Compliance & Data ProtectionGDPR
GDPR Compliance Overview
SSM.ro's approach to compliance with Regulation (EU) 2016/679 (GDPR)
Processing of personal data through the SSM.ro platform is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.
Controller and DPO
- Joint Controllers (Art. 26 GDPR): CONSULTIA S.R.L. and CONSULTIA DIGITAL S.R.L. (Brașov, str. Pârâului nr. 7) — dpo@ssm.ro
- Data Protection Officer (DPO): Neoprivacy SRL — marius.dumitrescu@neoprivacy.ro
- Supervisory Authority: ANSPDCP — www.dataprotection.ro
The reference document for data subjects is the Privacy Policy.
Processing Principles
| Principle | Application at SSM.ro |
|---|---|
| Lawfulness, fairness, transparency | Every processing operation has a documented legal basis; data subjects are informed |
| Purpose limitation | Data is processed only for the stated purposes |
| Data minimization | Only necessary, adequate, and relevant data is processed |
| Accuracy | Periodic confirmation of data accuracy |
| Storage limitation | Defined retention windows per purpose |
| Integrity and confidentiality | Encryption, tenant isolation, RBAC access control |
| Accountability | Compliance documentation, records of processing activities, DPO |
Related Topics
- Legal Grounds and Consent
- Rights of Data Subjects
- Data Protection Impact Assessment (DPIA)
- Data Breach Notification
- Records of Processing Activities
- Data Retention and Deletion
- International Transfers
- Subprocessors
Controller–Processor Role
In its relationship with clients (employers), SSM.ro may act as a data processor for employee data processed on behalf of the client. The allocation of responsibilities is governed by the Data Processing Agreement (DPA).