Private area
What it adds
- The GDPR: the association is the data controller, the provider its processor, with a contract; record of processing, information of people, answers to requests, notification of a breach to the Data Protection Authority within 72 hours
- Security: fast updates, two-factor authentication, access logs, tested backups, tests against known flaws
- Recurring maintenance: this work never stops and is quoted per year
- Shared responsibility: who has access, which accounts are closed, what is collected; decided beforehand and written down
In Kern4Good
No tier of the ladder includes a private area, whatever the size of the website. A members' area is quoted separately, with its maintenance, and responsibilities are set out in black and white before starting. A ten-page public website with a members' area costs more than a fifty-page public website without one.
Is a simple password on a documents page a private area?
Yes, as soon as there is reserved access and identified people behind it. If the documents are not sensitive, a non-public link is sometimes enough, without accounts: that is what we look at during scoping.
Who answers in case of a data leak?
The association, as data controller, notifies the Data Protection Authority within 72 hours; the provider helps and documents what happened. The processing contract says who does what.
