SlideShare a Scribd company logo
1 of 2
Download to read offline
GDPR AUDIT CHECKLIST FOR SMALLER BUSINESSES
© 500 Words Ltd, 2018. You may share only provided you keep this notice. You have no licence to adapt. Please tell us if it needs changes. Page 1
Topic Action Y/N/DK Evidence/action GDPR Requirements
1. Awareness  Is everyone aware of GDPR? Read ICO 12 Steps Train staff on GDPR
 Have you identified possible compliance
issues?
You should ensure suppliers are GDPR-
compliant by asking them to confirm their
security measures. Check contracts include
requirements in Article 28(3).
 Do you have records of the audit?
 Have you completed due diligence on
your supply chain?
2. Information
audit
 What personal data do you hold? GPR requires you to maintain records of your
processing activities. GDPR requires you to
show how you comply (accountability). Article
9 defines sensitive data.
 Is it any of it sensitive data?
 Where did it come from?
 Where is it stored (device & location)?
 Is it encrypted?
 Who do you share it with?
3. Communicating
privacy info
 What does your privacy notice say? GDPR requires you to explain your lawful basis
(see 6) for processing data, your data retention
periods and the individual’s rights (in plain
language).
See ICO Privacy Notice Guide
 Do you need to update your privacy notice
for GDPR?
 Is your privacy policy on your website?
 Do you need to update your T&C for the
new data regulations?
4. Individuals’
rights
 Do your data policy cover all rights
individuals have?
GDPR gives these rights to individuals:
 the right to be informed
 the right of access
 the right to rectification
 the right to erasure
 the right to restrict processing
 the right to data portability
 the right to object
 the right not to be subject to automated
decision -making including profiling
 Does your data policy need updating?
 Do you delete personal data?
 Do you provide data electronically or in a
commonly used format?
5. Access
requests
 Do your procedures allow you to (1)
handle requests for information in the
new timescales and (2) provide the
correct information?
GDPR gives a month to comply (was 40 days).
Mostly compliance is without charge.
GDPR AUDIT CHECKLIST FOR SMALLER BUSINESSES
© 500 Words Ltd, 2018. You may share only provided you keep this notice. You have no licence to adapt. Please tell us if it needs changes. Page 2
Topic Action Y/N/DK Evidence/action GDPR Requirements
6. Lawful basis  What is the lawful basis for your
processing of data?
Lawful bases for necessary processing are:
 Clear consent
 Contract
 Legal obligation eg as employer
 Vital interests (protect life)
 Public task
 Legitimate interests
See ICO Guide on lawful processing
 Do you have fair processing notices?
 Where is that stated?
 Have you updated your privacy notice to
explain it?
7. Consent  Have you reviewed how you seek, record
and manage consent?
Consent must be freely given, specific,
informed and unambiguous. It cannot be
inferred from silence, inactivity or pre-ticked
boxes.
Do not rely on implied consent. Separate
consent requests from other T&C.
Simplify unsubscribing. See ICO Consent
Guidance
 If someone joins your email list do they
know the content you will send?
 Can you prove their consent?
 Do your existing consents meet the GDPR
standards? Free choice + positive opt-in
 Can they unsubscribe easily?
8. Children  Does your data verify the ages of
individuals?
GDPR requires specific protection for children’s
(below 16YO) personal data and requires
parental consent if a child. Your privacy notice
should be understandable to children.
 Do you need a procedure to get parental
consent?
9. Data breaches  Do you have procedures to (1) detect, (2)
report and (3) investigate a data breach?
GDPR requires you to notify breaches to ICO if
it is likely to result in a risk to rights and
freedoms of individuals within 72 hours.
10. Privacy Impact
Assessment
 Has everyone read the ICO Code of
Practice on Privacy Impact Assessments?
GDPR requires privacy by design. You may need
a Data Privacy Impact Assessments. See ICO PIA
Guidance Do you know how & when you will
implement any DPIA?
11. Data
Protection
Officers
 Do you need a DPO to check compliance? GDPR requires a DPO if you are a public
authority, carry out large regular monitoring or
large scale processing of specific personal data.
 Who is our DPO (or equivalent)?
12. International  If you work across EU member states, who
is your lead data protection supervisory
authority?
Lead authority is where your main
establishment is.

More Related Content

What's hot

Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
PECB
 

What's hot (20)

Data classification-policy
Data classification-policyData classification-policy
Data classification-policy
 
General Data Protection Regulation (GDPR) and ISO 27001
General Data Protection Regulation (GDPR) and ISO 27001General Data Protection Regulation (GDPR) and ISO 27001
General Data Protection Regulation (GDPR) and ISO 27001
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
GDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping ELGDPR and ISO27001 mapping EL
GDPR and ISO27001 mapping EL
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
ISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptx
 
GDPR
GDPRGDPR
GDPR
 
ISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to knowISO/IEC 27701 vs GDPR: What you need to know
ISO/IEC 27701 vs GDPR: What you need to know
 
GDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratgGDPR most actionable cheatsheet and checklist by cyberstratg
GDPR most actionable cheatsheet and checklist by cyberstratg
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
 
Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
Key Data Privacy Roles Explained: Data Protection Officer, Information Securi...
 
