Technical and Organizational Measures (TOMs)
This document describes Schwarz Group's standard data protection measures for ensuring compliance with the data processing principles set out in Article 5(1) of the EU General Data Protection Regulation (GDPR), including the technical and organisational measures (TOMs) pursuant to Article 32 GDPR. Any project- or system-specific deviations from these measures or supplemental measures are documented separately.
Headings that contain a sequence of numbers refer to Schwarz-internal SIMPL policies. These expound upon the descriptions under the headings and can be provided on request.
TOMs descriptions in the "shall" form indicate the actual status, not a target status.
1 Data Protection Management
Data protection management is geared toward the legal requirements for data protection and allows us to regulate, plan, control, implement and monitor data protection within the organisation.
The following measures ensure that the aforementioned requirements are complied with:
Where required by law, a data protection officer is designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks referred to in Article 39. The provision of sufficient resources for the data protection officer is generally ensured.
All employees are familiarised with company data protection policies. Employees shall be bound by data confidentiality and appropriately instructed on the issues of data protection and information security, e.g., through training and sensitisation measures. Processes for identifying and reporting personal data breaches in good time are established and communicated.
Data protection is integrated in the corporate strategy. These include, for example, regular reporting or the opportunity to escalate data protection-related issues to management at any time. The roles required for data protection management and the responsibilities of the Data Protection department have been defined and communicated. Regular exchange between Data Protection and Information Security is ensured.
The department responsible for the process (the controller) shall document in the record of processing activities all processes, IT systems and other processes in which personal data are processed. The processing form prepared for the relevant process shall include any and all information related to data protection, in particular the purposes for which the personal data were processed as well as the scope, source and time limits for erasure of such personal data. Additionally, the form shall also include information about the intended analyses, the nature and scope of the data subject's information, the data flow and the IT systems used, and the transfer to internal or external bodies, both within and outside the EU/EEA.
When processes, IT systems or other procedures are redesigned or modified, the Data Protection department shall be involved as early as the conceptual phase. Every documented process shall be assessed for lawfulness, fairness and transparency on the basis of the information in the processing form, in order to ensure compliance with such principles and the duties to provide information to data subjects in order to enable them to understand the nature and manner of the data processing. The responsible person within the department decides whether or not to approve the implementation of the process based on this assessment. This process is repeated any time processes, IT systems or other procedures are changed.
2 Fulfilment of Data Subject Rights
Data subjects shall be granted their rights to notification, access, rectification, erasure, restriction of processing, data portability, to object and to obtain human intervention in automated decision-making promptly and effectively if the statutory requirements are met. The controller is obligated to implement the corresponding measures.
The following measures ensure that rights asserted by data subjects are enforced.
The fulfilment of data subjects' rights is ensured by established processes.
16-1
A process for detecting and handling security incidents and reporting them to relevant stakeholders shall be defined.
16-2
Security incidents potentially or demonstrably affecting Schwarz Group information shall be reported to the Schwarz Group SOC/CERT function in a timely manner.
20-2
Functions for erasing, correcting and providing personal data shall be available, and it shall be possible to restrict or terminate the processing of personal data.
20-3
If the consent to the processing of personal data is obtained via an IT system, this consent shall be logged.
3 Data Minimization
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (Article 5(1)(c) GDPR).
The following measures ensure that the aforementioned requirements are complied with:
20-4
An appropriate concept for deleting personal data shall be in place for any IT systems that are used to process personal data.
20-5
In IT systems that process personal data, there shall be appropriate separation of data records that are processed for different purposes, or, in the case of shared IT systems, by different controllers.
4 Transparency
Data subjects as well as system operators and competent supervisory authorities should be able to identify which data is collected and processed when and for what purpose during a processing activity, which systems and processes are used for this, where the data flows to and for what purpose, and who is legally responsible for the data and systems in the various phases of data processing. Transparency is necessary for monitoring and control of data, processes and systems from their inception to their deletion and is a prerequisite for data processing to be operated in compliance with the law and, where necessary, for informed consent to be given by data subjects.
The following measures ensure that the aforementioned requirements are complied with:
In the context of assessing processes under data protection law, it is ensured that the information obligations are checked and complied with.
The use of contractors and customers is described and documented in a record of processing activities.
1.1-1
Information security policies shall be documented, approved and communicated to relevant groups via a binding requirements management process. In addition, these shall be regularly reviewed with regard to suitability and appropriateness.
1.2-1
Information security roles and responsibilities shall be defined and assigned to appropriate persons.
