Frequently asked questions about the General Data Protection Regulation (GDPR)
These questions and answers have been prepared in cooperation with DHK Rechtsanwälte (attorneys-at-law). It does not constitute legal advice and does not substitute for legal advice. The answers given to the present questions solely serve as an orientation.
Is there a GDPR declaration for Rohde & Schwarz Networks and Cybersecurity products?
R&S Networks and Cybersecurity products comply with all requirements necessary for their legal operation. This applies to all aspects in relation to security and data protection. Since the new data protection regulation applies to processes, not products, we cannot supply you with an expressive declaration of conformity.
Is data stored by R&S Networks and Cybersecurity devices which are relevant to the GDPR?
The basic settings of Rohde & Schwarz Networks and Cybersecurity hardware provide for data storage (e.g. IP-addresses, data volume). This is based on technical grounds and, according to our assessment, complies with the provision of data-friendly technology design, as stipulated in Art. 25 GDPR.
Which data is stored and what does the provider need to know when operating these devices in a GDPR-conform way?
The basic settings of Rohde & Schwarz Networks and Cybersecurity hardware provide for data storage (e.g. IP-addresses, data volume). In part, the client can modify these settings. In addition, storage is not indefinite and the data can be deleted at any time. Therefore, Rohde & Schwarz Networks and Cybersecurity hardware enables operation that fully adheres to the GDPR.
Does the GDPR have consequences for the use of the R&S®LANCOM Security Essentials Option? If so, what are the implications?
No, we do not see any implications here: the function of the external web filter are integrated in the selected basic settings as an optional function into the router. The client can adjust the filter to his or her individual needs. These settings block the respectively defined websites/contents. In…
Does the GDPR have consequences for the operation of Wi-Fi hotspots?
There are no relevant changes with the coming into effect of the GDPR: the operation of a Wi-Fi hotspot and especially the question which user data will be collected has repeatedly been subject matter of legal disputes for the past years. The point in question was and still is the weighting of the…
What does this mean for me as user of the R&S®LANCOM Public Spot?
Rohde & Schwarz Networks and Cybersecurity supplies providers of hotspots with sample user terms of use for public spot solutions in order to enable the legal use of hotspots. However, providers are not under any obligation to use these terms of use. The hotspot providers are responsible for the relationship to their users and may create their own terms of use.
Are cloud based network management solutions such as the R&S®LANCOM Management Cloud subject to the GDPR?
As with all processes in which personal data is processed – for example including IP-addresses and Mac-addresses which are collected and used in the context of network management – the network management in the cloud generally is subject to the GDPR.
What measures has Rohde & Schwarz Networks and Cybersecurity taken to guarantee the GDPR-conform use of the R&S®LMC (in the Public Cloud)?
Rohde & Schwarz Networks and Cybersecurity works with a cloud provider that operates its infrastructure exclusively in Germany. This ensures that the technical and administrative requirements, which the new regulations also demand for the protection of the R&S®LMC users, can be fully met. Providers…
Is the processing of the R&S®LANCOM Management Cloud done by a third party on behalf of Rohde & Schwarz Networks and Cybersecurity?
This depends of the selected user model. If a provider orders a system house to administrate its network infrastructure over the public version of the R&S®LANCOM Management Cloud, this constitutes a third party data processing contract between the system house and Rohde & Schwarz Networks and…