Privacy Battles
Fathom
Privacy Score
94
%
⚔️
AT Internet
Privacy Score
86
%

Designated DPO or GDPR correspondent

Compliant
Partially Compliant
Not Compliant

A DPO is said to be designated but no direct contact or identity was found on Fathom’s website and policies.

Compliant
Partially Compliant
Not Compliant

AT Internet has appointed a Data Protection Officer who can be contacted at the following address: dpo@atinternet.com or by post.

Privacy Policy

Country & Type of Data storage

Compliant
Partially Compliant
Not Compliant

Company Headquarters:
Canada 🇨🇦

Storage Facilities:
EU traffic is processed by German cloud provider Hetzner in Germany and Iceland.

EU residents’ personal data is pseudonymized before being transferred on US servers (cloud provider is AWS), except if option « Extreme EU isolation » is contracted by the controller which ensures data stays in the European Union.

Compliant
Partially Compliant
Not Compliant

Company Headquarters:
France 🇫🇷  (EU) 🇪🇺

Storage Facilities:
All analytics data is stored in the EU by cloud providers AWS and SFR.

AT Internet however doesn’t specify in which country data is hosted.

Data transfers outside the EU

Compliant
Partially Compliant
Not Compliant

The adequate level of protection in Canada has been approved by the European Commission.

However, Fathom doesn’t transfer data to Canada but to the US after it being pseudonymized.

If chosen by the controller, Fathom option “Extreme EU isolation” ensures data is never transferred outside the EU.

Compliant
Partially Compliant
Not Compliant

AT Internet doesn’t transfer analytics data outside the EU.

Legal tools for Subcontractors

Compliant
Partially Compliant
Not Compliant

Subcontractors are subjects to written agreements substantially similar to Fathom’s DPA: https://usefathom.com/dpa

Fathom has made public its list of subprocessors: https://usefathom.com/dpa

Prior to modifying the list of subprocessors, the controller will be notified by email and is able to object.

Fathom conducts risk assessments for every data processor used.

Compliant
Partially Compliant
Not Compliant

At Internet commits itself to verify that its subcontractors present sufficient guarantees regarding the implementation of technical and organizational measures.

AT Internet has made public its list of subprocessors: https://www.atinternet.com/en/processor-sub-processor-information-parent-company/

Prior to modifying the list of subprocessors, the controller will be notified and is able to object.

Data Breach Notification

Compliant
Partially Compliant
Not Compliant

In case of a data breach, Fathom will notify the controller without undue delay after becoming aware of the breach, and assist the controller in providing necessary information.

Compliant
Partially Compliant
Not Compliant

In case of a data breach, AT Internet will notify the controller without undue delay after becoming aware of the breach, and provide the necessary information to notify Data Protection Authorities.

Right Requests Process

Compliant
Partially Compliant
Not Compliant

Reasonable assistance will be provided for the fulfilment of the controller’s obligation to respond to data subjects' right requests.

Compliant
Partially Compliant
Not Compliant

Data request will be forwarded to the controller without delay and assistance will be provided to the controller to answer any request.

Data Privacy Impact Assessment

Compliant
Partially Compliant
Not Compliant

Fathom explains conducting DPIAs on its processing activities but doesn’t mention assistance to controller if needed.

Compliant
Partially Compliant
Not Compliant

AT Internet will provide necessary assistance to the controller in case of Data Privacy Impact Assessment on an analytics processing activity.

Employee Trainings

Compliant
Partially Compliant
Not Compliant

Persons authorized to process the personal data are subject to confidentiality obligations.

Compliant
Partially Compliant
Not Compliant

Employees are trained on the confidentiality of personal data and subjects to a strict confidentiality obligation.

Security Policy

Compliant
Partially Compliant
Not Compliant

Fathom mentions having a security policy but has not made it public.

Compliant
Partially Compliant
Not Compliant

AT Internet mentions having a security policy and updating it regularly, but has not made it public.

Organizational and Technical Security Measures

Compliant
Partially Compliant
Not Compliant

Server security:
Cloud security relying on Amazon US and Hetzner for German/Icelandic servers.

Other measures:
Hashes (user signature) daily generated via secret key (SHA256) - this equals data pseudonymisation, prevention against DDoS spam attacks, self-audits on data processing activities and systems, strong passwords, data encryption, two-factor authentication.

Compliant
Partially Compliant
Not Compliant

AT Internet mentions having a security policy and updating it regularly, but has not made it public.

Data Encryption

Compliant
Partially Compliant
Not Compliant

Fathom mentions data encryption but doesn’t precisely says if data is encrypted at rest or in transit.

Compliant
Partially Compliant
Not Compliant

AT Internet never mentions data encryption.

Restriction of access

Compliant
Partially Compliant
Not Compliant

Fathom only allows external access or processing of personal data in accordance with their instructions and only when strictly necessary (for instance, IT support).

Compliant
Partially Compliant
Not Compliant

AT Internet limits access to data only to persons who need to know and does not share data with third parties without prior demand of the controller.

Reuse of data

Compliant
Partially Compliant
Not Compliant

Fathom only processes personal data pursuant to controller instructions.

Compliant
Partially Compliant
Not Compliant

AT Internet doesn’t pursue its own purposes with this data processing. The controller stays the data owner.

Exemption of cookie consent

Compliant
Partially Compliant
Not Compliant

YES, Fathom technology doesn’t require cookies.

Compliant
Partially Compliant
Not Compliant

YES, if controller masks the following personal data by default (visitor ID, postal code, internet service provider, converted visit) and anonymizes IP addresses.

Submission to Cloud Act/FISA

Compliant
Partially Compliant
Not Compliant

NO, if controller selects “Extreme EU isolation” storage option. If not, data is only pseudonymized through SHA256 when transferred to Amazon US servers.

Compliant
Partially Compliant
Not Compliant

YES, data hosted on Amazon servers doesn’t appear to be anonymized nor encrypted at rest, therefore can be accessed by an American intelligence agency on demand.