Bloomreach Data Protection Impact Assessment guidelines

When working with Bloomreach, your Data Protection or Security team may request information to complete a Data Protection Impact Assessment or "DPIA". This task is down to you as the collector and controller of the data, but as a privacy-driven provider, we've created this guide to answer questions you may have when carrying out this assessment to work with Bloomreach. You'll find the information divided into several steps outlining the process of completing the DPIA below.

🚧

Not legal advice

These guidelines aren't legal advice and act as a guideline to help assist your completion of DPIA when using Bloomreach as your Processor. The completion of a DPIA is your legal responsibility as a Controller.

If you're looking for more information on Bloomreach security in general, read our security pages.

Identify the need for completing a DPIA

You need to indicate why you've decided to complete a DPIA for working with Bloomreach and for this data processing. At this point, you could refer to why you've begun the process of a DPIA based on your reasons for using Bloomreach as a processor.

Explain the processing

When discussing your processing, you should explain what data is being used, how your customer data is used, why the data is processed, and the overall data flow.

Bloomreach can ingest any data which you provide, including identifiers, properties, and events, and creates actionable customer intelligence. As a result, the specific what, how, and why, and subsequently this section of the DPIA, differs between our clients, depending on their use cases. Remember that the core aim of completing a DPIA is to illustrate how personal data will move between tools and persons.

What data is being used in our data processing?

The answer to this question will be different for each of our clients' campaigns, but could include:

  • Personal data about your customers (such as email, full name, address).
  • Customer browsing behavior and information collected through our Bloomreach cookie (such as clicks, time on page, referrer).
  • Any other information you collect and choose to process via Bloomreach.

Mention whether you're processing any high-risk (for example, health) data or minors' data.

How is the data being used?

How long are you retaining the data?

You should specify how long specific data will be held. Inside Bloomreach, you can set an expiration date on event types at your discretion.

How transparent are you with your customers about your data processing?

Highlight how you indicate to your customers that you process their data. This could be, for example, via a cookie banner or privacy notice.

How can customers control the use of their personal data?

Indicate how your customers can adjust how you handle their data and what actions they can take to exercise their rights in this area. This could be, for example, requesting to delete their information by emailing you.

Which other parties are receiving the data?

The core of a DPIA is to illustrate how personal data will move between tools and persons. In this regard, Bloomreach relies on several subprocessors to operate. See the list of subprocessors. A more detailed description of Bloomreach's data flows can be found in Managing PII.

If you require further information on our infrastructure, IT architecture, and technical and organizational security measures, our SOC 2 report will help. You can obtain our SOC 2 report under an NDA after contacting our team.

As a reminder:

  • Bloomreach relies on Google Cloud Platform (GCP).
  • Bloomreach uses data centers in the US, UK, and the EU depending on your agreement with us.
  • Bloomreach deletes data according to our DPA agreed with you.

Describe the consultation process

In this section, you can mention who in your company you've engaged in the DPIA process, such as your Legal team, Customer Success, Security, and Data Protection team.

Assess necessity and proportionality

By completing the necessity and proportionality assessment, you can indicate that you've considered if people's rights will be affected by your processing and how to protect them. Necessity and proportionality can be split based on the EDPS assessment. This assessment is dependent on your use cases, and in case you require assistance, our team would require further information on your data flows.

You can mention Bloomreach's capabilities in data minimization, the ability to protect users' rights under GDPR, and other data protection features.

Other points to remember

Is there an alternative way to process specific data?

For example, you could ask users to specify items they purchased after purchasing something else (zero-party data). You could justify doing this as long as you can show you've balanced necessity and proportionality.

Have you covered all the purposes the data is to be processed for?

To process data for a different reason, you need to ask for consent or be able to fit under another legal basis such as legitimate interest.

Have you notified your customers in a transparent way about processing?

As a Controller, you have to make sure to let your customers know how you're processing their data and to update your privacy policy and cookie notice.

Identify and assess risks

At this point, you've explained what data you're processing, why you're processing it, and how you're protecting individuals. Now it's time to evaluate if the processing opens any risks.

Some categories of risks could be:

  • Access management
  • Third-party access
  • International data transfers
  • Appropriate security standards
  • Business continuity
  • Incident response and management

Identify measures to reduce risk

At this stage, you can think about and highlight any approaches you're taking to reduce these risks. Some buckets that these measures could fall into include:

  • Access management (for example, using our role-based access or flagging PII to only allow selected users to see it)
  • Security measures (including audit log, vulnerability scan, VPN, Bloomreach SSO, Captcha, DDoS Protection, SSH tunnels, integration protection, and logging or more depending on your instance)
  • Data transfer mechanisms such as standard contractual clauses (SCCs) for data transfers

For further technical details, it may be helpful to request our SOC 2 report (conditional on NDA). Let us know, and we can provide it to you.


Did this page help you?

© Bloomreach, Inc. All rights reserved.