GDPR Compliance Checklist 2023 | IT Governance UK (2024)

1. Obtain board-level support and establish accountability

2. Scope and plan your GDPR compliance project

3. Conduct a data inventory and data flow audit

4. Undertake a comprehensive risk assessment

5. Conduct a detailed gap analysis

6. Develop operational policies, procedures and processes

7. Secure personal data through procedural and technical measures

8. Ensure teams are trained and competent

9. Monitor and audit compliance

1. Obtain board-level support and establish accountability

GDPR compliance requires board-level support. This means the board must understand the implications of the Regulation to allocate the resources needed to achieve and maintain compliance.

The board should also assign someone to be accountable for compliance within the organisation.

What you need to do:

  • Advise the board about data protection risks and the benefits of GDPR compliance.
  • Obtain management support for your GDPR compliance project.
  • Assign accountability for GDPR compliance to a director.

2. Scope and plan your GDPR compliance project

Once you have obtained top-level support, you need to determine what areas of your organisation fall under the GDPR’s scope.

What you need to do:

  • Appoint and train a project manager.
  • Appoint a DPO (data protection officer) if necessary. If you’re unsure whether or how to appoint a DPO, visit our DPO information page.
  • Identify standards that could provide a framework to help you establish your compliance priorities:
  • The international information security standard ISO 27001 can help you apply data security best practices. This will help you meet the requirements for appropriate technical and organisational security measures of the GDPR (Article 32).
  • Other standards have been developed to enable compliance with essential privacy laws. These include ISO 27701 the international standard for privacy information management and BS 10012 the standard for a personal information management system.
  • Assess whether data protection by design and by default has been incorporated into processes and systems.
  • Consider the implications of Brexit in your planning.

3. Conduct a data inventory and data flow audit

To comply with the GDPR's data processing requirements, you must fully understand what data you process and how you process it.

You can conduct a data inventory and data flow audit to achieve this.

A data inventory is a list of all the personal data you hold, where it came from and who you share it with. A data flow audit is a procedure that maps out all the personal data you process, from its original source to its destination.

You can use the results of your data inventory and data flow audit to develop a data processing policy that complies with the GDPR.

What you need to do:

  • Assess thecategories of datayou hold, where it comes from and the lawful basis for processing.
  • Create a map that shows how data flows to, through and from your organisation.
  • Use the data map to identify the risks in your data processing activities and determine whether aDPIA (data protection impact assessment) is required.
  • Create records of personal data processing activities, as required by Article 30, drawn from the data flow audit and gap analysis.

4. Undertake a comprehensive risk assessment

Risk assessments play a crucial role in any GDPR compliance plan. The GDPR encourages a risk-based approach to data processing. This enables organisations to develop appropriate measures to manage their risks. However, the Regulation does not clarify how you should assess and quantify those risks.

What you need to do:

  • Establish a risk assessment plan.
  • Identify your risks.
  • Analyse and evaluate your risks.
  • Determine ways to control your risks.

5. Conduct a detailed gap analysis

Conducting a GDPR gap analysis will help you identify any areas which may need to be addressed to ensure you are fully compliant with GDPR’s requirements.

What you need to do:

  • Audit your current compliance position against the GDPR’s requirements.
  • Determine which compliance gaps require remediation.

6. Develop operational policies, procedures and processes

You should bring your existing policies, processes and procedures into line with the GDPR’s requirements and develop new ones to fulfil your legal obligations.

What you need to do:

  • Ensure your data protection policies and privacy notices align with the GDPR.
  • Where you rely on consent as your lawful basis for processing, ensure it meets the GDPR’s requirements.
  • Review employee, customer and supplier contracts and update them if necessary to cover personal data processing.
  • Plan how to recognise and handle DSARs (data subject access requests) and respond within one calendar month.
  • Have a process in place for determining whether a DPIA is required.
  • Review whether your mechanisms for transferring data outside the EEAare compliant,especially after Brexit.

7. Secure personal data through procedural and technical measures

Article 32 of the GDPR requires organisations to implement “appropriate technical and organisational measures” to ensure that personal data is processed appropriately.

What you need to do:

  • Have aninformation security policyin place.
  • Implement basic technical controls specified by established frameworks likeCyber Essentials.
  • Use organisational controls where appropriate.
  • Ensure policies and procedures are in place to detect, report and investigate personal data breaches.

8. Ensure teams are trained and competent

Staff awareness and education are vital components of any organisation’s GDPR compliance framework. Everyone involved in processing data must be appropriately trained to follow approved processes and procedures.

What you need to do:

  • Ensure internal communications with stakeholders and staff are effective.
  • Train your employees to understand the importance of data protection, basic GDPR principles and the procedures you have implemented to ensure compliance.

9. Monitor and audit compliance

GDPR compliance is an ongoing project – a journey rather than a destination. You should undertake periodic internal audits and regularly update your data protection processes. This includes checking your records of processing activities and consent, testing information security controls and conducting DPIAs.

What you need to do:

  • Schedule regular audits of data processing activities and security controls.
  • Keep records of personal data processing up to date.
  • Undertake DPIAs where required.
  • Assess data protection practices and manage some of the more demanding elements of GDPR compliance.
GDPR Compliance Checklist 2023 | IT Governance UK (2024)
Top Articles
Live chat support 2024 guide: Definition, Benefits, Best Practices
Yes, You Need a Password Manager. Your Online Security Depends on It
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Dmv In Anoka
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Umn Biology
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Rogold Extension
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Weekly Math Review Q4 3
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Stevie Stamm

Last Updated:

Views: 6025

Rating: 5 / 5 (80 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Stevie Stamm

Birthday: 1996-06-22

Address: Apt. 419 4200 Sipes Estate, East Delmerview, WY 05617

Phone: +342332224300

Job: Future Advertising Analyst

Hobby: Leather crafting, Puzzles, Leather crafting, scrapbook, Urban exploration, Cabaret, Skateboarding

Introduction: My name is Stevie Stamm, I am a colorful, sparkling, splendid, vast, open, hilarious, tender person who loves writing and wants to share my knowledge and understanding with you.