Dokumendiregister | Andmekaitse Inspektsioon |
Viit | 2.2-9/25/1291-1 |
Registreeritud | 25.04.2025 |
Sünkroonitud | 28.04.2025 |
Liik | Sissetulev kiri |
Funktsioon | 2.2 Loa- ja teavitamismenetlused |
Sari | 2.2-9 Selgitustaotlused |
Toimik | 2.2-9/2025 |
Juurdepääsupiirang | Avalik |
Juurdepääsupiirang | |
Adressaat | DNAlyse |
Saabumis/saatmisviis | DNAlyse |
Vastutaja | Maarja Kirss (Andmekaitse Inspektsioon, Koostöö valdkond) |
Originaal | Ava uues aknas |
Tähelepanu! Tegemist on välisvõrgust saabunud kirjaga. |
Tähelepanu! Tegemist on välisvõrgust saabunud kirjaga. |
Dear DPI team,
DNAlyse is newly established company that wants to focus on re-selling DNA testing under its own label from an already established provider to distributors in different countries. The provider is based in EU, has all the necessary GDPR compliance but in order to re-sell under DNAlyse brand, its important the end clients to log in directly on the DNAlyse website where they can see their personal DNA reports. Currently we are working on the contract where the provider remains GDPR controller and processor, however they agree DNAlyse to host the reports under DNAlyse brand on its own website. DNAlyse will not change anything, it will only host the reports, as the distributors will only re-sell the service and wont have access here into the reports. Sure in privacy and policy we will publicly state who is the provider.
I assume this requires DNAlyse to become GDPR processor and to assign its own DTO. I already have qualified and certified DTO in mind that is located in North Macedonia. Please come back to me on what are the required steps so we do everything correct on our end.