Universign

RGPD harmonisation at European level

Context & objectives

Following the departure of Universign’s internal DPO, a 360 RGPD maturity audit was carried out by Dposystem at SignaturIT Group level, including 3 entities (Universign, SignaturIT, Ivnosys) on the legal, organisational and technical aspects. In order to complete the action plan identified in the audit, dposystem has continued its RGPD compliance work as part of a new outsourced DPO assignment. The project is being managed by dposystem as DPO for Universign and as advisor at group level.

  • Needs at group level: need to harmonise RGPD compliance actions between the 3 SignaturIT Group entities.
  • Company-level requirements: need for an outsourced DPO for Universign, in particular to support the IT and legal teams in complying with the RGPD.
Business challenge

Involvement in the merger of several SignaturIT Group entities. International dimension of the project (collaboration between Spanish players on the SignaturIT/Ivnosys side and French players on the Universign side). Universign is a company subject to the eIDAS Regulation as part of its activities as a qualified trust service provider. This regulation requires the implementation of technical and organisational security measures to guarantee the integrity of the services provided by Universign. The application of this Regulation has repercussions, particularly with regard to the liability status that must be imposed to protect the personal data of signatories and end customers. It also has repercussions on the supervision of data transfers following the opening up of information systems and the pooling of tools.

Response & method
  • A 360° audit report and action plan
  • Setting up governance
  • Mapping of personal data processing
  • RGPD training
  • Confidentiality policies
  • Drawing up a Data Protection Agreement between SignaturIT group entities and internal communication on this DPA.
Key success factors

The expertise of Netsystem consultants, the service centre, a proven method, adaptability to the specific context of each customer and the ability to operate in an international context.

Related Case Studies