{"id":18882,"date":"2024-06-05T09:11:33","date_gmt":"2024-06-05T09:11:33","guid":{"rendered":"https:\/\/www.amoconsultancy.com\/amo-consultancy-pii-policy\/"},"modified":"2024-06-21T14:08:45","modified_gmt":"2024-06-21T14:08:45","slug":"amo-consultancy-pii-policy","status":"publish","type":"page","link":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/","title":{"rendered":"AMO Consultancy PII Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"18882\" class=\"elementor elementor-18882 elementor-18148\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-afd8df4 e-flex e-con-boxed e-con e-parent\" data-id=\"afd8df4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-7210f61 e-con-full e-flex e-con e-child\" data-id=\"7210f61\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8e3b78a elementor-widget elementor-widget-heading\" data-id=\"8e3b78a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Politique des Informations Personnellement Identifiables (IPI) de ISPMS<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-997b92c elementor-widget elementor-widget-text-editor\" data-id=\"997b92c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Derni\u00e8re mise \u00e0 jour : <em>04\/06\/2024<\/em><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-022df42 elementor-widget elementor-widget-text-editor\" data-id=\"022df42\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2><strong>Introduction<\/strong><\/h2>\n<p><a name=\"_Toc168342406\"><\/a>L&rsquo;Organisation doit collecter et utiliser certains types d&rsquo;informations sur le personnel, les clients et d&rsquo;autres individus qui entrent en contact avec l&rsquo;entreprise afin de fonctionner. De plus, il peut \u00eatre n\u00e9cessaire de collecter et d&rsquo;utiliser certains types d&rsquo;informations pour se conformer aux obligations l\u00e9gales des autorit\u00e9s locales, des agences gouvernementales et d&rsquo;autres organismes.<\/p>\n<p>Ces informations personnellement identifiables (appel\u00e9es IPI) doivent \u00eatre trait\u00e9es correctement, qu&rsquo;elles soient collect\u00e9es, enregistr\u00e9es et utilis\u00e9es \u2013 que ce soit sur papier, dans un ordinateur, ou enregistr\u00e9es sur un autre support \u2013 et des mesures de protection sont en place pour garantir leur conformit\u00e9 au R\u00e8glement G\u00e9n\u00e9ral sur la Protection des Donn\u00e9es de l&rsquo;UE et \u00e0 la Loi sur la Protection des Donn\u00e9es de 2018.<\/p>\n<p>Nous consid\u00e9rons le traitement l\u00e9gal et correct des IPI comme tr\u00e8s important pour le bon fonctionnement de nos op\u00e9rations et pour maintenir la confiance entre les personnes avec lesquelles nous interagissons et nous-m\u00eames. Nous veillons \u00e0 ce que notre organisation traite les informations personnelles de mani\u00e8re l\u00e9gale et correcte. Cette politique des IPI est destin\u00e9e \u00e0 \u00eatre utilis\u00e9e en conjonction avec le syst\u00e8me de gestion de la s\u00e9curit\u00e9 de l&rsquo;information ISO 27001 \u00e9tabli par l&rsquo;organisation (y compris la politique de protection des donn\u00e9es). Il est donc pr\u00e9sum\u00e9 que les exigences du SGSI (Syst\u00e8me de Gestion de la S\u00e9curit\u00e9 de l&rsquo;Information) ont d\u00e9j\u00e0 \u00e9t\u00e9 d\u00e9finies et mises en \u0153uvre.<\/p>\n<p>La politique des IPI fait partie de l&rsquo;ensemble des politiques du SGSI de l&rsquo;organisation et n&rsquo;est pas destin\u00e9e \u00e0 \u00eatre utilis\u00e9e de mani\u00e8re ind\u00e9pendante. L&rsquo;Organisation confirme son soutien et son engagement \u00e0 se conformer \u00e0 la l\u00e9gislation et\/ou aux r\u00e9glementations applicables en mati\u00e8re de protection des IPI ainsi qu&rsquo;aux termes contractuels convenus entre l&rsquo;Organisation et ses partenaires, ses sous-traitants et ses tiers concern\u00e9s (clients, fournisseurs, etc.), lesquels doivent clairement attribuer les responsabilit\u00e9s entre eux.<\/p>\n<h2><strong>Termes et D\u00e9finitions<\/strong><a name=\"_Toc168342407\"><\/a><\/h2>\n<h4><strong>Informations Personnellement Identifiables (IPI)<\/strong><\/h4>\n<p>Toute information qui (a) peut \u00eatre utilis\u00e9e pour identifier la personne concern\u00e9e \u00e0 laquelle ces informations se rapportent, ou (b) est ou pourrait \u00eatre directement ou indirectement li\u00e9e \u00e0 une personne concern\u00e9e.<\/p>\n<h4><strong>Personne Concern\u00e9e par les IPI<\/strong><\/h4>\n<p>Personne physique \u00e0 laquelle les informations personnellement identifiables (IPI) se rapportent.<\/p>\n<h4><strong>Responsable du Traitement des Donn\u00e9es<\/strong><\/h4>\n<p>A person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any PII are or are to be processed.<\/p>\n<h4><strong>Data Processor<\/strong><\/h4>\n<p>In relation to PII, means any person (other than an employee of the data controller, and either alone or jointly or in common with other persons) who processes the data on behalf of the Data Controller.<\/p>\n<\/p>\n<h2><strong>Responsibilities<\/strong><\/h2>\n<p>This policy relates to all information that is dealt with by all employees and may include contractors, sub-contractors and other third parties who have access to information as a result of being connected in any way to the Organisation network, applications, systems and data.<\/p>\n<p>If you are not sure about any aspect of this Policy, please contact the ISMS Manager.<\/p>\n<h2><strong>Objectives<\/strong><\/h2>\n<p>The Organisation needs to collect and use information about staff, clients and other individuals who come into contact with the company. In addition, it may be required by law to collect and use information to comply with statutory obligations of Local Authorities, government agencies and other bodies.<\/p>\n<p>We view the lawful and correct treatment of PII as very important to successful operations and to maintaining confidence between those with whom we deal and ourselves. Our primary objective is to ensure that our Organisation treats personal information lawfully and correctly.<\/p>\n<p>In addition, the Organisation aims to ensure that information is dealt with in accordance with the EU General Data Protection Regulation and the Data Protection Act 2018.<\/p>\n<h2><strong>PII Policies &amp; Procedures<\/strong><\/h2>\n<h4><strong>Data Controller or Data Processor?<\/strong><\/h4>\n<p>In its contractual relationships with customers, the Organisation first establishes whether it is a Data Controller or Data Processor. The roles may not be the same across all contracts, so, where the Organisation acts in both roles (e.g. a PII controller and a PII processor), separate roles are determined, each of which is the subject of a separate set of controls. Please see \u2018Key Definitions\u2019 above to facilitate this determination of role.<\/p>\n<h4><strong>PII Risk Assessment<\/strong><\/h4>\n<p>ISO 27001 risk assessment processes are applied to PII in order to identify risks associated with the loss of confidentiality, integrity and availability. GDPR privacy risk assessment processes are applied in order to identify risks related to the processing of PII.<\/p>\n<h4><strong>PII Point of Contact<\/strong><\/h4>\n<p>Mr Bertrand Piquet has been appointed to fulfil the following responsibilities:<\/p>\n<ul>\n<li>Be independent and report directly to the Board of Directors in order to ensure effective management of privacy risks<\/li>\n<li>Be involved in the management of all issues which relate to the processing of PII<\/li>\n<li>Be expert in data protection legislation, regulation and practice<\/li>\n<li>Act as a contact point for supervisory authorities<\/li>\n<li>Inform top-level management and employees of the Organisation of their obligations with respect to the processing of PII<\/li>\n<li>Provide advice in respect of privacy impact assessments conducted by the Organisation.<\/li>\n<\/ul>\n<h4><strong>Device applicability<\/strong><\/h4>\n<p>No distinction is made between different types of device or physical media on which PII may reside.<\/p>\n<h4><strong>PII Awareness<\/strong><\/h4>\n<p>Measures are in place, including awareness of incident reporting, to ensure that relevant staff are aware of the possible consequences to the Organisation, to the staff member and to the PII Principal of breaching privacy or security rules and procedures, especially those addressing the handling of PII.<\/p>\n<h4><strong>PII Classification<\/strong><\/h4>\n<p>The Organisation&rsquo;s information classification system explicitly considers PII as part of the scheme it implements. Considering PII within the overall classification system is integral to understanding what PII the Organisation processes (e.g. type, special categories), where such PII is stored and the systems through which it can flow.<\/p>\n<h4><strong>PII Stored on Removable Media<\/strong><\/h4>\n<p>It is the policy of the Organisation to not use removable media for any purpose.<\/p>\n<h4><strong>PII Stored on Physical Media<\/strong><\/h4>\n<p>It is the policy of the Organisation to not use physical media for any significant purpose.<\/p>\n<h4><strong>User Registration and De-registration<\/strong><\/h4>\n<p>The ISPMS Manager must be informed immediately if user access control for users who administer or operate systems and services that process PII has been compromised, such as the accidental or deliberate release of passwords. De-activated or expired user IDs for systems and services that process PII must never be reissued.<\/p>\n<p>In pre-defined cases where PII processing is being provided as a service, it is permissible for the customer to be responsible for some or all aspects of user ID management. Such cases must be included in the documented information.