Data Protection Officer
A DPO has been appointed as the contact for matters relating to the protection of personal data and the exercise of data subjects’ rights.
Quality and Safety Srl is committed to strict compliance with European Regulation No. 679 of 2016 (GDPR) and with all directives and instructions issued by the supervisory authorities. The technical and organizational measures we apply are aligned with the ISO/IEC 27001 standard.
A DPO has been appointed as the contact for matters relating to the protection of personal data and the exercise of data subjects’ rights.
Strict compliance with Regulation (EU) 2016/679 and with all directives and instructions issued by the supervisory authorities.
We collect only the data strictly necessary for the stated purposes, following the privacy-by-default principle.
Infrastructure in Italy and Europe, at-rest and in-transit encryption, access governed by ISO/IEC 27001 policies.
We promptly handle requests for access, rectification, erasure, restriction, portability and objection.
Documents
Internal policy and form to submit requests regarding the protection of personal data.
In the services we provide to clients we typically act as Data Processor (Art. 28 GDPR), with an appointment contract governing instructions, security measures, confidentiality obligations and audits.
On request we provide our clients with the DPA (Data Processing Agreement) and the up-to-date list of sub-processors, including ACN-qualified infrastructure providers.
For processing that requires it — such as in healthcare or involving AI technologies — we collaborate with our clients on drafting the DPIA (Data Protection Impact Assessment) and, where applicable, the FRIA (Fundamental Rights Impact Assessment) required by the AI Act.
Contact the DPO at the certified email (PEC) DPO@pec.qualityandsafety.org or download the request form in the Documents section.