GDPR TEAM Responsibilities:
Manage the privacy@Solvay sco-privacy@syensqo.com mailbox mailbox - where we receive Requests of EOR (Exercise of Rights) as well as companies contacts that are incorrectly sent to us, spam, invoices, etc;- Record the emails received on the mailbox in the file Privacy Mailbox - Daily Report;
- Update the database of all applications and application’s owners (EOR Applications Monitoring);
- Improve the procedure;
- Manage the GDPR Documentation in Wiki/ Confluence;
- Answer to the employees about GDPR Questions - analysis and follow up with the DPPO team (Team responsible for the reply).
- Treat all EOR requests - do the first analysis, start the procedure, finalise it and register it on Adequacy tool
- Revise annually existing information in Google Drive as well as access to it.
...
This is a daily task that allows us to check on time if any request for EOR was sent to us and also to keep the box clean of any other type of requests that generate clutherclutter.
EOR requests have a deadline on 30 days to be treated so we need to be on top of them.
...
For other emails that do not match with these instructions you can check and contact Richard Laurant or Virginia LePennec contact DPPO Responsible member.
Daily report:
When entering the box we need also to open the google sheet - Privacy Mailbox - Daily Report
On the file you must insert the number of emails received each day of the month. This was a procedure that was initially done to provide detailed information to the GDPR team but nowadays is just to provide numbers to our Data leaders
...
- Email received on Privacy mailbox from the data subject with a request to access the data.
- Send an email of First Acknowledgement (template here) for the data subject’s email requesting the identity confirmation
- Open a sub -label in Privacy Mailbox with 1st letter of Name and surname + date of the request (Ex.: Jon Doe requests an EOR ACCESS on 01.01.2022 - must add a sub-label in EOR Access with JD010122 and adding all Process data in this sublabel until recording in Adequacy)
- Open a confidential ticket / Case to HR/ Global Contact Center to request the data they have in:
...
YouGrow if wants to access the training information
- or any other current tool that HR uses for what is being requested of data of the own person.
NOTE: To create a Case for HR should be by Service One and follow the following path: Catalog/Human resources/HR admin and document requests/HR Admin / Personal Data /GDPR
HR EMAIL:
Title /Summary : GDPR Exercise of Rights (URGENT) - Add the code of the EOR (first letters of Name and surname + date of the request)
e.g.: URGENT - EOR ACCESS JD010122
In “Description” In “Description” field you can use a text like this two according the request, according the relation that the person has with Solvay:
...
Could you please send us the request data?
If Requester needs some specific data, you should also inform in the case.
Thank you so much for your support.
...
5. Attached the reply letter and sent it to the data requester.
7. Archive all information, reply letter and proofs in Adequacy.
...
- Received from the request from the data subject to erase the data.
- Send an email of First Acknowledgement (template here) for the data subject’s email requesting the identity confirmation
- Open a sub -label in Privacy Mailbox with 1st letter of Name and surname + date of the request (Ex.: Jon Doe requests an EOR Deletion on 01.01.2022 - must add a sub-label in EOR Deletion with JD010122 and adding all Process data in this sublabel until recording in Adequacy)
- Open a confidential ticket to HR/ Global Contact Center to request the data they have in:
...
Avature if is a candidate
NOTE: To create a Case for HR should be by Service One and follow the following path: Catalog/Human resources/HR admin and document requests/HR Admin / Personal Data /GDPR
Title /Summary : GDPR Exercise of Rights (URGENT) - Add the code of the EOR (first letters of Name and surname + date of the request)
e.g.: URGENT - EOR DELETION JD010122
In “Description” In “Description” field you can use a text like this two according the request, according the relation that the person has with Solvay:
...
5. Attached the reply letter and sent it to the data requester.
7. Archive all information, reply letter and proofs in Adequacy.
...
The requests for modification are usually for data update so we need to find all Data Subject information related to what he needs to correct and replace for the information provided.
Nowadays, most of situation is handled directly by the requester by Solvay Portal unless is a former employee.
STEPS
- Received from the request from the data subject to erase change the data.
- Send an email of First Acknowledgement (template here) for the data subject’s email requesting the identity confirmation
- Open a confidential ticket to HR/ Global Contact Center to request the data they have in:
...
- Avature if is a candidate
NOTE: To create a Case for HR should be by Service One and follow the following path: Catalog/Human resources/HR admin and document requests/HR Admin / Personal Data /GDPR
HR EMAIL:
Follow the model below:
...
We have received an urgent Exercise of Rights request for data erasure and we need to verify if the data subject exists on AVATUREchange.
The concerned data subject is: REQUESTER FIRST AND LAST NAME DATE OF BIRTH + REASON
Could you please check, and update the information as requested by the user ?
(provide the information)
Thank you so much for your support.
...
5. Attached the reply letter and sent it to the data requester.
7. Archive all information, reply letter and proofs in Adequacy.
Very Important Note in EOR Process
With this new platform - SERVICE ONE - the HR Team will reply to your e-mail therefore, you should do the additional steps:
1 - Forward the HR conformation email to sco-privacy@syensqo.com
And the, in the Privacy mailbox we can continuing EOR Process by sending to DPPO and with letter to be approved by the team.
2 - It is also positive if you save the case to attach in Adequacy
-» This should be deleted right after adding in Adequacy Tool as this info should not be kept in any other storage
Adequacy Tool:
SBS has selected the tool of the Infhotep company (ADEQUACY) to build and maintain the Solvay Register.
...
By mandatory enriching the registry with additional information, the registry shall be a real tool to manage Solvay compliance with the GDPR. Indeed, the GDPR documentation requirements are not limited to the obligation to keep a register, and ADEQUACY will propose additional functions to cover other GDPR documentation needs like history of data breaches, documents related to data transfers outside the European Union (contractual clauses, BCR, etc.)…
https://solvaysyensqo.adequacy-corporate.com/
- On the side bar, click on "Exercise of Rights".
- To register a new exercise of rights. Click on "Add a request".
...
- Type of request: Access, Erasure, Portability...
- Request Date: Date that received the request (first email)
- Source of request: privacy mailbox, letter…
- Data subject: as the exemple: EOR-ERA-20200121-001
- If erasure ERA
- If access ACC
- EOR means exercise of rights
- ERA means erasure If
- erasure ERA
- If access ACC
- 20200121 means year month day
- 001 number of requests of the day. In this was the first request
...
Closing date: the process is closed
- Click on “Save”
For attach the Acknowledgement letter, Final letter and any information about the EOR.
...