<\/p>\n<p>No authentication credentials related to systems that process PII are to remain unused. Regular checks are to be made to ensure that no unused credentials exist.<\/p>\n<h4><strong>PII User Access Provisioning<\/strong><\/h4>\n<p>The Organisation maintains an accurate, up-to-date record of the user profiles created for users who have authorised access to the information systems and the PII contained in them. This profile comprises the set of data about that user, including user ID, necessary to implement the identified technical controls providing authorised access.<\/p>\n<p>Implementing individual user access IDs enables appropriately configured systems to identify who accessed PII and what additions, deletions or changes they made. As well as protecting the Organisation, users are also protected as they can identify what they have processed and what they have not processed. In the case where the Organisation is providing PII processing as a service, the customer can be responsible for some or all aspects of access management. Where appropriate, the Organisation should provide the customer the means to perform access management, such as by providing administrative rights to manage or terminate access. Such cases should be included in the documented information.<\/p>\n<h4><strong>Cryptography<\/strong><\/h4>\n<p>Some jurisdictions can require the use of cryptography to protect particular kinds of PII, such as health data, resident registration numbers, passport numbers and drivers\u2019 licence numbers.<\/p>\n<p>The Organisation provides information to the customer regarding the circumstances in which it uses cryptography to protect the PII it processes. The Organisation also provides information to the customer about any capabilities it provides that can assist the customer in applying their own cryptographic protection.<\/p>\n<h4><strong>Secure Disposal or Re-use of Equipment<\/strong><\/h4>\n<p>The Organisation ensures that, whenever storage space is re-assigned, any PII previously residing on that storage space is not accessible.<\/p>\n<p>On deletion of PII held in an information system, performance issues can mean that explicit erasure of that PII is impractical. This creates the risk that another user can access the PII. Such risks are avoided by specific technical measures.<\/p>\n<p>For secure disposal or re-use, equipment containing storage media that can possibly contain PII is treated as though it does contain PII.<\/p>\n<p>Note: The equipment hard disk drive is typically securely erased before equipment disposal.<\/p>\n<h4><strong>Information Backup<\/strong><\/h4>\n<p>The Organisation\u2019s information is backed up in accordance with the Backup Policy. Particular care is taken when backing up PII, ensuring that such backups are maintained in an encrypted environment.<\/p>\n<p>The Organisation ensures that the customer has been informed of the limits of the service regarding backup.<\/p>\n<p>Specific requirements regarding the frequency of backups of PII, the frequency of reviews and tests of backup, or regarding the recovery procedures for PII may be legally or organisationally defined. If applicable, the Backup Policy defines how the Organisation demonstrates compliance with these requirements.<\/p>\n<p>Whenever PII needs to be restored, processes are in place to ensure that the PII is restored into a state where the integrity of PII can be assured, and\/or where PII inaccuracy and\/or incompleteness is identified, and processes put in place to resolve them.<\/p>\n<p>The Organisation has a procedure for, and a log of, PII restoration efforts. As a minimum, the log contains:<\/p>\n<ul>\n<li>The name of the person responsible for the restoration<\/li>\n<li>A description of the restored<\/li>\n<\/ul>\n<p>Specific requirements regarding content of the logs of PII restoration efforts may be legally or organisationally defined. If applicable, the Backup Policy defines how the Organisation documents compliance with these requirements for restoration log content, along with the conclusions of any associated discussions.<\/p>\n<h4><strong>Event Logging<\/strong><\/h4>\n<p>Where possible, event logs record access to PII, including by whom, when, which PII principal&rsquo;s PII was accessed, and what (if any) changes were made (additions, modifications or deletions) as a result of the event.<\/p>\n<p>Where multiple service providers are involved in providing services, there can be varied or shared roles in implementing this guidance. These roles are clearly defined and included in the documented information, and agreement on any log access between providers is addressed.<\/p>\n<h5><strong>Implementation guidance for when the Organisation acts as a PII Processor:<\/strong><\/h5>\n<p>The Organisation defines criteria regarding if, when and how log information can be made available to or usable by the customer. These criteria are made available to the customer.<\/p>\n<p>Where the Organisation permits its customers to access log records controlled by the Organisation, the Organisation implements appropriate controls to ensure that:<\/p>\n<ul>\n<li>The customer can only access records that relate to that customer\u2019s activities<\/li>\n<li>Cannot access any log records which relate to the activities of other customers<\/li>\n<li>Cannot amend the logs in any<\/li>\n<\/ul>\n<h5><strong>Protection of Log Information<\/strong><\/h5>\n<p>Log information is held where possible as a system record with access restricted to those with appropriate administrator authorisation.<\/p>\n<h2><strong>Information Transfer Policies &amp; Procedures<\/strong><\/h2>\n<p>The Organisation considers procedures on a case-by-case basis for ensuring that rules related to the processing of PII are enforced throughout and outside of the system, where applicable.<\/p>\n<h4><strong>Confidentiality or non-disclosure agreements<\/strong><\/h4>\n<p>The Organisation ensures that individuals operating under its control with access to PII are subject to a confidentiality obligation. The confidentiality agreement, whether part of a contract or separate, specifies the length of time the obligations should be adhered to.<\/p>\n<p>When the Organisation acts as a PII processor, a confidentiality agreement, in whatever form, between the Organisation, its employees and its agents ensure that employees and agents comply with the policy and procedures concerning data handling and protection.<\/p>\n<h4><strong>Securing Application Services on Public Networks<\/strong><\/h4>\n<p>The Organisation ensures that PII which is transmitted over untrusted data transmission networks is encrypted for transmission.<\/p>\n<p>Untrusted networks can include the public internet and other facilities outside of the operational control of the Organisation.<\/p>\n<h4><strong>Secure Systems Development<\/strong><\/h4>\n<p>Systems and\/or components related to the processing of PII are designed following the principles of privacy by design and privacy by default, and to anticipate and facilitate the implementation of relevant controls for PII controllers and PII processors respectively, in particular such that the collection and processing of PII in those systems are limited to what is necessary for the identified purposes of the processing of PII.<\/p>\n<p>For example, an organisation that processes PII should ensure that it disposes of PII after a specified period. The system that processes PII should be designed in a way to facilitate this deletion requirement.<\/p>\n<p>The Secure Development Policy has considered the following aspects and includes appropriate requirements where deemed necessary:<\/p>\n<ul>\n<li>Guidance on PII protection and the implementation of the privacy principles (see ISO\/IEC 29100) in the software development lifecycle<\/li>\n<li>Privacy and PII protection requirements in the design phase, which can be based on the output from a privacy risk assessment and\/or a privacy impact assessment<\/li>\n<li>PII protection checkpoints within project milestones<\/li>\n<li>Required privacy and PII protection knowledge<\/li>\n<li>By default, minimise processing of PII<\/li>\n<li>By default, the collection of information must be limited to what is necessary for the identified purposes of the processing of PII.<\/li>\n<li>Systems and\/or components related to the processing of PII must be designed in accordance with the principles of privacy by design and privacy by default.<\/li>\n<li>Outsourced systems and\/or components related to the processing of PII must be designed in accordance with the principles of privacy by design and privacy by<\/li>\n<\/ul>\n<p>If outsourced development is utilised, then the following is considered:<\/p>\n<ul>\n<li>Developer contracts<\/li>\n<li>Developer compliance with Organisation development methods and source code control<\/li>\n<li>Monitoring methods used for control and associated<\/li>\n<\/ul>\n<h4><strong>Protection of Test Data<\/strong><\/h4>\n<p>If genuine PII is used for testing purposes, a risk assessment must be undertaken and used to inform the selection of appropriate mitigating controls.<\/p>\n<h4><strong>Addressing Security within Supplier Agreements<\/strong><\/h4>\n<p>The Organisation specifies in agreements with suppliers whether PII is processed and the minimum technical and organisational measures that the supplier needs to meet in order for the Organisation to meet its information security and PII protection obligations.<\/p>\n<p>Supplier agreements clearly allocate responsibilities between the Organisation, its partners, its suppliers and its applicable third parties (customers, suppliers, etc.) taking into account the type of PII processed.<\/p>\n<h4><strong>Implementation guidance for when the Organisation acts as a PII Processor:<\/strong><\/h4>\n<p>The organisation should specify in contracts with any suppliers that PII is only processed on its instructions.