The first steps for an organisation with nothing in place.
WHAT NOT TO DO FIRST
Buy a policy pack.
WHY
It describes someone else, and changes nothing.
WHAT TO DO IN WEEK ONE
List every system holding personal data Name a responsible person Establish whether registration applies
HOW TO LIST SYSTEMS
Ask each person what data they handle and where.
WHAT TO DO IN WEEK TWO
For each system, record what, why, who, how long Identify anything with no purpose
WHAT TO DO IN WEEK THREE
Delete what has no purpose Review who has access Remove access for departed staff
WHY DELETION EARLY
It is the fastest, cheapest risk reduction available.
WHAT TO DO IN WEEK FOUR
Write an accurate privacy notice Publish a contact route
WHAT TO DO IN MONTH TWO
Processor agreements with your main suppliers A retention schedule A rights request process A breach plan with contacts
WHAT TO DO IN MONTH THREE
Train staff Review forms and remove unnecessary fields Document what you have done
WHAT TO ACCEPT
That this will not be perfect.
WHAT MATTERS MORE THAN PERFECTION
Knowing what you hold, holding less, and being able to respond.
WHAT TO SCHEDULE
An annual review.