The Top 10 Things We’re Doing at TeleSign to Comply With the GDPR

The right to privacy is included as a fundamental right in the EU Charter.
The GDPR’s sanctions-based regime was created to protect that right, and TeleSign firmly believes that full compliance with the GDPR benefits all global citizens, especially our customers.
The GDPR, as a legal framework for data processing and free movement of personal data in the EU (with allowances for data transfers outside the EU), will promote accountability and establish trust in the digital economy. At TeleSign, we believe that your trust in our conduct as a responsible corporate citizen is fundamental to the success of our business.
TeleSign is owned by BICS (a subsidiary of Proximus Group) which is headquartered in Brussels, Belgium – the beating heart of the European Union and the location of all her major institutions. That proximity to the epicenter of privacy rights, which will be enshrined by the GDPR, shines a spotlight on TeleSign’s role as a caretaker of privacy rights of all individuals, not just ones based in the EU. In short, privacy and the GDPR are in our DNA – there is no patch or fix for compliance, it has to be (and will be) embedded in everything that we do in service to our customers.
The personal data that TeleSign holds on behalf of our customers belongs to the individuals themselves. The personal data is theirs, not ours. Those individuals have the right to control how their personal data is processed.
In the delivery of our products and services, we can and do only use this personal data for approved purposes. The owners of the data have given us permission (consent) to use their data for purposes that have been transparently disclosed to them. In short, the individual is giving us a restricted license to use his/her personal data.
TeleSign will not abuse that restricted license, or in any way compromise the trust given to us by our customers. We understand we have earned this trust by how we handle your personal data, and we will steadfastly maintain it by complying with the GDPR.
The full, global TeleSign team has been engaged to ensure that all elements of the GDPR are adhered to. Here are 10 of the top things we’re doing to comply.
We are now (and have been since October 31, 2017) owned by BICS (a subsidiary of Proximus Group), which is based within the EU in Brussels, Belgium. All members of senior management from Proximus to BICS and TeleSign are fully supportive of our efforts towards complete GDPR compliance by May 25, 2018. TeleSign firmly believes that the privacy and security of personal data is fundamental to our business operations. Data protection is taken very seriously by all TeleSign employees.
We have laid out a 6-phase compliance roadmap that will get us to GDPR compliance by the May 25 deadline: (1) Training/Awareness for the entire company; (2) Data Mapping; (3) Gap Analysis; (4) Data Protection Impact Assessments (DPIA); (5) Implementation (our current phase); and (6) Steady State (aka long-term compliance post deadline).
This is a big one for us. Privacy cannot exist without security, which is why we are committed to protecting personal data through the use of appropriate security measures. We keep detailed records of all processing of personal data that occurs so we can ensure adequate security throughout the data protection lifecycle. We have established a Privacy Office (PO) (see #10 below) to ensure continuous and long-term compliance with the GDPR.