<\/p>\n<h5><strong>Responsibilities and Procedures<\/strong><\/h5>\n<p>As part of the overall information security incident management process, the Organisation has established responsibilities and procedures for the identification and recording of breaches of PII (documented in the Security Incident Reporting Policy).<\/p>\n<p>Additionally, the Organisation establishes responsibilities and procedures related to notification to required parties of PII breaches (including the timing of such notifications) and the disclosure to authorities, taking into account the applicable legislation and\/or regulation.<\/p>\n<h2><strong>Response to Information Security Incidents<\/strong><\/h2>\n<h4><strong>Implementation guidance for when the Organisation acts as a PII Controller:<\/strong><\/h4>\n<p>An incident involving PII triggers a review by the Organisation, as part of its information security incident management process, to determine if a breach involving PII requires a response.<\/p>\n<p>An event does not necessarily trigger such a review.<\/p>\n<p>N.B. a breach involving PII which could result in a risk to the rights and freedoms of natural persons must be notified to the ICO without undue delay and within 72 hours.<\/p>\n<p>When a breach of PII has occurred, response procedures include relevant notifications and records. Notifications are clear and contain such information as:<\/p>\n<ul>\n<li>A contact point where more information can be obtained<\/li>\n<li>A description of the breach including the number of individuals concerned as well as the number of records concerned<\/li>\n<li>Measures taken or planned to be<\/li>\n<\/ul>\n<p>Where a breach involving PII has occurred, a record is maintained with sufficient information to provide a report for regulatory and\/or forensic purposes, such as:<\/p>\n<ul>\n<li>A description of the incident<\/li>\n<li>The time period<\/li>\n<li>The consequences of the incident<\/li>\n<li>The name of the reporter<\/li>\n<li>To whom the incident was reported<\/li>\n<li>The steps taken to resolve the incident (including the person in charge and the data recovered)<\/li>\n<li>The fact that the incident resulted in unavailability, loss, disclosure or alteration of<\/li>\n<\/ul>\n<p>In the event that a breach involving PII has occurred, the record also includes a description of the PII compromised, if known; and if notifications were performed, the steps taken to notify PII principals, regulatory agencies or customers.<\/p>\n<h4><strong>Implementation guidance for when the Organisation acts as a PII Processor:<\/strong><\/h4>\n<p>Provisions covering the notification of a breach involving PII form part of the contract between the Organisation and the customer. The contract specifies how the Organisation will provide the information necessary for the customer to fulfil their obligation to notify relevant authorities. This notification obligation does not extend to a breach caused by the customer or PII principal or within system components for which they are responsible. The contract also defines expected and externally mandated limits for notification response times.<\/p>\n<p>N.B. a breach involving PII which could result in a risk to the rights and freedoms of natural persons must be notified to the ICO without undue delay and within 72 hours. The PII Controller must also be notified.<\/p>\n<p>Where a breach involving PII has occurred, a record is maintained with sufficient information to provide a report for regulatory and\/or forensic purposes, such as:<\/p>\n<ul>\n<li>A description of the incident<\/li>\n<li>The time period<\/li>\n<li>The consequences of the incident<\/li>\n<li>The name of the reporter<\/li>\n<li>To whom the incident was reported<\/li>\n<li>The steps taken to resolve the incident (including the person in charge and the data recovered)<\/li>\n<li>The fact that the incident resulted in unavailability, loss, disclosure or alteration of<\/li>\n<\/ul>\n<p>In the event that a breach involving PII has occurred, the record also includes a description of the PII compromised, if known and, if notifications were performed, the steps taken to notify the customer and\/or the regulatory agencies.<\/p>\n<h2><strong>Identification of Applicable Legislation and Contractual Requirements<\/strong><\/h2>\n<p>The Organisation identifies any potential legal sanctions (which can result from some obligations being missed) related to the processing of PII, including substantial fines directly from the local supervisory authority.<\/p>\n<p>The contract defines their respective security, privacy and PII protection responsibilities. The terms of the contract may provide a basis for contractual sanctions in the event of a breach of those responsibilities.