GDPR - General Data Protection Regulation

7 Principles

  1. Lawfulness, Fairness & Transparency - Legal 
  2. Purppose limitation 
  3. Data minimisation - only ncecessary data collected
  4. Accuracy - accurate and corrected
  5. Storage limitation - Keep it for the required time mentioned in transparency
  6. Security - Fundamental 
  7. Accountability - Responsible to uphold the principles


12  Steps

  1. Data inventory - Creat  a list of all personal data collected.
  2. Data Expiration- Delete all personal data after the purpose is served. 
  3. Consent - Get consent before collecting personal data
  4. Individual rights - People have the right to ask question. Answer in 30 days
  5. Data transfers - Adequate security while transfering
  6. Transparency - Inform what data collected, what processing, purpose etc (Privacy/cookie notice)
  7. Awareness & Training - Train all staff about data protection
  8. Data breaches - If uninteded breach happens... inform authorities in 72 hours
  9. Data protection impact assessment - High risk processes
  10. Data protection officer - Implemntaion and monitoring person
  11. Privacy operations team - 
  12. Evidencing - Document all decisions Most important 





Comments

Popular posts from this blog

How to select and cut out an image in Krita

Transform and Stretch an image in Krita

Joomla error: Your site may not have been upgraded completely