{"id":4688,"date":"2023-01-03T10:31:53","date_gmt":"2023-01-03T10:31:53","guid":{"rendered":"https:\/\/backoffice.as\/?page_id=4688"},"modified":"2023-03-08T05:10:49","modified_gmt":"2023-03-08T05:10:49","slug":"gdpr","status":"publish","type":"page","link":"http:\/\/backoffice.as\/en\/gdpr\/","title":{"rendered":"GDPR"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"4688\" class=\"elementor elementor-4688\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0f03732 elementor-section-height-min-height elementor-section-boxed elementor-section-height-default elementor-section-items-middle\" data-id=\"0f03732\" data-element_type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;jet_parallax_layout_list&quot;:[],&quot;shape_divider_bottom&quot;:&quot;opacity-tilt&quot;}\">\n\t\t\t\t\t\t\t<div class=\"elementor-background-overlay\"><\/div>\n\t\t\t\t\t\t<div class=\"elementor-shape elementor-shape-bottom\" data-negative=\"false\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewbox=\"0 0 2600 131.1\" preserveaspectratio=\"none\">\n\t<path class=\"elementor-shape-fill\" d=\"M0 0L2600 0 2600 69.1 0 0z\"\/>\n\t<path class=\"elementor-shape-fill\" style=\"opacity:0.5\" d=\"M0 0L2600 0 2600 69.1 0 69.1z\"\/>\n\t<path class=\"elementor-shape-fill\" style=\"opacity:0.25\" d=\"M2600 0L0 0 0 130.1 2600 69.1z\"\/>\n<\/svg>\t\t<\/div>\n\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-no\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-39f0707\" data-id=\"39f0707\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f5f7a95 elementor-widget elementor-widget-heading\" data-id=\"f5f7a95\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">General Data Protection Regulation (GDPR)<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4b75fe2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4b75fe2\" data-element_type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[],&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4d5080a\" data-id=\"4d5080a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c9bd059 gdpr-text elementor-widget elementor-widget-text-editor\" data-id=\"c9bd059\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>Let's start with the simple:<\/h2><ol><li>Remote access by a company outside the EEA to data in a Norwegian company is considered a transfer.<\/li><li>It is not illegal to transfer accounting data without personal data.<\/li><li>In order for you to legally transfer personal data out of the EEA, you must, among other things, have the right routines and agreements in place that ensure a sufficient level of protection on the same lines as in the EEA.<\/li><li>For the transfer of sensitive personal data, additional and extended measures must be considered.<\/li><\/ol><h2>1. What is a transfer?<\/h2><p>It is not a transfer when you are on holiday outside the EEA and remotely connect to the accounting program to make payroll for a customer. The reason is that the employee (you) is not another data controller, joint data controller or data processor.<br \/>If there is an employee of a company outside the EEA who has the same remote access and makes the payroll run for your customer, this is considered a transfer, even if no data is downloaded. You must then ensure that the personal data is adequately secured.<\/p><h2>2. What is a personal data?<\/h2><p>Directly from the Norwegian Data Protection Authority: <a href=\"https:\/\/www.datatilsynet.no\/rettigheter-og-plikter\/personopplysninger\/\" target=\"_blank\" rel=\"noopener\">Personal data | The Norwegian Data Protection Authority<\/a><br \/>Personal information is all information and assessments that can be linked to you as an individual. Typical personal data are name, address, telephone number, e-mail and social security number. An image is considered personal data if people can be recognised, and audio recordings can be personal data even if no names are mentioned in the recording. Biometrics such as fingerprints, iris patterns, head shape (for facial recognition) are also personal data. etc.<\/p><h2>3. Transfer personal data out of the EEA<\/h2><p>The Norwegian Data Protection Authority's websites and the helpline provide very good information. We have been in constant contact with them to find the right agreements and how to fill them out. See about the businesses' duties: <a href=\"https:\/\/www.datatilsynet.no\/rettigheter-og-plikter\/virksomhetenes-plikter\/overforing-av-personopplysninger-ut-av-eos\/\" target=\"_blank\" rel=\"noopener\">Transfer of personal data outside the EEA | The Norwegian Data Protection Authority. <\/a>Before data is transferred, a separate agreement must be drawn up that secures the personal data. We use the version of the Standard Contractual Clauses with annexes that the Norwegian Data Protection Authority has recommended to us. The contract, routines around security and our transparency towards our customers ensure proper processing of personal data outside the EEA.