It's already the third anniversary of the GDPR!
Here are 10 questions that controllers should consider when self-assessing their compliance. Most of these questions are relevant for processors too!
- Have you set up and maintained a record/register of processing activities?
- Are you identifying, on an ongoing basis, lawful bases for all the processing you carry out (including recording consent as appropriate and conducting a balancing test if relying on legitimate interest)?
- Are you drafting or updating your internal data protection policy and privacy information notice?
- Are you putting in place processes and procedures to respond to data subjects' requests (access, update, erasure, etc.) and managing data breaches?
- Destroying or deleting personal data that is no longer necessary to pursue the purposes for which it has been collected?
- Implementing appropriate technical and organisational measures to protect personal data (including an information security policy and training for the member of your staff who processes personal data) and are you regularly reviewing the security of your IT environment?
- Have you entered into a written contract with the processors you use?
- Do you have documents that you do not need and have you conducted data protection impact assessments (DPIA)?
- Do you have documents that you do not need and have you appointed a DPO;
- Are you ensuring all transfers of personal data are made under appropriate safeguards and are you taking appropriate measures further to the Schrems II case?
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.