Back to Inquiries
🛡️

Annual GDPR Compliance Assessment

in progress
Siemens AGGDPRData Protection
Submitted:20. Dez. 2025
Due:15. Jan. 2026 (Overdue)

Progress

65%
Answered3
Pending2
Needs Review1
1

Documents

2/3 uploaded

2

Questions

3/6 answered

3

Review & Send

Pending

Step 1: Document Requirements (2/3)

67% complete

Data Processing Agreement (DPA)

Signed DPA with Standard Contractual Clauses

Requireduploaded
DPA_Siemens_2025.pdf(1.2 MB)

ISO 27001 Certificate

Valid ISO 27001:2022 certification

Requireduploaded
ISO27001_Certificate.pdf(856 KB)

Privacy Policy

Current privacy policy document

Requiredpending

Step 2: Questions (3/6)

1
Documentation

Do you maintain a Record of Processing Activities (ROPA) as required by Art. 30 GDPR?

answered
Answered
2
Legal Basis

What is your legal basis for processing personal data for each category of processing (Art. 6 GDPR)?

pending
AI Suggestion

We process personal data under the following legal bases: (1) Contract performance (Art. 6(1)(b)) for customer service delivery, (2) Legitimate interest (Art. 6(1)(f)) for analytics with opt-out mechanisms, (3) Consent (Art. 6(1)(a)) for marketing communications...

3
Risk Management

Do you conduct Data Protection Impact Assessments (DPIAs) for high-risk processing as required by Art. 35 GDPR?

pending
AI Suggestion

Yes, we conduct DPIAs for all processing operations that are likely to result in high risk to data subjects. Our DPIA process follows the ICO guidelines and includes assessment of necessity, proportionality, and risk mitigation measures...

4
Data Subject Rights

How do you fulfill Data Subject Access Requests (DSARs) within the 30-day timeframe (Art. 12-22 GDPR)?

answered
Answered
5
International Transfers

What mechanisms do you use for international data transfers outside the EU/EEA (Chapter V GDPR)?

needs review
AI Suggestion

Consider adding: We also implement supplementary measures including encryption in transit and at rest, pseudonymization where possible, and contractual commitments from sub-processors...

6
Governance

Do you have an appointed Data Protection Officer as required by Art. 37 GDPR?

answered
Answered