Data Processing Agreement (DPA)

A Data Processing Agreement is a legally binding contract declaring how your data will be used by us (Cyber Legion) and our portal (Cyber Legion) and by any third parties we might rely on for services including but not limited to email, web hosting, storage, and data analytics.
Want to know more? Fill out our data request form to request and sign an electronic DPA.
Our Data Protection Officer
Contact us.

What is the GDPR?

The GDPR or the “General Data Protection Regulation” is a regulation designed to ensure the appropriate protection of personal data in a digital society. It encompasses how, why, and when your data may be used online, the security standards organizations must utilize to protect that data, and penalties for non-compliance.
The GDPR replaces the Data Protection Direction, and like its predecessor, is based on Article 8(1) of the Charter of Fundamental Rights of the European Union, echoing Article 12 of the Universal Declaration on Human Rights, which was first adopted by the UN General Assembly in 1948. It also echoes the Article 16(1) of the Treaty of the Functioning European Union, pursuant to which “everyone has the right to protection of personal data”. The GDPR includes changes to account for digital privacy rights relating to email, digital marketing, encryption and data security, right to be informed/forgotten, and much more. Read the full text of the GDPR here.
The GDPR was first adopted in 2016 and became enforceable by law throughout the EU in May of 2018. It affects all organizations working with, controlling, storing, analysing or implementing Personal Data. Cyber Legion and its third-party organizations are affected by the GDPR.

What are Cyber Legion’s Responsibilities Under the GDPR?

The GDPR requires that Cyber Legion take precautions to protect personal data in every way. This includes but is not limited to ensuring that data is:
• Processed lawfully, fairly, and in a transparent manner
• Collected for specific, explicated, and legitimate purposes and not further processed or controlled in manners incompatible with those purposes. Furthermore, this data must be adequate, relevant, and limited to what is necessary for achieving those purposes.
• Accurate and kept up to date
• Stored securely to prevent accidental loss, destruction, or damage and kept no longer than is necessary to achieve the purpose for which it is collected
Documentation and Compliance – Cyber Legion is also responsible for documenting all data processing activities. We are required to demonstrate our compliance with the above principles in regular GDPR audits. GDPR necessitates implementing data protection by design when developing our processes, products, and systems.
Third-Parties – The GDPR states that Cyber Legion is responsible for negotiating GDPR compliance on behalf of our customers when contracting third-party services. This ensures client protection, even when we utilize third-party services like AWS, GCP, Microsoft Azure, Linode etc.
International Data Transfer – Under the GDPR, Cyber Legion may not transfer any Private Data outside the UK, EU unless the UK, EU Commission has deemed that country to have adequate data processing regulations. Exceptions can be made in the case of using alternative safeguards such as the UK, EU-US Privacy Shield and standard contractual clauses.

What Does “Personal Data” Mean Under the GDPR?

Personal Data, referred to by various terms throughout our website and terms, refers to:
“Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;”
This data may encompass IP addresses, device IDs, phone numbers, and other information, even when it is subject to change. In any case where information can be used to identify any persona aspect of the user, including physical location, it is considered Private Data.

Your GDPR Rights

Under the GDPR, you have the right to access personal data collected by Cyber Legion and Cyber Legion. Send us a request at “Contact us” and we will provide any data we have stored. We can also transfer a copy of stored data to you with the purpose of you sending it to another processor or controller.
Should you feel this data is incorrect or wish to have it removed, you can submit a correction request. We will process needed changes at our earliest convenience and will notify our data compliance officer in case you are not our customer. Data will be changed or removed from our servers no later than 30 business days following the request. You may also request a restriction of personal processing.

CREST Approved Penetration Testing Services

Secure your business with top-tier expert knowledge and advanced Penetration Testing (CREST Approved)

Let's collaborate to build and maintain secure businesses

Cyber Legion convert threats into trust by leveraging Advanced Technology and Expertise in Product Security and Business Continuity. Our approach integrates Secure by Design, comprehensive Security Assurance, Red Teaming, Adversary Emulation and Threat Intelligence, Penetration Testing, and Expert Security Advisory and Consultancy. We ensure compliance with meticulous security assurance and detailed documentation, from design to post-market.

As a CREST-certified Penetration Testing provider in the EMEA region, we are committed to the highest security standards.Cyber Legion - CREST Approved