Building a Compliance Programme Print

  • 0

Moving from nothing to functioning.

WHAT THE STAGES ARE

Understand what applies Know what you hold Fix the obvious gaps Document Embed into how work happens Review

WHAT TO DO IN THE FIRST WEEK

Establish whether you are in scope, and of what.

WHAT TO DO IN THE FIRST MONTH

Build the inventory Delete what has no purpose Write an accurate privacy notice Name a responsible person

WHAT TO DO IN THE FIRST QUARTER

Processor agreements in place Retention schedule defined Rights request process Breach plan and contacts Access review

WHAT TO DO ONGOING

Training Impact assessments for new processing Annual review

WHAT NOT TO DO

Buy a template pack and file it.

WHY

It describes someone else's organisation.

WHAT TO PRIORITISE IF RESOURCES ARE LIMITED

The inventory, deletion, security and the breach plan.

WHY THOSE FOUR

They reduce actual risk, rather than documenting it.

WHAT TO MEASURE

Whether the programme changes behaviour.

HOW

Whether new processing gets assessed before launch.

WHAT TO REPORT UPWARD

Status, gaps and risks.

WHAT TO SECURE

Senior support, without which nothing embeds.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot