ssm.ro Docs
Compliance & Data ProtectionGDPR

GDPR Compliance Overview

SSM.ro's approach to compliance with Regulation (EU) 2016/679 (GDPR)

Processing of personal data through the SSM.ro platform is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.

Controller and DPO

The reference document for data subjects is the Privacy Policy.

Processing Principles

PrincipleApplication at SSM.ro
Lawfulness, fairness, transparencyEvery processing operation has a documented legal basis; data subjects are informed
Purpose limitationData is processed only for the stated purposes
Data minimizationOnly necessary, adequate, and relevant data is processed
AccuracyPeriodic confirmation of data accuracy
Storage limitationDefined retention windows per purpose
Integrity and confidentialityEncryption, tenant isolation, RBAC access control
AccountabilityCompliance documentation, records of processing activities, DPO

Controller–Processor Role

In its relationship with clients (employers), SSM.ro may act as a data processor for employee data processed on behalf of the client. The allocation of responsibilities is governed by the Data Processing Agreement (DPA).