Knowledgebase

Data Protection and Privacy Compliance: Everything That Matters, Briefly Print

  • 0

The whole category in one page.

YOU CANNOT COMPLY WITH WHAT YOU DO NOT KNOW YOU HOLD

The data inventory is the foundation; every other obligation depends on it, and building one takes about a day.

WHAT YOU DO NOT HOLD CANNOT BE BREACHED, MISUSED OR REQUESTED

Minimisation is the most underused protection available. Review every form field and ask what it is used for — remove anything without an answer.

CONSENT IS USUALLY THE WRONG BASIS

It must be freely given, specific and withdrawable, which rarely fits employment or anything the person cannot realistically refuse. Pick the basis that actually applies and record it.

NEARLY EVERY NIGERIAN BUSINESS MAKES CROSS-BORDER TRANSFERS

Cloud infrastructure, analytics and business tools are hosted abroad. Identify each transfer and document its mechanism.

ACCOUNTABILITY MEANS DEMONSTRATING, NOT ASSERTING

Records of processing, assessments, agreements and training logs are the evidence — and documentation describing practices nobody follows is evidence against you.

THE BREACH CLOCK STARTS WHEN YOU BECOME AWARE

Prepare the plan, the contacts and the templates now; there is no time to write them during an incident, and a blame culture delays the reporting the clock depends on.

NEVER PUT PRODUCTION DATA IN TEST ENVIRONMENTS, AND NEUTRALISE EVERY EMAIL ADDRESS

MARKETING AFTER AN OPT-OUT IS THE COMMONEST COMPLAINT — MAKE ONE SYSTEM AUTHORITATIVE FOR PREFERENCES

AND TAKE ACTUAL ADVICE ON ANYTHING CONSEQUENTIAL, BECAUSE NONE OF THIS IS LEGAL ADVICE


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot