Understand your GDPR compliance requirements
Our data protection consultants will assess your organization’s privacy management and data protection practices through an on-site review of the following areas:
- Governance – the extent to which data protection accountability, responsibility, policies and procedures, performance measurement controls, and reporting mechanisms to monitor compliance are in place and operating throughout your organization.
- Risk management – your organisation’s arrangements for privacy risk management, the extent to which information-specific risks are incorporated into corporate risk management, and the extent to which risks to the rights and freedoms of data subjects are addressed.
- Privacy by design – the extent to which data protection by design has been incorporated into the development of your systems, services, products, and/or processes.
- DPO (data protection officer) – whether your organization is required to appoint a DPO, whether one has been appointed and, if so, whether they meet the Regulation’s requirements.
- Roles and responsibilities – the extent to which your organization has defined and established appropriate roles and responsibilities, and delivered appropriate training and awareness.
- Scope of compliance – whether your organization has clearly defined the scope of its GDPR compliance, taking account of all data processing in which it has a part, whether as data controller or processor, as well as any data sharing.
- PIMS (personal information management system) – whether your organization has implemented a PIMS that documents its GDPR compliance, and addresses staff training and awareness.
- ISMS (information security management system) – whether your organization has implemented an ISMS to meet the GDPR’s requirements for “appropriate technical and organizational measures” in order to ensure the security of the personal data it processes.
- Rights of data subjects – the processes your organization has implemented to facilitate and respond to data subjects exercising their rights under the GDPR.
What to expect
A GDPR specialist will interview key managers and perform an analysis of your existing data protection and privacy arrangements and documentation.
Following this, you will receive a gap analysis report of the findings. The report outlines the areas of compliance and improvement, providing further recommendations for the proposed GDPR compliance project.
Please click on each image for a closer look: