Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R14_Compliance-und-Datenschutz.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

5.6 KiB

Policy Compliance and Data Protection

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This policy governs compliance with regulatory/contractual requirements as well as the protection of personal data. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.

2. Scope

This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Requirements and implementation

Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).

3.1 Regulatory and contractual compliance

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 7.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.31, A.5.32, A.5.33{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] Legal, regulatory and contractual requirements relevant to information security are determined regularly.
  • [MUST] Policies for complying with the requirements are defined, implemented and communicated to the responsible persons. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account. {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.31] Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date.
  • [ISO A.5.32] Appropriate procedures to protect intellectual property rights are implemented.
  • [ISO A.5.33] Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release. {{/if}}

Implementation at {{ORG_NAME}}

Relevant legal, regulatory and contractual requirements are determined regularly and recorded in a compliance/legal register in the ISMS tool ({{TOOL_NAME}}); policies for compliance are defined, implemented and communicated to the responsible persons, and the integrity of records is taken into account.

{{#if FLAG_PERSONAL_DATA}}

3.2 Protection of personal data

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 7.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.34{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] Legal and contractual information security requirements for procedures and processes when processing personal data are determined.
  • [MUST] Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.
  • [MUST] Processes and procedures for protecting personal data are taken into account in the information security management system. {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.34] Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations. {{/if}}

Implementation at {{ORG_NAME}}

Legal and contractual requirements for the processing of personal data (GDPR) are determined; provisions are defined, known to those involved and taken into account in the ISMS. {{ROLE_DPO}} is involved, the record of processing activities is maintained in the ISMS tool ({{TOOL_NAME}}), and TOMs and deletion concepts (BL-DEL-01) are regulated; legal register review, deletion periods and data subject rights are processed following the data protection/compliance maintenance procedure ({{LINK:VA-18}}).

{{/if}}

4. Binding nature

This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.

5. Roles and responsibilities

Role Responsibility in this policy
{{ROLE_ISB}} Compliance register
{{ROLE_DPO}} Data protection

6. Review and update

This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.

7. Evidence

The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • Further: {{LINK:L00}}, {{LINK:R03}}