Fiabilis Consulting Group
About FCG - Data Protection

Our data protection initiatives and commitments

Fiabilis does everything possible to guarantee the protection of your data - relying in particular on a global information security management system (ISMS) certified ISO/IEC 27001 by an independent auditor. But that's not all.

Two colleagues sketching an idea on a whiteboard in the office
Data Protection

What does the ISO/IEC 27001 standard involve?

Fiabilis Consulting Group is committed to a data protection process. ISO 27001 certification confirms our ability to protect all data and information essential to our analyses.

We provide our clients, partners and employees with complete security of their data through the implementation, updating and maintenance of an integrated global information security management system (ISMS).

The certification demonstrates Fiabilis's ability to assess its capacity to address all categories of risk present, whether posed by infrastructure, people or processes.

ISO 27701

The ISO 27701 standard, a complement to ISO/IEC 27001

In addition to the ISO 27001 standard, Fiabilis obtained ISO 27701 certification in 2022. This international certification standard extends the scope of the 27001 standard to the governance and security measures to be implemented to protect personal data. It takes into account the main applicable texts on personal data protection, and in particular the GDPR.

This standard allows us, in particular, to demonstrate - in accordance with the accountability principle - that our internal practices regarding the processing of personal data are aligned with the basic principles set out by the GDPR: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality.

Certification

External control and renewal of ISO certifications

In-depth audits are carried out each year by Aenor. Every three years, certifications are re-examined and renewed following a strict compliance review.

Our Initiatives

An overview of the initiatives taken to protect your data

HR

  • Signing of an IT Charter and confidentiality commitment.
  • Regular training, awareness sessions and assessments of information security knowledge.

Physical Security

  • Direct supervision of visitors by a Fiabilis staff member for the entire duration of the visit.
  • Controls and restricted access to premises.

Asset Management

  • Automated and decentralized asset inventory management.
  • Management policy, tracking and disposal of entrusted assets throughout their lifecycle.
  • Device security policy (automatic locking, password complexity and rotation, real-time malware protection, firewall, disk encryption, software installation restrictions, automatic updates).
  • Centralized access rights management policy with regular independent reviews.
  • Supplier and procurement management policy, mandatory confidentiality commitment, annual security audit.
  • Development control policy, code auditing and vulnerability testing.
  • All of our assets fall under the management of our ISO 27001-certified ISMS.

Data

  • Appointment, in each country, of a personal data protection specialist to monitor compliance with the GDPR and other privacy laws (DPO or Privacy Champion).
  • Hosting of all client and internal data on our own internal infrastructure.
  • Strict file exchange and sharing policy using our own internally hosted tools.
  • Pseudonymization of data as soon as it is downloaded from the Social Security website.
  • No transfer of sensitive data to any subcontractor.
  • Mandatory user authentication via login and password, with mandatory two-factor authentication (MFA) for remote access (VPN).
  • Centralized archiving of data access logs.
  • Strict data lifecycle in accordance with current regulations (GDPR) and local recommendations (ISO 27001 and ISO 27701).
  • Backup policy clearly defining the encryption and storage location of data internally and at a secure external site.

Hosting and Networks

  • The entire infrastructure is hosted locally in our own physical offices.
  • Fiabilis has various internal networks allowing for fine-grained access management and separation of environments.
  • Access to data, reserved for Fiabilis staff, is only possible via a local physical connection or via VPN protected by two-factor authentication (MFA).

Security Audit

  • Each year, in accordance with our ISO 27001 certification, the independent body Aenor audits, controls and certifies our ISMS, in addition to controlling our PIMS under ISO 27701.
  • An internal audit plan ensures the consistency of the PDCA (Plan, Do, Check, Act) cycle essential across all our processes.
  • Each year, 3 internal penetration tests are carried out by internal IT teams, supplemented by 1 external and independent penetration test and vulnerability scan.
FAQ

Data protection compliance

Fiabilis generally processes its clients' personal data as a data processor. Before launching an analysis, we sign an appropriate Data Processing Agreement (DPA) with each client. This agreement precisely defines the principles under which data processing will take place, as well as our obligations during this process, in accordance with Article 28 of the GDPR.
We have created a secure, individual data exchange platform for each client, through which the client can send their data directly to our server. The client can also opt for a data transfer method of their choice, such as via a dedicated internal infrastructure provided by them.
Your data is stored and processed exclusively on our secure servers in Europe. In accordance with the terms of the DPA, it is retained for the agreed period and then permanently deleted after that period.
Contact our DPO

Questions about our data protection policy?

Our Data Protection Officer (DPO) is at your complete disposal.

About you
Please enter your last name
Please enter your first name
Please enter a valid e-mail address
Please enter a valid phone number
Your organisation
Please enter your company
Your message
Please enter your message

Privacy Policy

Please accept the data processing consent

Thank you!

Your message has been sent. Our DPO will get back to you as soon as possible.

Contact us