Check your GDPR Compliance

It’s always a good idea to check your compliance with GDPR. That is why we have created a simple GDPR checklist for your to download and complete. The eight questions ask you to check the core elements of your legal duties and put in evidence that the things you need to do have been done. Completing the evidence-based checklist will provide assurance of ongoing compliance with the requirements of the Data Protection Act 2018 that brings GDPR into UK Law.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

What Does the Checklist Cover?

 

There are eight elements to the checklist, but there are a broader range of requirements you should consider and these are set out below:

 

  1. Are you registered with the Information Commissioner as a data controller?

 

  • It is a legal requirement and it is a criminal offence not to register. We are surprised how many organisations overlook this simple first step! Hint: you can check your registration here.

 

  1. Do you have a publicly available privacy statement?

 

  • You have a legal obligation to tell people what data you collect, the lawful basis for doing so, and what you use it for. You should provide this at the time the data are collected. This is known as the “right to be informed”

 

  1. Is that written in a way that the people using your products and services would understand?

  • You must ensure that your privacy statement can be understood by the people whose data you process. For example the Information Commissioner is clear that when you process children’s data you must write your privacy information in a way those children will understand and consider using videos, animations or other media than the written word if necessary.

 

  1. Have you appointed a Data Protection Officer (DPO)?

 

  • This is another legal requirement and one you are very likely to have complied with. All public authorities are required to have one, as are those likely to be processing sensitive data – such as information about health – or you may have CCTV. This means the scope of your data processing would require you to appoint a DPO in any case.

 

  1. Have you got a comprehensive Record of Processing Activity (ROPA)?

 

  • A ROPA is another requirement of the GDPR. It is a comprehensive summary of your data processing activity from the point you collect the data to the point it is destroyed, and examines access, security, and sharing arrangements as well as the lawful basis for data processing.

 

  1. Do you have a process in place for when people make a subject access request?

 

  • People are entitles to a range of information when they make a subject access request, and not just a copy of their data. Do you have processes in place that can also tell people the lawful basis for data processing, and (for example) where data are transferred abroad.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

 

  1. Do you have a retention schedule and regularly destroy personal data that is no longer needed?

 

  • Data should only be stored for as long as it is needed. Retaining data for longer can cause issues relating to complying with people’s rights, and may impose costs – especially if they are kept in paper form.

 

  1. Do you undertake regular exercises to ensure the data you hold is accurate and up to date?

 

  • A key principle of the GDPR is that data must be accurate and complete. This includes giving people opportunities to update or correct information about them when they need to. Personal information quickly becomes out of date, especially in an education context, so it is important to have mechanisms in place to refresh personal data from time to time.

 

  1. Do the people working in your organisations understand how to recognise and report a data breach?

 

  • A data breach is not just the loss or theft of personal data. It can be the accidental alteration or deletion of information, or the improper access to personal data – and this can have serious consequences as this case shows. It is important that everyone knows what a data breach may be, how to avoid them, and what to do if they think a data breach has occurred.

 

  1. Do you understand the lawful bases for all your data processing?

 

  • There are several different lawful bases for processing personal data, with additional protections for sensitive personal data. It is important to know the lawful basis for all your data processing activity as this will affect the way people’s rights apply. For example in some circumstances people have the right to have their data deleted, but for some purposes you will have a great need to keep it.

 

  1. Do you undertake Data Privacy Impact Assessments (DPIAs) for higher-risk data processing?

 

  • Some types of processing, particularly relating to sensitive data, requires a DPIA, This is done to help evaluate the data protection and privacy risks involved. They are a useful tool if you decide to go ahead with risk data processing activity or if there is a data breach as they provide an audit trail of your decision making.

 

  1. Do you understand the difference between operational processing of personal data, which is regulated by the GDPR, and purely personal processing, which is not?

 

  • This can be a difficult area. People are free to, for example, take pictures or videos and publish them on social media if it is for purely personal reasons – even if it reveals data about other people. Conversely people at work have the same rights to privacy as everyone else, and legal precedent  shows there are limits to what people can reasonably claim is purely personal.

 

Download The GDPR Compliance Checklist Here

Complete the form below and get the checklist, and a copy of this post, direct to your inbox

 

 

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial