Article 15: Right of access by the data subject
The data subject has a right to know what personal data is stored by the controller.
Encrypt and store patient PHI in a Data Privacy Vault. Manage access rights and usage purposes centrally.
Article 16: Right of rectification
The data subject can require the controller to rectify inaccurate information.
Article 17: Right to be forgotten
The data subject has the right to erase all personal data stored by the controller.
Article 25: Data protection by design and by default
Controllers must implement appropriate technical and organizational measures to safeguard the personal data collected from data subjects.
Skyflow helps customers protect PII in zero trust data vaults and enable them to manage access centrally.
When using Skyflow Data Privacy Vault, Skyflow takes on the recovery responsibilities on the behalf of the customer.
Article 32: Security of processing
The controller and processor must ensure the adequate protection of personal data, the ability to restore availability, and regular assessment of measures to security.
Article 33: Notification of a personal data breach to the supervisory authority
In the case of a personal data breach, the controller has to notify the supervisory authority within 72 hours.
Skyflow Data Privacy Vault keeps audit logs of all data access. Customer will likely need to ingest audit log with a monitoring service to notice irregularities.
Article 34: Communication of a personal data breach to the data subject
Requires HIPAA-covered entities to provide notification following a breach of PHI unless the probability of re-identification is low.
When copies of PII are replaced with tokens, if the tokenized data gets lost in a result of a breach, no reporting is needed.
Article 44: General principle for transfers
Controllers and processors can only transfer personal data outside of the EU if the receiving country has the same level of data protection.
Localizing EU PII in Europe with a Skyflow Data Privacy Vault can remove company out of data transfer compliance scope.
Article 89: Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is subject to appropriate safeguards (data minimization and pseudonymization).
Customer can grant column-level and row-level data access for public interest without violating GDPR.