Internal Data Protection Controls

Operational measures for the publisher and website team – not intended as public-facing website text.

1. Record of Processing Activities (ROPA)

Maintain an internal processing register covering at least newsletter subscriptions, contact and partnership enquiries, publication / event requests, website security logs, analytics, cookie-consent records and any payment processing. The register should identify purposes, data categories, recipients / processors, transfers, retention and security measures.

2. Processor Agreements and Due Diligence

For Hostinger, newsletter services, analytics, consent-management providers, backup / security tools and payment providers, retain the applicable Data Processing Agreement or equivalent data-processing terms. Record any subprocessors and material changes notified by providers.

3. Processor and Transfer Inventory

Maintain a single inventory with: provider; contracting legal entity; role (processor / independent controller); data categories; hosting / processing countries; DPA; transfer mechanism; subprocessor information; retention; security options; and internal owner.

4. Personal-Data Breach Procedure

Maintain an internal breach register and response procedure. Potential breaches should be escalated immediately, risk-assessed, documented and, where notifiable, reported to the APDP without undue delay and, where possible, within 72 hours after awareness. The procedure should include contacts for the publisher, developer, hosting provider and relevant processors.

5. Consent Evidence

Retain sufficient evidence of newsletter consent and cookie choices to demonstrate compliance. Do not collect more information than necessary solely to prove consent.

6. DPO Assessment

Document whether the legal conditions requiring a Data Protection Officer are met. Based on the currently described website activities, no conclusion should be assumed in this draft; counsel should confirm the position after the final analytics, monitoring and data-processing scope is known.

7. Data Protection Impact Assessment (DPIA)

If new technology or processing is likely to create a high risk for individuals – for example large-scale systematic monitoring, extensive profiling or large-scale sensitive-data processing – assess whether a DPIA is required before launch of that processing.

8. EU / GDPR Territorial-Scope Check

Because Ad Astra Journal has an international audience, counsel should assess whether any planned activity intentionally offers goods or services to individuals in the European Union or monitors their behaviour in a manner that may bring specific processing within the territorial scope of the GDPR. This is an additional assessment and does not replace Monaco law.

9. Print Publication Compliance

Before printing or distributing a periodical publication from Monaco, including future print editions of New Coalitions for the Planet, confirm the declaration, Director of Publication, printer / imprint and any deposit or copy requirements applicable under Monaco Law No. 1.299. The final print colophon should be reviewed before sending files to press.

Scroll To Top