Spaces:
Running
Running
Update app.js
Browse files
app.js
CHANGED
|
@@ -212,33 +212,44 @@ const STEPS = [
|
|
| 212 |
{ title: "Normen (logging/encryption)", url: "https://www.helsedirektoratet.no/normen/logging-og-innsyn-i-logg-faktaark-15" }
|
| 213 |
],
|
| 214 |
},
|
| 215 |
-
|
| 216 |
k: "4e",
|
| 217 |
label:
|
| 218 |
-
"Data comes from an external source
|
| 219 |
req: false,
|
| 220 |
-
|
| 221 |
-
|
| 222 |
-
|
| 223 |
-
|
| 224 |
-
|
| 225 |
-
req: false,
|
| 226 |
-
refs: [
|
| 227 |
-
{ title: "HRL §19e; HPA §29", url: "https://lovdata.no/dokument/NL/lov/2014-06-20-43" }
|
| 228 |
-
],
|
| 229 |
-
},
|
| 230 |
-
{
|
| 231 |
-
k: "4e-2",
|
| 232 |
-
label:
|
| 233 |
-
"Processor/joint controller contracts (GDPR 28(3), 26) and DSA/DUA signed (scope, duration, security, destruction/return).",
|
| 234 |
-
req: false,
|
| 235 |
-
refs: [
|
| 236 |
-
{ title: "GDPR Art. 28(3)", url: "https://gdpr-info.eu/art-28-gdpr/" },
|
| 237 |
-
{ title: "GDPR Art. 26", url: "https://gdpr-info.eu/art-26-gdpr/" }
|
| 238 |
-
],
|
| 239 |
-
},
|
| 240 |
-
],
|
| 241 |
},
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 242 |
{
|
| 243 |
k: "4f",
|
| 244 |
label:
|
|
|
|
| 212 |
{ title: "Normen (logging/encryption)", url: "https://www.helsedirektoratet.no/normen/logging-og-innsyn-i-logg-faktaark-15" }
|
| 213 |
],
|
| 214 |
},
|
| 215 |
+
{
|
| 216 |
k: "4e",
|
| 217 |
label:
|
| 218 |
+
"Data comes from an external source, obtain data access agreements, processor/joint controller contracts, DSA/DUA signed",
|
| 219 |
req: false,
|
| 220 |
+
refs: [
|
| 221 |
+
{ title: "HRL §19e; HPA §29", url: "https://lovdata.no/dokument/NL/lov/2014-06-20-43" },
|
| 222 |
+
{ title: "GDPR Art. 28(3)", url: "https://gdpr-info.eu/art-28-gdpr/" },
|
| 223 |
+
{ title: "GDPR Art. 26", url: "https://gdpr-info.eu/art-26-gdpr/" }
|
| 224 |
+
],
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 225 |
},
|
| 226 |
+
// {
|
| 227 |
+
// k: "4e",
|
| 228 |
+
// label:
|
| 229 |
+
// "Data comes from an external source (outside institutions: registries/health trusts).",
|
| 230 |
+
// req: false,
|
| 231 |
+
// children: [
|
| 232 |
+
// {
|
| 233 |
+
// k: "4e-1",
|
| 234 |
+
// label:
|
| 235 |
+
// "Obtain data access agreements; dispensation where applicable.",
|
| 236 |
+
// req: false,
|
| 237 |
+
// refs: [
|
| 238 |
+
// { title: "HRL §19e; HPA §29", url: "https://lovdata.no/dokument/NL/lov/2014-06-20-43" }
|
| 239 |
+
// ],
|
| 240 |
+
// },
|
| 241 |
+
// {
|
| 242 |
+
// k: "4e-2",
|
| 243 |
+
// label:
|
| 244 |
+
// "Processor/joint controller contracts (GDPR 28(3), 26) and DSA/DUA signed (scope, duration, security, destruction/return).",
|
| 245 |
+
// req: false,
|
| 246 |
+
// refs: [
|
| 247 |
+
// { title: "GDPR Art. 28(3)", url: "https://gdpr-info.eu/art-28-gdpr/" },
|
| 248 |
+
// { title: "GDPR Art. 26", url: "https://gdpr-info.eu/art-26-gdpr/" }
|
| 249 |
+
// ],
|
| 250 |
+
// },
|
| 251 |
+
// ],
|
| 252 |
+
// },
|
| 253 |
{
|
| 254 |
k: "4f",
|
| 255 |
label:
|