1.3-1
Information security policies for users shall be defined and communicated to users.
1.4-1
Legal, regulatory, self-imposed and contractual information security requirements shall be known and documented.
2.1-1
Information security risks shall be identified, assessed, treated, and monitored.
2.2-1
Key performance indicators for controlling information security objectives shall be defined and regularly reported to management in order to derive measures for continuous improvement.
2.3-1
Information security-related assets shall be identified, documented, and classified by criticality.
3.2-1
All employees shall be regularly trained and sensitized with regard to information security in accordance with their tasks.
4-1
The security of processes, IT systems and external service providers shall be audited regularly and independently.
12-1
Security-relevant system events shall be logged in a tamper-proof manner and continuously evaluated.
15-1
Information security requirements for external service providers and a right to audit these requirements shall be defined and contractually agreed.
16-1
A process for detecting and handling security incidents and reporting them to relevant stakeholders shall be defined.
16-2
Security incidents potentially or demonstrably affecting Schwarz Group information shall be reported to the Schwarz Group SOC/CERT function in a timely manner.
20-2
Functions for erasing, correcting and providing personal data shall be available, and it shall be possible to restrict or terminate the processing of personal data.
20-3
If the consent to the processing of personal data is obtained via an IT system, this consent shall be logged.
5 Purpose Limitation
The purposes for processing personal data shall be specified in advance and documented in writing in the record of processing activities in the relevant processing form. Suitable technical and organisational measures are implemented to ensure that personal data are not processed further in a manner that is incompatible with the specified purposes.
The following measures ensure that the aforementioned requirements are complied with:
The mandatory involvement of the Data Protection department in the redesign or modification of processes, IT systems or other processing - as early as the conceptual phase - ensures that changes to defined purposes are reassessed and avoided if they violate the principle of purpose limitation.
Where processing is to be carried out on behalf of a controller or in the event of a joint controller arrangement, the proper contract drafting and engagements are, as a rule, carried out using model agreements and documented. If a company of Schwarz Group is engaged to process personal data, this is done on the basis of the respective applicable master agreement on the "Provision of Data Protection-related Services within Schwarz Group" and using a model agreement to govern the specifics of the data processing operations in the given case.
Processors shall disclose the technical and organisational measures taken prior to processing. Depending on the individual case, it shall be decided whether additional audit measures will be introduced in addition to the document-based audit of the technical and organisational measures.
Prior to commissioning data processing on behalf of a controller, the controller shall duly verify that the processor complies with the promised technical and organisational measures. Depending on the responses and the documents provided by the processor, it is decided whether further measures are required, such as on-site inspections or the engagement of third parties to verify the level of data protection afforded.
Employees are made aware of the fact that, where processing on behalf of a controller is involved, they may only process personal data provided by the customer within the scope of the customer's instructions.
14.1-1
No developments and tests may be carried out in productive systems.
14.1-2
Best practice approaches to secure software development shall be considered and implemented.
14.2-1
Before a software development goes live, it shall be tested for security vulnerabilities and correct functionality.
20-1
IT systems shall be hardened according to best practice approaches in such a way that only services and functions that are considered secure according to the current state of the art and are necessary for operation are activated.
20-3
If the consent to the processing of personal data is obtained via an IT system, this consent shall be logged.
20-4
An appropriate concept for deleting personal data shall be in place for any IT systems that are used to process personal data.
20-5
In IT systems that process personal data, there shall be appropriate separation of data records that are processed for different purposes, or, in the case of shared IT systems, by different controllers.
6 Integrity
IT systems and processes shall comply at all times with the specifications defined for them to execute their intended functions. The data to be processed should remain intact, complete, correct and current. Any deviations from these properties should be ruled out or at least be identifiable so that they can be taken into account and corrected.
The following measures ensure that the aforementioned requirements are complied with:
6.2-1
IT systems shall be regularly checked for vulnerabilities, which shall be remedied within a defined remediation period, based on their criticality.
6.3-1
Security patches shall be applied to IT systems regularly and promptly after their release.
8-1
IT systems and interfaces shall be protected from malware through the use of anti-malware solutions.
9.3-1
The creation, modification and allocation of access rights shall be carried out in a comprehensible manner using the 4-eyes principle.
9.3-2
Permissions shall be assigned according to the principle of minimal rights assignment.
9.3-3
Authorizations shall be reviewed regularly for appropriateness and adjusted as needed.
12-1
Safety-relevant system events shall be logged in a tamper-proof manner and continuously evaluated.
13.2-1
The internal network shall be segmented according to suitable criteria and controlled by communication rules.
14.2-1
Before a software development goes live, it shall be tested for security vulnerabilities and correct functionality.
14.2-2
Changes to IT systems shall be tested and approved.
16-1
A process for detecting and handling security incidents and reporting them to relevant stakeholders shall be defined.
16-2
Security incidents potentially or demonstrably affecting Schwarz Group information shall be reported to the Schwarz Group SOC/CERT function in a timely manner.
7 Availability
Access to personal data and its processing should be possible without undue delay. Availability encompasses the retrievability of specific data, e.g., by data management systems, structured databases and search functions, and the ability of the technical systems used to display data appropriately for humans as well. To implement availability, measures shall also be put in place to ensure that personal data and access to it can be restored quickly in the event of a physical or technical incident. Measures shall also be implemented to guarantee the availability of personal data and the systems and services that process them when they are under an expected load commensurate with the processing and, in the event of an unexpectedly high load, to ensure that the protection of personal data is not jeopardised. If, in exceptional cases, the protection of personal data is nevertheless violated with regard to availability, it shall be ensured that measures are taken to remedy and mitigate the violation.
The following measures shall be implemented to ensure the availability of personal data on a permanent basis.
Fire and Lightening Protection:
All central administrative and special properties are equipped with a sufficient number of fire extinguishers in accordance with German Workplace Regulation (ASR) A2.2. Fire compartments are also separated by fire and smoke protection doors in accordance with legal and insurance requirements, in particular the stairwells and necessary corridors.
At least two separate escape routes are designated at all times. Depending on their size and dimensions, smoke alarms, automated fire alarm and/or extinguishing systems are installed in the buildings. Alerts of fire alarms, the deployment of extinguishers, water ingress and power outages are monitored centrally by the permanently staffed security control centre, from where the responsible persons are notified via alert software if necessary.
In all properties, employees are instructed on their work environment through the annual safety briefing. In addition, people are instructed in the proper use of fire alarms, fire extinguishers and wall hydrants through regular fire safety training courses. A general no-smoking policy applies on all company premises and particularly inside buildings. If the building classification requires a lightning protection system, this is operated in the required protection class. The fire safety officers appointed in writing carry out fire safety inspections at least once a year, during which the above-mentioned points are checked. Technical systems are inspected, maintained and tested in accordance with legal, trade association or insurance requirements.
11.2-2
Data centers and server rooms shall be protected from environmental hazards such as water, fire, overheating, overvoltage or power failures.
12-2
The capacities and availabilities of IT systems shall be monitored.
16-1
A process for detecting and handling security incidents and reporting them to relevant stakeholders shall be defined.
16-2
Security incidents potentially or demonstrably affecting Schwarz Group information shall be reported to the Schwarz Group SOC/CERT function in a timely manner.
17-1
Emergency processes and tested emergency concepts shall be in place to ensure emergency operations and the necessary communication in the event of an emergency.
18.1-1
Backups shall be performed on a regular basis. Backup media shall be stored in a location away from data processing.
18.2-1
Backups shall be checked for functionality through regular recovery tests.
8 Confidentiality
Personal data may not be disclosed to or used by unauthorised third parties. Unauthorised persons are not only third parties outside the controller, but also employees who do not need access to personal data to perform their tasks or persons in organisational units who have no substantive connection to a processing activity or to the respective data subject. The confidentiality of personal data shall also be ensured if the underlying systems and services are subject to unexpectedly high loads. If, in exceptional cases, the confidentiality of personal data is nevertheless violated with regard to availability, it shall be ensured that measures are taken to remedy and mitigate the resulting personal data breach.
Anti-burglary Measures:
As a rule, buildings shall be fenced in and access roads shall be gated. The buildings are generally equipped with a burglar alarm system. Entrances to the building are monitored. Inside the building, the rooms are monitored by motion detectors. When triggered, a permanently staffed control centre is alerted.
Key Management:
Office buildings shall always remain locked. Doors may only be opened by authorised personnel using an electronic key card or a mechanical key. Electronic key cards, mechanical keys and cylinders are assigned on the basis of a hierarchical access control system, meaning that direct supervisors can access the offices of their employees. Offices in which personal data are processed shall be locked when employees leave for extended periods or after office hours. Confidential data in open-plan offices shall be locked away in office furniture.
