Data Recipients
In the course of our operations, Sonat engages with various third parties who may receive personal data as part of the services they provide to us. It is vital to our compliance with the General Data Protection Regulation (GDPR) that we disclose who these recipients are, under what circumstances they receive personal data, and the safeguards we put in place to protect your information when it is shared. This section aims to provide transparency about the recipients of personal data processed by Sonat and the measures taken to ensure ongoing protection of your data.
Definition of Data Recipients
A data recipient is any natural or legal person, public authority, agency, or another body to which personal data is disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry shall not be regarded as recipients.
Categories of Data Recipients
Sonat shares personal data with the following categories of recipients:
Service Providers: We engage various service providers who perform functions on our behalf. These include hosting and IT services, customer service, email delivery services, and marketing agencies. Only the minimum necessary information is shared with these service providers to perform their services.
Professional Advisors: Legal, financial, and audit advisors may receive personal data as necessary for the provision of their professional services, under strict confidentiality agreements.
Regulatory Authorities and Law Enforcement: We may be required to disclose personal data to regulatory authorities, law enforcement agencies, or in compliance with legal obligations, court orders, or government requests.
Business Partners: In cases where we collaborate with business partners for the provision of joint services or offerings, we may share personal data to the extent necessary for the partnership.
Legal Basis for Sharing
The sharing of personal data with recipients is conducted under strict adherence to the legal bases outlined by the GDPR, such as:
- Consent: When we have obtained explicit consent to share personal data with certain recipients for specific purposes.
- Contractual Necessity: When sharing is necessary for the performance of a contract with the data subject or to take steps at the request of the data subject before entering into a contract.
- Legal Obligation: When we are legally required to share personal data with certain recipients, such as law enforcement or regulatory bodies.
- Legitimate Interests: When sharing is necessary for our legitimate interests or the interests of a third party, provided those interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
Safeguards and Protections
Sonat is committed to ensuring the security and protection of personal data when it is transferred to third parties. We implement the following safeguards:
- Data Processing Agreements (DPAs): We enter into DPAs with all third-party service providers that process personal data on our behalf, requiring them to comply with GDPR requirements and ensuring the protection of data subjects' rights.
- Standard Contractual Clauses (SCCs): For international transfers of personal data outside the European Economic Area, we use SCCs approved by the European Commission to ensure adequate protection of personal data.
- Security Measures: We require all recipients to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the data processing activities.
Subprocessors
For the list of Subprocessors please see here
Conclusion
Sonat takes the sharing of personal data seriously and is committed to maintaining the trust of our clients and partners by ensuring that personal data is shared responsibly, in compliance with GDPR, and with appropriate safeguards in place. We regularly review our relationships with data recipients to ensure ongoing compliance and protection of personal data.