Why Are Security and Data Protection Important?
Gillie processes sensitive personal data related to social and healthcare. The data belongs to the client, and its processing is regulated by the EU General Data Protection Regulation (GDPR), national data protection legislation, and special laws concerning social and healthcare.
Data protection is not just about legalities – it is part of good care: when a client can trust that their information remains secure, they are more likely to share their situation openly and receive better service.
What Does Gillie Record?
Gillie logs key actions in the Changes log:
- logins
- two-factor authentication steps and session terminations
- views of client information
- creation, modification, and deletion of data (old → new value)
- sessions initiated with an API key
Viewing the log requires a separate permission and is itself recorded in the log. The log is used for security monitoring, troubleshooting, and fulfilling notification obligations.
Client Rights (GDPR)
| Right | What Can the Client Request? | Action in Gillie |
|---|---|---|
| Access Their Own Data | A copy of the personal data being processed. | Requesting own data (GDPR) in the client view. |
| Be Forgotten | Deletion of their data. | Data deletion. |
| Receive Information About Processing | An explanation of what data is collected and why. | Inform the client as part of the service; use the organization’s own privacy notice. |
| Request Correction | Correction of incorrect information. | Correct in the patient information system and, if necessary, in Gillie’s data. |
Important. Never delete or modify client data for concealment purposes. All actions are recorded in the log, which can be reviewed later.
Deleting and Requesting Data
If client data needs to be sent to the client or deleted, this is done from the client view. In the client view, press the menu button and select either delete client or send all client data as needed.
Security Incidents
A security incident is a situation where data may have fallen into the wrong hands or the system has been misused. Common situations include:
- login credentials have been exposed or used without authorization
- a laptop or phone has been lost
- client data has been accidentally sent to the wrong recipient
- a suspicious phishing message has been opened
What to Do
- Change your password immediately if you suspect it has been compromised.
- Report the situation immediately to your supervisor and the organization’s data protection officer.
- Record the time, what happened, and whose data may have been exposed.
- Follow your organization’s incident handling procedures.
Tip. Use your organization’s security training as a reminder and ask the administrator if any setting seems outdated.