V12 Data verifies that it adheres to all of the Privacy Shield Principles concerning the transfer of personal data from the European Union (“EU”) to the United States (“U.S.”). As such, we follow the Privacy Shield Principles published by the U.S. Department of Commerce (the “Principles”) with respect to all such data.
The Privacy Principles are:
To learn more about the Privacy Shield program please visit the U.S. Department of Commerce: https://www.privacyshield.gov/.
V12 Data provides customized computer services designed to help companies manage their customer information more effectively, increase profitability of their marketing and reduce the operational costs of processing customer information. In this capacity, V12 Data does not own or control any of the information it processes on behalf of V12 Data’s clients. All such information is owned and controlled by V12 Data’s clients. In this capacity V12 Data receives information transferred from the EU to the United States merely as a processor on behalf of our clients.
When V12 Data acts as a processor on behalf of its clients, the policies outlined below apply to all data processing operations concerning personal information that has been transferred from the EU to the United States.
Before starting any processing on behalf of V12 Data’s clients, V12 Data will enter into a processing contract with the EU data controller responsible for the personal information pursuant to the applicable EU Member State Data Protection law. The processing contract ensures that the EU data controller will be in compliance with the Member State Data Protection law.
Any data processed by V12 Data will not be further disclosed to third parties except where permitted or required by the processing contract, EU Safe Harbor or the applicable Member State Data Protection law.
Any information V12 Data’s client (acting as the EU controller) identifies as sensitive will be treated accordingly.
The processing contract will also specify that the processing will be carried out with appropriate data security measures. V12 Data has in place measures to protect personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction.
V12 Data adheres to the Principles of the Privacy Shield, and is committed to subject all personal data received from the EU to the Privacy Shield Principles. To find out more about participating companies, here is a link to the list maintained by the USDOC: https://www.privacyshield.gov/list.
Prior to the transfer of any non-public personal information from the EU to the United States, V12 Data requires contractual confirmation from the EU controller from whom V12 Data acquired the information that the personal data has been provided to V12 Data in accordance with the applicable EU Member State Data Protection law, thereby ensuring the data subjects have been provided with proper notice regarding how their personal data will be used. In addition, when personal data is collected directly from data subjects, V12 Data provides the data subject with notice regarding the manner and circumstances in which the personal data will be used and transferred to third parties.
Prior to the transfer of any non-public personal information from the EU to the United States, V12 Data requires contractual confirmation from the EU controller from whom V12 Data acquired the information that the personal data has been collected in accordance with applicable EU member State Data Protection law, thereby ensuring the data subjects have been provided with the proper choice regarding how their personal data may be used.
Accountability for Onward Transfer
V12 Data complies with the notice and choice principles as described above for all data disclosed or transferred to a third party. However, when V12 Data uses data processors to perform processing tasks on behalf and under the instruction of V12 Data, V12 Data requires that its data processors:
V12 Data has in place an information security policy to protect personal information from loss, misuse, unauthorized access, disclosure, alteration and destruction. V12 Data’s security officer is responsible for conducting investigations into any alleged computer or network breaches, incidents or problems and ensuring the proper disciplinary action is taken against those who violate V12 Data’s information security policy.
Any security compromises or potential security compromises and any inquiries concerning security should be reported to the V12 Data consumer advocate. Contact information is provided below under Access.
Data Integrity and Purpose Limitation
V12 Data takes reasonable steps to ensure the information transferred from the EU to the United States is reliable, accurate, complete and current. The steps V12 Data takes to assure data integrity are based on the purposes for which the personal information is used.
An individual may request access to the information V12 Data maintains in its information products. The individual has the right to learn whether or not data about him or her is found in V12 Data’s information products and to correct, amend or delete that information when it is inaccurate. This right applies only to personal information about the individual making the request and is subject to other limitations as defined by law.
Individuals can request access by emailing or writing:
Office of Consumer Advocacy
One East Oak Hill Dr. Suite 301
Westmont, IL 60559
V12 Data’s consumer advocate will explain the process for making an access request. In order to confirm the identity of the individual and have the necessary information to retrieve the individual’s information, V12 Data provides a request form which the individual fills out, signs and postal mails to V12 Data. V12 Data agrees to process all reasonable requests for access within a reasonable time period, but reserves the right to deny access or limit access in cases where the burden or cost of providing access would be disproportionate to the risks to the individual’s privacy or in the case of an unwarranted or fraudulent request.
Recourse, Enforcement and Liability
Individuals who wish to file a complaint or who take issue with V12 Data’s EU U.S. Privacy Shield Principles should contact V12 Data’s consumer advocate. V12 Data’s consumer advocate will explain the process to be followed when filing a complaint. Filing a complaint in English will speed-up the request process.
V12 Data has registered under the DMA’s safe harbor complaint resolution process. If consumers can’t resolve a complaint after contacting V12 Data’s consumer advocate, they may file a written complaint with the DMA:
Privacy Shield Line
1615 L St. NW, Suite 1100
Washington, DC 20036
V12 Data is also subject to the jurisdiction of the U.S. Federal Trade Commission. Consumers unable to resolve a complaint through the DMA Privacy Shield Complaint process may contact the Federal Trade Commission:
Federal Trade Commission
Attn: Consumer Response Center
600 Pennsylvania Avenue NW
Washington, DC 20580
In the event a dispute cannot be resolved V12 Data is open to the possibility of Binding Arbitration.
See more at: V12 Data-privacy-point-view
V12 Data is required to disclose personal information in response to lawful requests by public authorities, including meeting national security or law enforcement requirements.