<\/p><p>Our agreements regarding personal data have been reviewed and quality assured by the law firm PricewaterhouseCoopers AS.<\/p><h2>4. What is Sensitive personal data (called special categories in the law)?<\/h2><p>The Act defines a number of categories of information that require more processing than other information:<\/p><ul><li>information on ethnic origin<\/li><li>information about political opinion<\/li><li>information about religion<\/li><li>information about philosophical beliefs<\/li><li>information about trade union membership<\/li><li>genetic information<\/li><li>biometric information for the purpose of uniquely identifying someone<\/li><li>health information<\/li><li>information about sexual relationships<\/li><li>information about sexual orientation<\/li><\/ul><p>We have also created routines for work tasks so that sensitive information can be legally processed outside the EEA.<\/p><h2>How does the Back Office ensure that personal data is processed in a legal manner outside the EEA?<\/h2><p>We use the Norwegian Data Protection Authority's Data Processing Agreement <a href=\"https:\/\/www.datatilsynet.no\/rettigheter-og-plikter\/virksomhetenes-plikter\/databehandleravtale\/hvordan-lage-en-databehandleravtale\/\" target=\"_blank\" rel=\"noopener\">How to create a data processor agreement? | The Norwegian Data Protection Authority<\/a> which is approved by the European Data Protection Board (EDPB).<\/p><p>In addition, we use Standard Contractual Clauses (SCC) which contain the European Commission's standard privacy regulations <a href=\"https:\/\/www.datatilsynet.no\/rettigheter-og-plikter\/virksomhetenes-plikter\/overforing-av-personopplysninger-ut-av-eos\/sarlig-om-standard-personvernbestemmelser-som-overforingsgrunnlag\/\" target=\"_blank\" rel=\"noopener\">Transfer of personal data outside the EEA | The Norwegian Data Protection Authority<\/a>.<\/p><p>These two agreements, with attachments, provide a detailed description of responsibility, security and how the personal data must be processed to ensure that Europeans' personal data is as well protected after the \"transfer\" to a third country as it is in the EEA.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>General Data Protection Regulation (GDPR) La oss starte med det enkle: Fjerntilgang for et selskap utenfor E\u00d8S til data i et norsk selskap regnes som overf\u00f8ring. Det er ikke ulovlig \u00e5 overf\u00f8re regnskapsdata uten personopplysninger. For at du lovlig kan overf\u00f8re personopplysninger ut av E\u00d8S m\u00e5 du bl.a. ha de rette rutiner og avtaler p\u00e5 [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"footnotes":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Back Office AS &#187; GDPR<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/backoffice.as\/en\/gdpr\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Back Office AS &#187; GDPR\" \/>\n<meta property=\"og:description\" content=\"General Data Protection Regulation (GDPR) La oss starte med det enkle: Fjerntilgang for et selskap utenfor E\u00d8S til data i et norsk selskap regnes som overf\u00f8ring. Det er ikke ulovlig \u00e5 overf\u00f8re regnskapsdata uten personopplysninger. For at du lovlig kan overf\u00f8re personopplysninger ut av E\u00d8S m\u00e5 du bl.a. ha de rette rutiner og avtaler p\u00e5 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/backoffice.as\/en\/gdpr\/\" \/>\n<meta property=\"og:site_name\" content=\"Back Office AS\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/BackOfficeas\" \/>\n<meta property=\"article:modified_time\" content=\"2023-03-08T05:10:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/backoffice.as\/wp-content\/uploads\/2022\/09\/DSC_0503.