GDPR Compliance Step 9 - Technical and Security Measures

Steps to GDPR Compliance: Security and Technical Measures

Posted · Add Comment

Step 9 – ISO27001: A Data Privacy Odyssey: How to demonstrate technical and security measures under the GDPR Introduction Under current privacy laws, only one of the privacy principles applies directly to a data processor, and that is to ensure that adequate security and technical measures are in place.  The GDPR mirrors this obligation on […]

GDPR_step 7

Steps to GDPR Compliance: Data Breach

Posted · Add Comment

“Once more unto the breach….” Why galvanising your troops to deal with data breach is a key part to compliance with the GDPR Introduction to data breaches The GDPR introduces a duty on organisations to report certain data breaches to their supervisory authority (Article 33) and, in some cases, to individuals (Article 34).  The GDPR […]

GDPR_step 6

Steps to GDPR Compliance: Privacy Impact Assessments

Posted · Add Comment

Use Privacy Impact Assessments to measure the impact of data processing operations Crash Test Dummy – why every prudent processor of data should use Privacy Impact Assessments (PIA) We all feel more secure when we get into our cars knowing they are kitted out with multiple safety features developed through testing and predicting risks of […]

GDPR_step 5

Steps to GDPR Compliance: Vendor Management

Posted · Add Comment

Vendor management Through the GDPR looking glass… “She generally gave herself very good advice, (though she very seldom followed it)” – Why all entities processing data should follow the “very good advice” to “know your Vendor” Introduction In Step 2 of our GDPR blog series, we talked about the importance of data mapping, and knowing where […]

GDPR_step 4

Steps to GDPR Compliance: The Right to be Forgotten

Posted · Add Comment

The “Right To Be Forgotten” What is the “right to be forgotten”? Article 17 of the GDPR contains the right for data to be erased: otherwise known as “the right to be forgotten”. The principle behind this, as stated by the UK Information Commissioner’s Office (ICO), is to “enable an individual to request the deletion […]

Steps to GDPR Compliance: Subject Access Rights

Posted · Add Comment

“What you looking at?” Will subject access rights become the Vogue under the GDPR? What changes will there be to the current regime? Based on what we know for now, the GDPR subject access request (“SAR”) process will be similar to that under the current regime. The key changes taking effect from May 2018 are: […]

GDPR_step 2

Steps to GDPR Compliance: Data Mapping

Posted · Add Comment

Data mapping Step 2 – Follow the yellow brick road Why data map Data mapping should be a key element in any organisation’s compliance strategy, including any pre-employment screening policy. The prospective employer (data controller) can face questions from its candidate base about where their personal data is being sent and how it is used. […]