PII and Europe (GPDR reqs)
Content
Hi all ... We have identified one of our OVI vendors stores their data in the UK and does not have a US storage option. As we are not globally deployed, we have elected to avoid offshore data storage of an PII data, thus not having to meet the GPDR requirements that will go into affect May 2018.
What we are considering is limiting the data that goes to the vendor to non-PII data. That will create some potential service/support issues for our candidates along with some analytic development challenges.
Has anyone already gone down this path with a vendor and do you have some lessons learned/insights to share?