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1620\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/backoffice.as\/gdpr\/\",\"url\":\"https:\/\/backoffice.as\/gdpr\/\",\"name\":\"Back Office AS &#187; GDPR\",\"isPartOf\":{\"@id\":\"https:\/\/backoffice.as\/#website\"},\"datePublished\":\"2023-01-03T10:31:53+00:00\",\"dateModified\":\"2023-03-08T05:10:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/backoffice.as\/gdpr\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/backoffice.as\/gdpr\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/backoffice.as\/gdpr\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Hjem\",\"item\":\"https:\/\/backoffice.as\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/backoffice.as\/#website\",\"url\":\"https:\/\/backoffice.as\/\",\"name\":\"Back Office AS\",\"description\":\"Offshoring gjort enkelt\",\"publisher\":{\"@id\":\"https:\/\/backoffice.as\/#organization\"},\"alternateName\":\"BackOffice AS\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/backoffice.as\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/backoffice.as\/#organization\",\"name\":\"Back Office AS\",\"alternateName\":\"BackOffice AS\",\"url\":\"https:\/\/backoffice.as\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/backoffice.as\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/backoffice.as\/wp-content\/uploads\/2020\/11\/backofficelogo.svg\",\"contentUrl\":\"https:\/\/backoffice.as\/wp-content\/uploads\/2020\/11\/backofficelogo.svg\",\"width\":533,\"height\":73,\"caption\":\"Back Office AS\"},\"image\":{\"@id\":\"https:\/\/backoffice.as\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/BackOfficeas\",\"https:\/\/www.linkedin.com\/company\/back-office-as\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Back Office AS &#187; GDPR","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/backoffice.as\/en\/gdpr\/","og_locale":"en_US","og_type":"article","og_title":"Back Office AS &#187; GDPR","og_description":"General Data Protection Regulation (GDPR) La oss starte med det enkle: Fjerntilgang for et selskap utenfor E\u00d8S til data i et norsk selskap regnes som overf\u00f8ring. Det er ikke ulovlig \u00e5 overf\u00f8re regnskapsdata uten personopplysninger. For at du lovlig kan overf\u00f8re personopplysninger ut av E\u00d8S m\u00e5 du bl.a. ha de rette rutiner og avtaler p\u00e5 [&hellip;]","og_url":"https:\/\/backoffice.as\/en\/gdpr\/","og_site_name":"Back Office AS","article_publisher":"https:\/\/www.facebook.com\/BackOfficeas","article_modified_time":"2023-03-08T05:10:49+00:00","og_image":[{"width":1620,"height":1080,"url":"https:\/\/backoffice.as\/wp-content\/uploads\/2022\/09\/DSC_0503.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/backoffice.as\/gdpr\/","url":"https:\/\/backoffice.as\/gdpr\/","name":"Back Office AS &#187; GDPR","isPartOf":{"@id":"https:\/\/backoffice.as\/#website"},"datePublished":"2023-01-03T10:31:53+00:00","dateModified":"2023-03-08T05:10:49+00:00","breadcrumb":{"@id":"https:\/\/backoffice.as\/gdpr\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/backoffice.as\/gdpr\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/backoffice.as\/gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Hjem","item":"https:\/\/backoffice.as\/"},{"@type":"ListItem","position":2,"name":"GDPR"}]},{"@type":"WebSite","@id":"https:\/\/backoffice.as\/#website","url":"https:\/\/backoffice.as\/","name":"Back Office AS","description":"Offshoring gjort enkelt","publisher":{"@id":"https:\/\/backoffice.as\/#organization"},"alternateName":"BackOffice AS","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/backoffice.as\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/backoffice.as\/#organization","name":"Back Office AS","alternateName":"BackOffice AS","url":"https:\/\/backoffice.as\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/backoffice.as\/#\/schema\/logo\/image\/","url":"https:\/\/backoffice.as\/wp-content\/uploads\/2020\/11\/backofficelogo.svg","contentUrl":"https:\/\/backoffice.as\/wp-content\/uploads\/2020\/11\/backofficelogo.svg","width":533,"height":73,"caption":"Back Office AS"},"image":{"@id":"https:\/\/backoffice.as\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/BackOfficeas","https:\/\/www.linkedin.com\/company\/back-office-as"]}]}},"_links":{"self":[{"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/pages\/4688"}],"collection":[{"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/comments?post=4688"}],"version-history":[{"count":112,"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/pages\/4688\/revisions"}],"predecessor-version":[{"id":4837,"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/pages\/4688\/revisions\/4837"}],"wp:attachment":[{"href":"http:\/\/backoffice.as\/en\/wp-json\/wp\/v2\/media?parent=4688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}