<\/p>\n<h2><strong>Protection of Records<\/strong><\/h2>\n<p>Review of current and historical policies and procedures may be required (e.g. in the cases of customer dispute resolution and investigation by a supervisory authority).<\/p>\n<p>The Organisation retains copies of its privacy policies and associated procedures for a period as specified in its retention schedule. This includes retention of previous versions of these documents when they are updated.<\/p>\n<h2><strong>Independent Review of Information Security<\/strong><\/h2>\n<p>Where the Organisation is acting as a PII processor, and where individual customer audits are impractical or can increase risks to security, the Organisation makes available to customers, prior to entering into, and for the duration of, a contract, independent evidence that information security is implemented and operated in accordance with the Organisation\u2019s policies and procedures.<\/p>\n<p>Evidence of certification to ISO 27001: 2013 is normally sufficient for this purpose.<\/p>\n<h2><strong>Technical Compliance Review<\/strong><\/h2>\n<p>As part of technical reviews of compliance with security policies and standards, the Organisation includes methods of reviewing those tools and components related to processing PII. These can include:<\/p>\n<ul>\n<li>Ongoing monitoring to verify that only permitted processing is taking place; and\/or<\/li>\n<li>Specific penetration or vulnerability tests (for example, de-identified datasets can be subject to a motivated intruder test to validate that de-identification methods are compliant with organisational requirements).<\/li>\n<\/ul>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d85c729 e-flex e-con-boxed e-con e-parent\" data-id=\"d85c729\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-d0155e9 e-con-full e-flex e-con e-child\" data-id=\"d0155e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4e2eb68 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"4e2eb68\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm elementor-animation-grow\" href=\"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2024\/06\/AMO-Consultancy-PII-Policy.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-download\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M216 0h80c13.3 0 24 10.7 24 24v168h87.7c17.8 0 26.7 21.5 14.1 34.1L269.7 378.3c-7.5 7.5-19.8 7.5-27.3 0L90.1 226.1c-12.6-12.6-3.7-34.1 14.1-34.1H192V24c0-13.3 10.7-24 24-24zm296 376v112c0 13.3-10.7 24-24 24H24c-13.3 0-24-10.7-24-24V376c0-13.3 10.7-24 24-24h146.7l49 49c20.1 20.1 52.5 20.1 72.6 0l49-49H488c13.3 0 24 10.7 24 24zm-124 88c0-11-9-20-20-20s-20 9-20 20 9 20 20 20 20-9 20-20zm64 0c0-11-9-20-20-20s-20 9-20 20 9 20 20 20 20-9 20-20z\"><\/path><\/svg>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download AMO PII Policy<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Politique des Informations Personnellement Identifiables (IPI) de ISPMS Derni\u00e8re mise \u00e0 jour : 04\/06\/2024 Introduction L&rsquo;Organisation doit collecter et utiliser certains types d&rsquo;informations sur le personnel, les clients et d&rsquo;autres individus qui entrent en contact avec l&rsquo;entreprise afin de fonctionner. De plus, il peut \u00eatre n\u00e9cessaire de collecter et d&rsquo;utiliser certains types d&rsquo;informations pour se [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":24885,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-18882","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>AMO Consultancy PII Policy | AMO Consultancy<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AMO Consultancy PII Policy | AMO Consultancy\" \/>\n<meta property=\"og:description\" content=\"Politique des Informations Personnellement Identifiables (IPI) de ISPMS Derni\u00e8re mise \u00e0 jour : 04\/06\/2024 Introduction L&rsquo;Organisation doit collecter et utiliser certains types d&rsquo;informations sur le personnel, les clients et d&rsquo;autres individus qui entrent en contact avec l&rsquo;entreprise afin de fonctionner. De plus, il peut \u00eatre n\u00e9cessaire de collecter et d&rsquo;utiliser certains types d&rsquo;informations pour se [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"AMO Consultancy\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-21T14:08:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2025\/10\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data1\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/\",\"url\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/\",\"name\":\"AMO Consultancy PII Policy | AMO Consultancy\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.amoconsultancy.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg\",\"datePublished\":\"2024-06-05T09:11:33+00:00\",\"dateModified\":\"2024-06-21T14:08:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.amoconsultancy.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg\",\"contentUrl\":\"https:\\\/\\\/www.amoconsultancy.