Management of other key cards and keys, such as their issue, return, inventory, etc., is documented using an audit-proof software solution.
The requirements for handling other access key cards and keys, such as sharing them with third parties, loss, etc., are specified accordingly in the relevant issuance form.
Master keys for central locations shall be locked away and secured with alarm systems with site security or in the control centre. In the event of fire, master keys shall be provided to the fire brigade to allow it access without the use of force. The issue and return of keys shall be recorded.
Access Control System:
Access for Employees of Schwarz Group:
When presented, electronic employee ID cards unlock and lock entry doors to buildings, doors to building floors and hallways as well as access doors to secured areas and offices. The electronic access profiles shall generally be based on the employee's department and position. There shall also be functional profiles for janitorial and maintenance staff, for example. The issue, respective access permissions and use of electronic ID cards shall be recorded. Access to these data is granted by the responsible employee in accordance with the documented authorisation concept.
Access for Permanently Engaged External Companies:
Technicians and cleaning and maintenance personnel are given electronic ID cards with additional access rights; their access to secured areas is restricted, however. They shall be given instructions for their activities in the buildings and supervised by employees of the responsible department; site security will escort them at the department's request.
Access for Other External Service Providers:
When they start work, tradespeople receive an electronic company ID card with basic access rights, but without access to secured areas. They shall be given instructions for their activities in the buildings and supervised by employees of the responsible department; site security will escort them at the department's request.
Access for Guests:
Central locations shall have reception areas where visitors can sign in during business hours. An employee shall receive the guests in the waiting area and accompany them for the duration of their stay on the premises. The doors shall be locked outside of reception hours or when the reception areas are unstaffed. In such instances, visitors contact the employee via the intercom or telephone in the reception area or site security when visiting central locations.
Video Surveillance:
At-risk sites may have a video surveillance system, which is governed by a valid video surveillance policy applicable to the respective site.
5-1
Bei der elektronischen Übertragung und Speicherung von Informationen müssen diese auf Basis ihrer Klassifikation angemessen vor unberechtigtem Zugriff geschützt werden.
6.2-1
IT systems shall be regularly checked for vulnerabilities, which shall be remedied within a defined remediation period, based on their criticality.
7-1
The deletion, destruction and disposal of data media shall be carried out using a procedure that is considered safe according to the current state of the art and shall be documented in a comprehensible manner.
7-2
Endpoint protection solutions shall control read and write access to mobile storage devices and interfaces.
7-3
Confidential paper documents shall be kept under lock and key. These shall not be left unattended and shall be safely destroyed.
9.1-1
When employees leave, all authorizations shall be revoked promptly.
9.1-2
User accounts shall be clearly assigned to a person.
9.2-1
Access to information within IT systems shall take place via secure authentication methods.
9.2-2
Accesses from external networks to internal information shall take place via multi-factor authentication.
9.2-3
Authentication information shall be protected from unauthorized access during transmission and storage.
9.2-4
Default passwords and default accounts shall be changed or locked.
9.2-5
End devices shall be locked automatically in case of inactivity. Unlocking shall only be possible by personal authentication.
9.2-6
The criteria for using passwords shall protect against guessing and trial-and-error access attempts (brute-force attack) of passwords.
9.3-1
The creation, modification and allocation of access rights shall be carried out in a comprehensible manner using the 4-eyes principle.
9.3-2
Permissions shall be assigned according to the principle of minimal rights assignment.
9.3-3
Authorizations shall be reviewed regularly for appropriateness and adjusted as needed.
10.1-1
Secure and non-compromised cryptographic methods shall be used for encryption.
10.2-1
Only trusted and non-compromised certificate authorities (CA) may be used.
10.3-1
The creation, distribution, storage and deletion of certificates shall follow a defined process.
10.4-1
Business data shall be transmitted over public networks in encrypted form.
11.1-1
An access concept shall ensure that physical access to business premises is restricted to authorized persons only.
11.2-1
Unauthorized access to data centers and server rooms shall be detected and reported.
13.1-1
Access to the internal network shall be restricted to authorized users and systems.
13.2-1
The internal network shall be segmented according to suitable criteria and controlled by communication rules.
13.4-1
Access from external networks to the internal network shall only be possible for defined and controlled connections.
13.5-1
Access to external networks and Internet sites shall be controlled.
22-1
It shall be ensured that business data from lost or stolen mobile devices cannot be accessed by unauthorized third parties.
22-2
IT devices shall not be left unattended in public spaces or shall be protected from unauthorized access.