Romet Saaliste Appointed Data Protection Officer at Smart MasterKey

Share article

Smart MasterKey strengthens its commitment to data protection and information security by appointing Romet Saaliste as Data Protection Officer.

Key takeaways

Reading time: 4 minutes

  • Romet Saaliste has been appointed Data Protection Officer at Smart MasterKey, giving customers a dedicated contact for privacy, compliance and data security matters.

  • He will oversee privacy reviews, data processing agreements, security questionnaires and enterprise vendor assessments.

  • His experience leading sensitive, mission-critical systems for the Estonian Police and Border Guard strengthens Smart MasterKey’s readiness for enterprise and regulated customers.

Smart MasterKey commitment to information security

Access control runs on personal data. Every credential is tied to a person. Every door event says who was where, and when. When a building moves from plastic cards to mobile credentials, that data moves into a cloud platform, and the platform provider becomes a data processor your compliance team has to be able to trust and verify.

Larger organisations know this. In almost every enterprise conversation we have, the questions about data protection and information security arrive before the questions about features.

Where is the data hosted? Who can access it? How are processing agreements handled? What happens when an employee leaves? These are the right questions, and they deserve a named, accountable owner on our side.

As DPO, Romet Saaliste will be the single point of contact for data protection at Smart MasterKey. He owns our privacy reviews, our data processing agreements, and the security questionnaires and vendor assessments that enterprise procurement runs before a project starts. If your legal or infosec team has a question about how we handle your people’s data, it lands on his desk and gets a direct answer.

Romet has spent his career building and running software in environments where data handling is not optional politeness but a hard requirement. He worked for over four years at the IT and Development Centre of the Estonian Ministry of the Interior (SMIT) as Head of the Border Service Department, leading the teams that developed and operated highly sensitive, mission-critical systems for the Estonian Police and Border Guard Board. Work that meant managing demanding stakeholders while keeping the systems, and the teams behind them, running. He knows what a serious compliance review looks like from both sides of the table.

Enterprise level partner and customer readiness

The appointment formalises how we already operate. Smart MasterKey processes and stores customer data in EU data centres. The platform is built for GDPR compliance, with data minimisation as a design principle. We collect what the service needs to function, not what might be interesting later. Our information security management follows ISO 27001 principles across access control, data handling, and system operations.

For a facilities or IT manager, the practical effect is that the compliance track of a Smart MasterKey rollout gets faster. Your DPA gets reviewed by our DPO, your security questionnaire gets answered by the person accountable for the answers, and your own DPO has a counterpart to call.

"Access data is some of the most sensitive operational data a company holds. It describes the physical movement of your people," says Romet. "My job is to make sure our customers never have to choose between a modern access platform and a clean compliance posture."
Romet Saaliste
DPO

Talk to us

If you are considering implementing Smart MasterKey in your site then reach out to us to consult and improve your physical-cyber security processes while staying compliant.

Related Articles