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"AMO Logo and text\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/amo-consultancy-pii-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/solutions-sur-mesure\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AMO Consultancy PII Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#website\",\"url\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/\",\"name\":\"AMO Consultancy\",\"description\":\"Your digital partner bridging strategy, technology, and human experience\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#organization\",\"name\":\"AMO Consultancy\",\"url\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.amoconsultancy.com\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/cropped-Logo-Color-1@4x.png\",\"contentUrl\":\"https:\\\/\\\/www.amoconsultancy.com\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/cropped-Logo-Color-1@4x.png\",\"width\":2752,\"height\":959,\"caption\":\"AMO Consultancy\"},\"image\":{\"@id\":\"https:\\\/\\\/www.amoconsultancy.com\\\/fr\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/amoconsultancy\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"AMO Consultancy PII Policy | AMO Consultancy","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/","og_locale":"fr_FR","og_type":"article","og_title":"AMO Consultancy PII Policy | AMO Consultancy","og_description":"Politique des Informations Personnellement Identifiables (IPI) de ISPMS Derni\u00e8re mise \u00e0 jour : 04\/06\/2024 Introduction L&rsquo;Organisation doit collecter et utiliser certains types d&rsquo;informations sur le personnel, les clients et d&rsquo;autres individus qui entrent en contact avec l&rsquo;entreprise afin de fonctionner. De plus, il peut \u00eatre n\u00e9cessaire de collecter et d&rsquo;utiliser certains types d&rsquo;informations pour se [&hellip;]","og_url":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/","og_site_name":"AMO Consultancy","article_modified_time":"2024-06-21T14:08:45+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2025\/10\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Dur\u00e9e de lecture estim\u00e9e":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/","url":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/","name":"AMO Consultancy PII Policy | AMO Consultancy","isPartOf":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/#primaryimage"},"image":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/#primaryimage"},"thumbnailUrl":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2025\/10\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg","datePublished":"2024-06-05T09:11:33+00:00","dateModified":"2024-06-21T14:08:45+00:00","breadcrumb":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/#primaryimage","url":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2025\/10\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg","contentUrl":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2025\/10\/AMO-MAR-IMAGE-FEATUREIMAGE.jpg","width":1920,"height":1080,"caption":"AMO Logo and text"},{"@type":"BreadcrumbList","@id":"https:\/\/www.amoconsultancy.com\/fr\/amo-consultancy-pii-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.amoconsultancy.com\/fr\/solutions-sur-mesure\/"},{"@type":"ListItem","position":2,"name":"AMO Consultancy PII Policy"}]},{"@type":"WebSite","@id":"https:\/\/www.amoconsultancy.com\/fr\/#website","url":"https:\/\/www.amoconsultancy.com\/fr\/","name":"AMO Consultancy","description":"Your digital partner bridging strategy, technology, and human experience","publisher":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.amoconsultancy.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.amoconsultancy.com\/fr\/#organization","name":"AMO Consultancy","url":"https:\/\/www.amoconsultancy.com\/fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.amoconsultancy.com\/fr\/#\/schema\/logo\/image\/","url":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2022\/10\/cropped-Logo-Color-1@4x.png","contentUrl":"https:\/\/www.amoconsultancy.com\/wp-content\/uploads\/2022\/10\/cropped-Logo-Color-1@4x.png","width":2752,"height":959,"caption":"AMO Consultancy"},"image":{"@id":"https:\/\/www.amoconsultancy.com\/fr\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/amoconsultancy"]}]}},"_links":{"self":[{"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/pages\/18882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/comments?post=18882"}],"version-history":[{"count":1,"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/pages\/18882\/revisions"}],"predecessor-version":[{"id":18883,"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/pages\/18882\/revisions\/18883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/media\/24885"}],"wp:attachment":[{"href":"https:\/\/www.amoconsultancy.com\/fr\/wp-json\/wp\/v2\/media?parent=18882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}