\"caption\":\"DSGVO-Teaser\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/anexia.com\/blog\/de\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Is my service provider GDPR-compliant?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/anexia.com\/blog\/#website\",\"url\":\"https:\/\/anexia.com\/blog\/\",\"name\":\"ANEXIA Blog\",\"description\":\"[:de] ANEXIA Blog - Technischen Themen, Anexia News und Insights [:]\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/anexia.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"de\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/anexia.com\/blog\/#\/schema\/person\/9deea2a33a3e11d08144ff26e442a2f6\",\"name\":\"Lucia Sch\u00f6pfer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/anexia.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8aaacc3948d00240d95c5e3ca1c9faaa?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8aaacc3948d00240d95c5e3ca1c9faaa?s=96&d=mm&r=g\",\"caption\":\"Lucia Sch\u00f6pfer\"},\"url\":\"https:\/\/anexia.com\/blog\/author\/lschoepfer\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Is my service provider GDPR-compliant? - ANEXIA Blog","description":"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/","og_locale":"de_DE","og_type":"article","og_title":"Is my service provider GDPR-compliant? - ANEXIA Blog","og_description":"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.","og_url":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/","og_site_name":"ANEXIA Blog","article_publisher":"https:\/\/www.facebook.com\/anexiagmbh\/","article_published_time":"2018-02-26T13:19:16+00:00","article_modified_time":"2022-04-21T11:45:14+00:00","og_image":[{"width":672,"height":372,"url":"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png","type":"image\/png"}],"author":"Lucia Sch\u00f6pfer","twitter_card":"summary_large_image","twitter_creator":"@_ANEXIA","twitter_site":"@_ANEXIA","twitter_misc":{"Verfasst von":"Lucia Sch\u00f6pfer","Gesch\u00e4tzte Lesezeit":"4\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/","url":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/","name":"Is my service provider GDPR-compliant? - ANEXIA Blog","isPartOf":{"@id":"https:\/\/anexia.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage"},"image":{"@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage"},"thumbnailUrl":"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png","datePublished":"2018-02-26T13:19:16+00:00","dateModified":"2022-04-21T11:45:14+00:00","author":{"@id":"https:\/\/anexia.com\/blog\/#\/schema\/person\/9deea2a33a3e11d08144ff26e442a2f6"},"description":"The bugbear that is the GDPR is hovering close by. We asked Anexia\u2019s data protection expert, Christian Maciossek to give us some insight into these matters.","breadcrumb":{"@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/"]}]},{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#primaryimage","url":"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png","contentUrl":"https:\/\/anexia.com\/blog\/wp-content\/uploads\/2018\/02\/DSGVO-Teaser.png","width":672,"height":372,"caption":"DSGVO-Teaser"},{"@type":"BreadcrumbList","@id":"https:\/\/anexia.com\/blog\/en\/is-my-service-provider-gdpr-compliant\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/anexia.com\/blog\/de\/"},{"@type":"ListItem","position":2,"name":"Is my service provider GDPR-compliant?"}]},{"@type":"WebSite","@id":"https:\/\/anexia.com\/blog\/#website","url":"https:\/\/anexia.com\/blog\/","name":"ANEXIA Blog","description":"[:de] ANEXIA Blog - Technischen Themen, Anexia News und Insights [:]","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/anexia.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"de"},{"@type":"Person","@id":"https:\/\/anexia.com\/blog\/#\/schema\/person\/9deea2a33a3e11d08144ff26e442a2f6","name":"Lucia Sch\u00f6pfer","image":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/anexia.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8aaacc3948d00240d95c5e3ca1c9faaa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8aaacc3948d00240d95c5e3ca1c9faaa?s=96&d=mm&r=g","caption":"Lucia Sch\u00f6pfer"},"url":"https:\/\/anexia.com\/blog\/author\/lschoepfer\/"}]}},"lang":"en","translations":{"en":6701,"de":3387},"amp_enabled":true,"pll_sync_post":[],"_links":{"self":[{"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/posts\/6701"}],"collection":[{"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/comments?post=6701"}],"version-history":[{"count":1,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/posts\/6701\/revisions"}],"predecessor-version":[{"id":6704,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/posts\/6701\/revisions\/6704"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/media\/3389"}],"wp:attachment":[{"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/media?parent=6701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/categories?post=6701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anexia.com\/blog\/wp-json\/wp\/v2\/tags?post=6701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}