Data protection at twoday – we take care of your data
Organization
twoday operates with a robust system to ensure data protection and privacy compliance. The company has a Data Protection Officer (DPO), a Data Protection Council (Council), and Data Protection Managers (DPMs) in each twoday business unit.
Strategic data protection
Strategic decisions regarding data protection are made through the Council to guarantee transparency and accountability. twoday has delegated the responsibility of complying with privacy legislation to the DPO, a formal and independent role as described by the General Data Protection Regulation (GDPR). The DPO oversees privacy-related tasks within twoday.
All twoday business units adhere to the outlined framework and organizational requirements. Each business unit has a DPM resource who collaborates with the country DPM. The country DPM is part of the council with the DPO, reporting on various aspects such as privacy training progress, internal control, incidents, and policy compliance. The Council then reports these findings to twoday group management and owners.
Policies & Guidelines
We have an overview of the data we are working with, we have classified our data, and we have control over our subcontractors.
Data protection program
Incident handling
In case of incidents, twoday's Privacy and Security Incident Response Team promptly initiates the incident response procedure, working closely with the relevant teams.
All twoday employees undergo privacy awareness training due to the evolving legal landscape and increasing cyber threats. Additionally, confidentiality is upheld through employee contracts and e-learning courses in privacy. Development teams receive specialized training and support, including guidance from Data Protection Managers and Security Engineers.