1. Legal Basis for Processing
We process personal data based on legitimate interests for business operations, contract performance for genetic testing services, legal compliance for regulatory requirements, and explicit consent for marketing communications and research participation.
2. Data Subject Rights
Right of Access: Request copies of your personal data and information about processing activities.
Right to Rectification: Correct inaccurate or incomplete personal information.
Right to Erasure: Request deletion of personal data under certain circumstances.
Right to Restrict Processing: Limit how we use your data in specific situations.
Right to Data Portability: Receive your data in a structured, machine-readable format.
Right to Object: Opt-out of processing based on legitimate interests or direct marketing.
3. Consent Management
Consent is freely given, specific, informed, and unambiguous. You may withdraw consent at any time without affecting the lawfulness of prior processing. Withdrawal instructions are provided in all communications requiring consent.
4. Data Processing Activities
Personal data processing includes customer account management, genetic test processing, result delivery, customer support, quality assurance, regulatory compliance, and anonymized research activities. Each activity has appropriate legal basis and safeguards.
5. International Transfers
Data transfers outside the EU use adequacy decisions, Standard Contractual Clauses, or other approved transfer mechanisms. We ensure equivalent protection standards regardless of processing location through contractual and technical safeguards.
6. Data Protection Impact Assessments
We conduct DPIAs for high-risk processing activities, particularly those involving genetic data. Regular assessments ensure ongoing compliance and identify necessary additional safeguards for data subject protection.
7. Breach Notification
Data breaches are reported to supervisory authorities within 72 hours when required. Affected individuals are notified when breaches pose high risks to their rights and freedoms. We maintain detailed incident response procedures.
8. Data Protection Officer
Our DPO monitors compliance, conducts privacy impact assessments, and serves as contact point for supervisory authorities and data subjects. DPO contact information is available upon request.
9. Special Category Data
Genetic data receives enhanced protection as special category personal data. Processing requires explicit consent and additional safeguards including pseudonymization, encryption, and restricted access controls.
10. Supervisory Authority
EU residents may lodge complaints with their local data protection authority. We cooperate fully with supervisory authority investigations and implement recommended corrective measures.
11. Records of Processing
We maintain comprehensive records of processing activities including purposes, categories of data, retention periods, and security measures. Records are available for supervisory authority review upon request.
12. Contact Information
GDPR-related inquiries should be directed to our Data Protection Officer at 789 Innovation Drive, Boston, MA 02114, USA or +1 (617) 555-0189.