Putting it into practice Check where the data is stored and what the terms of the contract are. What kind of security practices do they commit to? Usually security settings in cloud storage platforms can be configured to meet the needs of the customer. Make sure someone in the NHRI is familiar with the security controls and knows how to change and manage them. International Data Transfers Different countries will have different rules around transferring personal information to other countries. Generally, ensure that the receiving organisation is able to handle and protect the information in a manner that is equivalent to the way you would. Being responsive: handling requests, queries and complaints Contact Information NHRIs should ensure that their forms and websites and any other location where personal information is collected has their contact details, such as email address and phone number, explicitly inviting anyone who has complaints, queries or concerns about handling of personal information to use these contact details. Some countries have a requirement that organisations make individuals aware of how to complain to the relevant regulatory agency if they are not happy with how complaints are handled by an organisation. Requests for access, correction and deletion Under the GDPR and some other privacy laws, individuals have the ability to access what personal information is held about them and to request that certain data about them be corrected or deleted. This is most relevant where the organisation holding the data has some power over the individual, for example is in a position to grant or deny a service or a benefit. NHRIs should train staff to handle such requests and generally should be prepared and able to meet such requests by: • Providing the individual with a copy of their personal data in a commonly used format like in an email or a PDF. The NHRI should, where relevant, include information about the purpose for which the information is held, who it is shared with externally and how long it is kept. • Correcting or deleting the data if requested unless there are lawful reasons you need to keep it. Lawful reasons could include legal obligations in a court proceeding. Data Protection Guidelines for NHRIs Toolkit 15

Select target paragraph3