
In this step we look at 'determining a base line position' - building the foundations for what comes next and getting your processes and records in order so you build up from solid foundations. Read the Data Audit PDF first, then watch the video and finally use the spreadsheet.
This video explains how to create and use a data inventory with details on how to use the tools provided with this step
This step explains the legal bases permitted for processing and provides further insight into the high standard of consent required under the GDPR.
This step takes you through the steps needed to ascertain Legitimate Interest is the correct basis for processing personal data
This step discusses data erasure and shows you why deleting data requires more under the GDPR to effectively erase data than a press of the delete button. Information to assist you is included in the PDF which supports this step and is correct at the time of uploading ie May 14th 2018
Our 5 Step GDPR introductory course to take you from zero to compliance so you access the expert support and explanation needed to help you reach compliance for GDPR. The law referred to within this course is correct at 22nd August 2022
This is what is included in this easy to follow, clear course
Step 1 – Data Audit – What data do I have? (with spreadsheet provided)
Step 2 – Data Audit – What do I do with the data that I found in Step 1? (with colour-tabbed Word tables provided)
Step 3 – Permissions – What are the Permissions which apply to how I process the data (as identified in Step 2).
Step 4 – ‘Legitimate Interest’ – What does it mean and how much of my processing can I fit under this umbrella?
Step 5 – Data Cleansing – a short explanation about why secure destruction of data doesn’t mean hitting the delete key and emptying a recycle bin, together with some options for secure destruction methods to investigate
Are you working on the DPO team in your business? This is what the law says:
To inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to this Regulation and to other Union or Member State data protection provisions;
To monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
To provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
To cooperate with the supervisory authority;
To act as the contact point for the supervisory authority on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, with regard to any other matter.
This course helps a complete beginner understand the 5 core steps of Data Protection which assists anyone working on the DPO team or shouldering some responsibility for Data Protection in your business.