The GDPR defines “personal data” as any information that can be used to directly or indirectly identify a person, such as a name, unique identifier, photograph, email address, or IP address.
The GDPR imposes the following principles-based requirements:
Organisations are assigned the role of data controller or data processor. Many organisations will qualify as both, depending on the relationship of the parties and specific data processing activities. This is how Zileo views those roles and associated responsibilities:
A “data controller” is the party that alone or jointly with others determines the purposes and means of the processing of personal data, and processes the personal data for its own purposes. While using Zileo to source candidates and/or clients, users (“you”) are the data controller because you determine the purpose (e.g. finding prospect clients) and the means (using Zileo) of processing the personal data. Separately, Zileo is a data controller for the personal data associated with your Zileo account (e.g. your business contact information) because we control the means and purposes of this processing for our use: invoicing, to communicate information about your account and for other administrative functions.