Legal Basis for Data Processing
1. Scope & Purpose
This document outlines the legal grounds under which MetalCore Manufacturing processes personal and enterprise data. As a precision manufacturing and engineering company operating across aerospace, automotive, medical, and industrial sectors, we handle sensitive technical, commercial, and personnel information.
Our data processing activities are strictly governed by the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable industry-specific compliance frameworks (AS9100, ISO 13485, IATF 16949).
2. Legal Basis Classification
Under Article 6(1) of the GDPR and equivalent national laws, personal data may only be processed when one or more of the following conditions apply. MetalCore Manufacturing maps each processing activity to its corresponding legal basis:
- Contractual Necessity (Art. 6(1)(b)): Processing required to fulfill manufacturing orders, supply agreements, or service contracts.
- Legal Obligation (Art. 6(1)(c)): Processing mandated by statutory requirements (e.g., tax compliance, export controls, OSHA, REACH, RoHS).
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for quality control, supply chain optimization, fraud prevention, and business continuity, provided it does not override data subject rights.
- Explicit Consent (Art. 6(1)(a)): Voluntary opt-in for marketing communications, webinar participation, or non-essential cookies.
3. Processing Activities & Data Categories
The following table details how specific data categories are processed, the associated legal basis, and retention periods:
| Data Category | Processing Purpose | Legal Basis | Retention |
|---|---|---|---|
| Customer & Supplier Master Data | Order processing, invoicing, compliance audits | Contract | 7 years post-relationship |
| Engineering & CAD Files | Manufacturing execution, prototyping, IP protection | Contract | Duration of NDA + 10 years |
| Quality Inspection Records | Traceability, defect analysis, regulatory reporting | Legal Legitimate Interest | 15 years (medical/aerospace) |
| Employee & Contractor Data | Payroll, access control, safety training, performance | Contract Legal | Employment period + 6 years |
| IoT & Machine Telemetry | Predictive maintenance, production optimization | Legitimate Interest | 3 years (aggregated/anonymized) |
| Marketing & Event Data | Newsletters, trade shows, product updates | Until withdrawal + 2 years |
4. Data Subject Rights
Under applicable privacy legislation, data subjects retain the following enforceable rights. MetalCore Manufacturing commits to responding to valid requests within 30 calendar days:
🔍 Right of Access
Request a copy of all personal data we hold, including processing purposes and recipients.
✏️ Right to Rectification
Request correction of inaccurate or incomplete personal data without undue delay.
🗑️ Right to Erasure
Request deletion of data where legal basis no longer applies or processing is unlawful.
⛔ Right to Restriction
Limit processing while accuracy is verified or legal claims are assessed.
📦 Data Portability
Receive structured, machine-readable data for transfer to another controller.
🚫 Right to Object
Opt-out of processing based on legitimate interests or direct marketing at any time.
To exercise any right, submit a verified request to our Data Protection Officer via the contact channel below. Identity verification may be required to prevent unauthorized disclosure.
5. International Data Transfers
Due to our global supply chain and multinational clientele, personal data may be transferred outside the European Economic Area (EEA) and California. All cross-border transfers comply with:
- EU Standard Contractual Clauses (SCCs) 2021/914
- Adequacy decisions where applicable
- California CCPA/CPRA cross-border disclosure requirements
- ISO 27001 & SOC 2 Type II security controls
Transfers to manufacturing partners, quality laboratories, or cloud infrastructure providers are contractually bound to equivalent data protection standards. A full transfer impact assessment (TIA) is maintained on file.
6. Retention & Secure Disposal
Data is retained only for as long as necessary to fulfill the stated processing purposes, comply with statutory obligations, or resolve disputes. Upon expiration:
- Digital records are securely purged using NIST 800-88 compliant wiping protocols
- Physical documents are cross-cut shredded (DIN 66399 Level P-5)
- Backups are overwritten according to lifecycle management policies
- Anonymized datasets may be retained for historical quality benchmarking
7. Data Protection Officer & Contact
For inquiries regarding this legal basis, data subject requests, compliance audits, or vendor security assessments, contact our Data Protection Office:
🛡️ MetalCore DPO Office
Email: dpo@metalcore-mfg.com
Secure Portal: https://compliance.metalcore-mfg.com/data-requests
Mailing Address: Data Protection Officer, MetalCore Manufacturing, 4200 Industrial Blvd, Detroit, MI 48201, USA
Regulatory Authority: Michigan Attorney General's Consumer Protection Division / UK ICO (EU Representative)
All submissions are encrypted via TLS 1.3. Response SLA: 10 business days for acknowledgment, 30 days for resolution.