Recertification: 09/2018
People Intouch B.V. provides the IT-based service “SpeakUp® System”. SpeakUp® is a whistleblowing system that enables client company officers to communicate directly – by telephone or the Internet – with messengers (employees and other associates) who want to report a grievance. Customers of People Intouch using the service are provided with meaningful information on how to make use of SpeakUp® in compliance with EU data protection law. Customers who adhere to the guidance provided by People Intouch can be sure that processing of personal data by means of the SpeakUp® Service is in line with EU data protection law.
Product/Version
SpeakUp® System
Function as provided in August 2018
Qualification: IT-based service (“processor service”)
Cert. No.
EP-S-WK25S6
Version of Certification Criteria
Gültigkeit
06/09/2018 – 30/09/2020
Initial Certification on 07/07/2017
Monitoring
05/2019 (O.K.)
01/2020 (O.K.)
Kurzgutachten
Recertification No. 1 2018/09: SpeakUpSystem Short Public Report [PDF]
Initial certification 2017: SpeakUp System Short Public Report [PDF]
Manufacturer/Provider
People Intouch B.V.
Olympisch Stadion 41
1076 DE Amsterdam
The Netherlands
BEST
Customers of People Intouch who make use of the SpeakUp® System are informed about relevant data protection issues by means of a specific information leaflet. They are also provided with a sample “SpeakUp Policy” and a document which may be used to introduce SpeakUp® to customers’ employees. These documents facilitate the privacy-compliant use of the SpeakUp® System in general and compliance with the duty to inform data subjects in particular.
ATTENTION
SpeakUp® System facilitates its privacy-compliant use. However, responsibility for the processing of personal data by means of SpeakUp® lies with the customer (user) of the service who qualifies as a controller whereas People Intouch B.V. acts as a processor on behalf of the customer.
SUMMARY
The SpeakUp® System is a whistleblowing system. It enables dedicated client company officers to communicate directly – by telephone or the Internet – with messengers (employees and other associates). Messengers may choose to reveal their identity or to remain anonymous or pseudonymous. Customers of People Intouch can provide a phone number and/or a hyperlink to the SpeakUp® System on their websites. Messengers may use the system to report grievances (e.g., criminal activities such as fraud or embezzlement). The SpeakUp® System facilitates a dialogue between messengers and company officers (e.g., compliance officers or corruption agents). A dedicated case management module supports the receiving and handling of the messages by client company officers.
DETAILS
Recertification 09/2018:
The recertification took place on the basis of v201701 of the EuroPriSe criteria catalogue for IT products and IT-based services. The ToE changed slightly (in comparison with the previous recertification). For details, please cf. at No. 11 of the short public report.
Initial Certification 07/2017:
Customers of People Intouch (PIT) are controllers of the processing of personal data that results from the use of the SpeakUp® System. People Intouch B.V. qualifies as a processor on behalf of its customers. When providing the service, PIT relies on transcription and translation services of dedicated translation agencies acting as sub-processors.
SpeakUp® is a free text system which means that it is up to the messengers to decide which (personal) data they submit or record to the system. People Intouch provides customers with a document that is addressed to messengers and informs them about privacy relevant aspects of the SpeakUp® System. In this document, messengers are advised (i.a.) to only submit or record personal data if and when this is necessary for the proper description of the grievance at hand and to dispense with the submission or recording of sensitive personal data.
It is worth noting that People Intouch and the commissioned translation agencies have access to clear text data. However, they cannot access the case management module to be used by client company officers. To protect messengers’ anonymity, both voice files as such and meta data (e.g., phone numbers or IP addresses) are never handed over to customers of PIT. This is explicitly stipulated in a clause of the sample contract to be concluded between People Intouch and each customer and is an important exception from PIT’s general obligation to act only on instructions from the customer.
Target of Evaluation (ToE) is the standard set-up of the processor service “SpeakUp® System” (function as provided in July 2017). The ToE includes:
- Web(-based) System
- Phone System
- Transcription and translation services (performed by dedicated translation agencies)
- Quality checks (performed by dedicated staff of PIT)
- Case management module
The ToE does not include special customizations for and the implementation and use of the service by customers of People Intouch.
Technical and Legal Evaluator
Johan Dahlsjö
JP Advokatfirma i Göteborg AB
Götabergsgatan 20
41134 Göteborg
Sweden
Formerly Certified Versions
N/A