Data Storage and International Transfers
At Sonat, we are committed to the highest standards of data protection and privacy, recognizing the importance of compliance with the General Data Protection Regulation (GDPR) for our European Union customers and partners. As part of our commitment to transparency and accountability, this section outlines our practices regarding the storage of data and the measures we have implemented to ensure that data storage and transfers, particularly to the United States where our data storage facilities are located, are in full compliance with GDPR requirements.
Location of Data Storage
Sonat stores its data in secure data centers located in the United States. These facilities are equipped with state-of-the-art security measures to prevent unauthorized access, disclosure, alteration, and destruction of the information under our control. Our choice of location is driven by our commitment to provide reliable, efficient, and secure services to our customers.
Compliance with GDPR
Despite the geographical distance, Sonat ensures that personal data transferred from the European Union to the United States is protected in a manner that is consistent with the requirements of the GDPR. To achieve this, we have implemented the following measures:
Privacy Program and Policies: We have established a comprehensive privacy program that includes policies and procedures designed to protect personal data. Our program is based on the principles of data minimization, limitation of purpose, and ensuring data accuracy. We regularly review our privacy policies and practices to ensure ongoing compliance with GDPR.
Data Protection Impact Assessments (DPIAs): When processing activities present a high risk to data subjects' rights and freedoms, Sonat conducts Data Protection Impact Assessments to systematically analyze, identify, and minimize data protection risks.
Employee Training and Awareness: Sonat ensures that all employees who have access to personal data are trained on our data protection policies and procedures. This ongoing training program is designed to promote awareness of privacy and data protection responsibilities within our organization.
Technical and Organizational Measures: We employ robust technical and organizational measures to ensure the security of data, including encryption, access controls, secure data transmission protocols, and regular security assessments. These measures are designed to guarantee the confidentiality, integrity, and availability of personal data.
Conclusion
Sonat's adherence to GDPR-compliant practices for the transfer and storage of data in the United States demonstrates our unwavering commitment to the privacy and protection of our customers' information. By employing rigorous safeguards and legal mechanisms such as Standard Contractual Clauses, we ensure that personal data is handled with the utmost care and respect, maintaining its protection to GDPR standards regardless of its physical location. Our proactive approach to data protection and privacy exemplifies our dedication to being a trusted and responsible partner to our EU customers and partners.