GDPR Compliance & Your Privacy Rights

At vigbc.ca, we are committed to protecting the privacy and personal data of our users, particularly those residing in the European Union. This page explains your rights under the General Data Protection Regulation (GDPR) and how we fulfill our obligations as a data controller.

Last Updated: January 2026

What is GDPR and Why It Matters

Understanding the European Union's landmark data protection regulation

The General Data Protection Regulation

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of individuals residing in the European Economic Area (EEA), regardless of where the organization is located.

GDPR establishes strict requirements for how personal data must be collected, stored, processed, and protected. It grants individuals significant control over their personal information and imposes substantial penalties for non-compliance-up to €20 million or 4% of annual global turnover, whichever is higher.

Key Principles of GDPR

Lawfulness & Transparency

Personal data must be processed lawfully, fairly, and in a transparent manner with clear communication to data subjects.

Purpose Limitation

Data must be collected for specified, explicit, and legitimate purposes and not further processed incompatibly.

Data Minimization

Only data that is adequate, relevant, and limited to what is necessary for processing purposes should be collected.

Accuracy

Personal data must be accurate and, where necessary, kept up to date with reasonable steps to correct inaccuracies.

Storage Limitation

Data should be kept in identifiable form only as long as necessary for processing purposes.

Security & Integrity

Appropriate technical and organizational measures must ensure data security against unauthorized processing.

Your Rights as a Data Subject

GDPR grants EU residents comprehensive rights over their personal data

Right of Access

You have the right to obtain confirmation of whether your personal data is being processed and, if so, access to that data along with information about how it is used.

Right to Rectification

You can request correction of inaccurate personal data and completion of incomplete data we hold about you without undue delay.

Right to Erasure

Also known as the 'right to be forgotten,' you can request deletion of your personal data when there is no compelling reason for its continued processing.

Right to Data Portability

You can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to Restriction

You can request limitation of processing in certain circumstances, such as when you contest data accuracy or object to processing.

Right to Object

You can object to processing based on legitimate interests, direct marketing, or processing for research or statistical purposes.

Important Notice: The mail-order bride industry operates within international laws and is fully legal when using reputable platforms. We ensure full compliance with GDPR and other applicable data protection regulations to protect your privacy while you use our informational services. For more information about the legal framework, please see our IMBRA Disclosure.

How We Protect Your Personal Data

Our comprehensive approach to GDPR compliance and data protection

1

Lawful Basis for Processing

We only process personal data when we have a valid legal basis under GDPR, such as your consent, contractual necessity, legal obligation, or legitimate interests. We document and maintain records of our lawful basis for each processing activity.

2

Transparent Privacy Notices

Our Privacy Policy clearly explains what data we collect, why we collect it, how we use it, who we share it with, and how long we retain it. We provide this information at the point of data collection and make it easily accessible.

3

Data Minimization Practices

We collect only the personal data that is strictly necessary for our stated purposes. We regularly review our data collection practices to ensure we are not gathering excessive or unnecessary information.

4

Technical Security Measures

We implement appropriate technical measures including encryption of data in transit and at rest, secure access controls, regular security assessments, and intrusion detection systems to protect your personal data.

5

Organizational Security Measures

Our staff receive regular data protection training. We maintain strict access controls on a need-to-know basis, conduct background checks on employees handling sensitive data, and enforce confidentiality agreements.

6

Third-Party Due Diligence

Before engaging any third-party processor, we conduct thorough due diligence to ensure they can provide sufficient guarantees of GDPR compliance. We maintain written contracts with all processors including required GDPR provisions.

7

Data Breach Response

We have established procedures to detect, report, and investigate personal data breaches. Where required, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

8

Regular Compliance Reviews

We conduct periodic audits of our data processing activities, update our privacy documentation, and continuously improve our practices to maintain compliance with evolving data protection requirements.

Submitting Data Access or Deletion Requests

How to exercise your GDPR rights with vigbc.ca

Request Process

To exercise any of your data subject rights under GDPR, please follow this straightforward process:

1

Submit Your Request

Send an email to our Data Protection Officer at the address provided below. Please clearly state which right you wish to exercise and provide sufficient information for us to verify your identity and locate your data.

2

Identity Verification

To protect your privacy, we may need to verify your identity before processing your request. We may ask for additional information to confirm you are the data subject or an authorized representative.

3

Request Processing

Once verified, we will process your request without undue delay. We will respond within one month, though this may be extended by two months for complex requests, in which case we will notify you.

4

Response & Fulfillment

We will provide the requested information or action free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, explaining our reasons.

Pros

  • Free to exercise any of your data rights
  • Response within 30 days (extendable to 90 for complex requests)
  • Dedicated Data Protection Officer to handle your requests
  • Clear documentation of all processing activities
  • Right to lodge a complaint with supervisory authority

Cons

  • Identity verification required for security
  • Some requests may require additional time for complex data sets
  • Certain legal obligations may override deletion requests

Policy Updates & Your Continued Protection

Our commitment to keeping you informed

Questions About Your Data Rights?

Our Data Protection Officer is here to help you understand and exercise your GDPR rights. Contact us for any privacy-related questions or concerns.

Contact Us