GDPR and CCPA Compliance
On May 25, 2018, the General Data Protection Regulation (GDPR) went into effect. GDPR is a set of data privacy laws across Europe that are designed to protect EU citizens’ data privacy and reshape the way organizations approach data privacy. On January 1, 2020, the California Consumer Privacy Act of 2018 (CCPA) will go into effect and enforcement will begin July 1, 2020. The CCPA is a California privacy law that is applicable to businesses doing business in California and that meet one of three revenue thresholds. It also applies to service providers of those businesses, who are defined under the CCPA as a company handling PI on behalf of a business, for a business purpose. The following is an update on Khoros’s compliance efforts as they relate to the GDPR and CCPA: We have worked with outside EU counsel to ensure we are correctly interpreting how the GDPR affects Khoros specifically, and to ensure we are handling EU personal data correctly. For example, we confirmed our interpretations of consent requirements and other legal bases for processing personal data and exporting personal data from the EEA with our EU counsel. Additionally, Khoros has been working with outside U.S. counsel to ensure we are compliant with the CCPA. One important point to make clear is that Khoros will never sell our customers’ personal information for any reason at all and we will contractually agree to the same. Khoros has updated its DPA template to expand its scope not just to EU personal data, but to PI covered under the CCPA also. Our DPA template also contains all the necessary GDPR flow-down provisions and accurately reflects the processes used by Khoros to comply with privacy laws. We would be happy to provide you a copy to make it easy for you to check the box in regards to your own GPDR/CCPA compliance efforts. Khoros is continually examining and documenting our internal processes and any aspects of our product portfolio that relate to personal data handling, not just to ensure regulatory compliance, but more importantly to achieve best practices and satisfy our customers’ needs. If you’re looking for more information, check out the links below to our product specific FAQs, privacy policies, details on our subprocessors, and the official sites for GDPR and CCPA. And I know this is complicated, so if you have specific questions, leave them in the comments and I’ll make sure they get addressed. GDPR and CCPA for Communities GDPR and CCPA for Care GDPR and CCPA for Marketing Khoros Privacy Policy Subprocessor web page Official CCPA site Official GDPR site48KViews
Sign in to react to this post12Comments
Khoros Cookies Datasheet (Community, Care, Marketing, Khoros Bot).
Cookies are small data files stored in web browsers to track usage and enable useful services and features when using Khoros Services or interacting with Khoros. This document provides information on the standard cookies used by Khoros Services and Khoros generally and how to reject or delete those cookies should users choose to do so. Understand that restricting cookies can have an adverse impact on the functionality and the online user experience when interacting with Khoros and Khoros Services. We classify the cookies typically used by Khoros and Khoros Services into the four broad categories described below. Type Classification Description Example 1 Strictly necessary These cookies are necessary for the proper functioning of the community, such as tracking a user session, or accessing secure areas. Session cookie used to pin a logged-in session to a browser 2 Performance The information these cookies collect is anonymous and is used to collect aggregate data including information about the pages users visit. Cookies delivered by Omniture WebAnalytics and Google Analytics for purposes of aggregate reporting 3 Functional These cookies allow websites to remember preferences and settings, such as your username, language, region, font size, and so on. Cookie used to hold a user’s username as part of a “remember me” feature 4 Tracking, targeting and sharing These cookies remember that you've visited a website, a particular web page, and/or track your activities on the site. This information is sometimes shared with third party advertisers for serving targeted online advertising or other personalized content. Cookies used to track visitor activity on an individual basis can be used by Khoros or its third party business partners to serve personalized content, and/or later aggregated and used to analyze website traffic and trends. How to control cookies Some cookies are necessary for the proper operation of Khoros Services and disabling or removing them may have an adverse impact on the proper functioning and user experience. However, users may choose to view, block, or remove cookies set by Khoros Services through their web browser settings (or any website cookies for that matter). Consult the help feature for your specific browser to find how. Here are some useful links for your convenience. Microsoft Internet Explorer Privacy Settings and Information Google Chrome Privacy Settings and Information Mozilla Firefox Privacy Settings and Information Apple Safari Privacy Settings and Information Also, you may choose to consult an external and independent third party website such as AboutCookies.org or www.youronlinechoices.eu/ if you are in the European Union which provides comprehensive information on a variety of browsers and how to control or change their respective privacy settings. Cookies used b…315KViews
Sign in to react to this post21Comments
Khoros Customer Data Retention and Destruction
Data Retention Customer data is generally retained for the duration of the customer’s contract with Khoros. Exceptions to this include: Khoros Marketing: Data imported from various social media platforms is retained for a rolling twenty four (24) months before it is automatically purged. Khoros Care: Data imported from various social media platforms is stored for the life of the agreement but can be viewed directly in the platform only for 24 months. Data can be exported from the Service via API for a period of 18 months. Khoros Community: Data processed within Khoros Community will be retained for the life of the agreement. While being retained, all customer data is retrievable and maintained per applicable legal, contractual and regulatory requirements. Customer data is available for 30 days from the date of termination or expiration of the agreement ("Data Retrieval Window"). Once the agreement ends, the data will be returned to the customer upon written request. If data is not requested by the customer, the customer agrees that Khoros has no further obligation to retain the data. Notes: (a) data on backup systems is maintained for 90 days and then deleted; (b) log files are maintained for up to twelve months and then deleted. During and after the life of the agreement, Khoros can use aggregated and anonymized data for metrics and reporting purpose. This data does not include any personal information. Data Backup and Restoration Backups are taken every day and are encrypted using AES 256-bit information. Backups are overwritten every 90 days. Access to the backups is restricted to authorized individuals. We conduct backup restoration testing annually. Data Retrieval At the expiration or termination of the agreement, if the customer wishes to have a copy of its data, the customer must send a written request via the support portal at https://supportportal.khoros.com/ within the Data Retrieval Period noted in the Data Retention section above. We security provide the extract for: Khoros Community content, one time and at no charge, in a machine-readable format. For all other Khoros Services, customers may download the content in a comma separated value (.csv) format. Khoros can provide additional assistance for data extractions at Khoros’s standard Professional Services rates. The availability of content for extraction or downloading from certain services will be limited as described above within the Data Retention section. Data Destruction The data is made available for 30 days from the agreement expiration or termination date. Unless otherwise required by applicable law, customer data is deleted after the Data Retrieval Window in accordance with the above 'Data Retention' section. The active databases are dropped from the production servers and data is permanently deleted according to NIST SP 800-88 guidelines.20KViews
Sign in to react to this post12Comments
You’ve seen all recent content