Scope
This policy applies to all employees, contractors, and third-party service providers who access or handle personal information in connection with G.S.D Group Inc.'s operations. It covers all data processing activities conducted by Octavue, a registered trademark of Global Surveillance Distribution Group Inc. (G.S.D Group Inc.) within Quebec and internationally, where applicable.
Compliance with Law 25
G.S.D Group Inc. is fully committed to complying with Law 25 and all applicable privacy regulations, including those involving:
- The protection of personal data.
- Transparent data processing practices.
- Accountability for data privacy and security.
This law emphasizes greater transparency and accountability for organizations handling personal data, particularly in relation to data subject rights, consent management, and incident reporting.
Data Protection and Privacy Obligations
To comply with Law 25, G.S.D Group Inc. ensures the following core obligations:
- Data Minimization: G.S.D Group Inc. only collects personal data that is strictly necessary for business operations and legitimate purposes.
- Consent Management: Personal data is collected only with clear, informed, and explicit consent. Individuals have the right to withdraw their consent at any time, and this withdrawal is respected by G.S.D Group Inc.
- Access and Transparency: Individuals have the right to access their personal data held by G.S.D Group Inc., request information on how their data is being used, and request corrections to any inaccuracies.
- Data Retention and Deletion: Personal data is retained only for the duration necessary to fulfill its purpose and is securely deleted once it is no longer needed.
- Data Accuracy: G.S.D Group Inc. ensures the accuracy and completeness of the personal data we process. We take reasonable steps to correct or delete inaccurate data upon request.
Data Residency and Security
At G.S.D Group Inc., we prioritize the security and sovereignty of our customers’ personal data. As part of our commitment to compliance with Law 25 and Canadian data protection standards, all personal data processed by G.S.D Group Inc. is stored and resides within Canada. We ensure that:
- Data Storage: All servers used for storing personal data are located within Canadian borders. This ensures that the data remains subject to Canadian laws, including data protection and privacy regulations.
- Data Processing: Personal data is processed in Canada, and all data handling activities comply with Canadian cybersecurity standards and regulations.
- No Cross-Border Data Transfers: G.S.D Group Inc. does not transfer personal data outside of Canada unless required by law or with explicit consent from the data subject. Any such transfer would be made in compliance with applicable laws to ensure that data protection standards are maintained.
Security Measures
G.S.D Group Inc. implements robust cybersecurity measures to protect personal data from unauthorized access, theft, loss, alteration, or misuse. These include:
- Encryption: Personal data is encrypted in transit and at rest to ensure confidentiality.
- Access Control: Only authorized personnel have access to personal data, and access is granted based on the principle of least privilege.
- Firewalls and Intrusion Detection Systems: Our IT infrastructure is equipped with the latest security technologies to prevent unauthorized access and detect potential breaches.
- Regular Audits and Assessments: We perform regular security audits and penetration testing to identify vulnerabilities and improve our cybersecurity posture.
- Employee Training: All employees are trained on cybersecurity protocols and data privacy best practices to ensure compliance with Law 25.
Data Subject Rights
In accordance with Law 25, individuals have the following rights regarding their personal data:
- Right of Access: Individuals can request a copy of their personal data held by G.S.D Group Inc.
- Right to Rectification: Individuals can request corrections to inaccurate or incomplete personal data.
- Right to Deletion: Individuals can request the deletion of their personal data, subject to legal or contractual retention requirements.
- Right to Portability: Where applicable, individuals can request that their personal data be transferred to another organization in a commonly used, machine-readable format.
- Right to Object: Individuals can object to the processing of their personal data, including for marketing purposes.
- Right to Restrict Processing: Individuals can request the restriction of data processing under certain conditions.
Incident Reporting and Breach Notification
In the event of a data breach, G.S.D Group Inc. is required by Law 25 to notify the Commission d'accès à l'information (CAI) and any affected individuals promptly, and no later than 72 hours after becoming aware of the breach. Octavue will take immediate action to mitigate the impact of the breach and prevent further data loss.
Breach Response Plan: G.S.D Group Inc. has a comprehensive incident response plan in place to handle data breaches efficiently and in compliance with Law 25. This plan includes containment, investigation, and notification procedures.
Third-Party Service Providers
G.S.D Group Inc. ensures that all third-party service providers who process personal data on behalf of the company comply with Law 25. We require these providers to sign data processing agreements that outline their obligations to safeguard personal data in accordance with Quebec's privacy laws.
Continuous Improvement
G.S.D Group Inc. is committed to continuous improvement and ongoing compliance with Law 25. Our cybersecurity and data privacy measures will be regularly reviewed and updated to adapt to changing legal requirements, emerging threats, and advancements in technology.
Consequences of Non-Compliance
Failure to comply with this policy and Law 25 may result in legal consequences for G.S.D Group Inc., including potential fines and reputational damage. Employees, contractors, or third parties who fail to adhere to this policy may face disciplinary actions, including termination of employment or contracts.
Contact Information
For any questions or concerns regarding our compliance with Law 25 or this policy, please contact:
- Email: support@gsdgroupinc.com
- Phone: 1-866-791-7020 ext. 6