[Presentation] GDPR - How to Ensure Compliance
[Presentation] GDPR - How to Ensure Compliance[Presentation] GDPR - How to Ensure Compliance
[Presentation] GDPR - How to Ensure Compliance
 
Data governance – an essential foundation to good cyber security practice
Data governance – an essential foundation to good cyber security practiceData governance – an essential foundation to good cyber security practice
Data governance – an essential foundation to good cyber security practice
 
Privacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program ImplementationPrivacy-ready Data Protection Program Implementation
Privacy-ready Data Protection Program Implementation
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...Privacy by Design and by Default + General Data Protection Regulation with Si...
Privacy by Design and by Default + General Data Protection Regulation with Si...
 

Similar to Checklist for SMEs for GDPR compliance

GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
Spain-Holiday.com
 

Similar to Checklist for SMEs for GDPR compliance (20)

NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR - what you need to know
GDPR -  what you need to know GDPR -  what you need to know
GDPR - what you need to know
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
ICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPRICO's Guide to Preparing for the GDPR
ICO's Guide to Preparing for the GDPR
 
GDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-stepsGDPR Preparing for-the-gdpr-12-steps
GDPR Preparing for-the-gdpr-12-steps
 
GDPR Changing Mindset
GDPR Changing MindsetGDPR Changing Mindset
GDPR Changing Mindset
 
GDPR_Skillcast Presentation Template (1).pptx
GDPR_Skillcast Presentation Template (1).pptxGDPR_Skillcast Presentation Template (1).pptx
GDPR_Skillcast Presentation Template (1).pptx
 
GDPR in the Healthcare Industry
GDPR in the Healthcare IndustryGDPR in the Healthcare Industry
GDPR in the Healthcare Industry
 
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take NowGDPR Guide: The ICO's 12 Recommended Steps To Take Now
GDPR Guide: The ICO's 12 Recommended Steps To Take Now
 
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental ownersGDPR & the Travel Industry: Practical recommendations for holiday rental owners
GDPR & the Travel Industry: Practical recommendations for holiday rental owners
 
What's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) ChangesWhat's Next - General Data Protection Regulation (GDPR) Changes
What's Next - General Data Protection Regulation (GDPR) Changes
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 
Impact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and ProcessingImpact of GDPR on Data Collection and Processing
Impact of GDPR on Data Collection and Processing
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
My presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPRMy presentation- Ala about privacy and GDPR
My presentation- Ala about privacy and GDPR
 
Cognizant business consulting the impacts of gdpr
Cognizant business consulting   the impacts of gdprCognizant business consulting   the impacts of gdpr
Cognizant business consulting the impacts of gdpr
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
UX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital ExperiencesUX & GDPR - Building Customer Trust with your Digital Experiences
UX & GDPR - Building Customer Trust with your Digital Experiences
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 

More from Sarah Fox

More from Sarah Fox (20)

Why use 50000 words when 500 will do? (March 2020)
Why use 50000 words when 500 will do? (March 2020)Why use 50000 words when 500 will do? (March 2020)
Why use 50000 words when 500 will do? (March 2020)
 
How accessibility, simplicity and clarity can stop contracts being a burden a...
How accessibility, simplicity and clarity can stop contracts being a burden a...How accessibility, simplicity and clarity can stop contracts being a burden a...
How accessibility, simplicity and clarity can stop contracts being a burden a...
 
Creating effective contracts
Creating effective contracts Creating effective contracts
Creating effective contracts
 
Managing Risks and Changes under NEC4
Managing Risks and Changes under NEC4Managing Risks and Changes under NEC4
Managing Risks and Changes under NEC4
 
From Captive Cult to Culture Change: Sarah Fox
From Captive Cult to Culture Change: Sarah FoxFrom Captive Cult to Culture Change: Sarah Fox
From Captive Cult to Culture Change: Sarah Fox
 
10 Tips to Improve Your Legal Writing
10 Tips to Improve Your Legal Writing10 Tips to Improve Your Legal Writing
10 Tips to Improve Your Legal Writing
 
Top 5 Methods for Resolving UK Construction Disputes
Top 5 Methods for Resolving UK Construction DisputesTop 5 Methods for Resolving UK Construction Disputes
Top 5 Methods for Resolving UK Construction Disputes
 
Never Sign on the Dotted Line
Never Sign on the Dotted LineNever Sign on the Dotted Line
Never Sign on the Dotted Line
 
Creating Smart(er) Construction Contracts
Creating Smart(er) Construction ContractsCreating Smart(er) Construction Contracts
Creating Smart(er) Construction Contracts
 
8 Habits of Highly Defective Contracts
8 Habits of Highly Defective Contracts8 Habits of Highly Defective Contracts
8 Habits of Highly Defective Contracts
 
Why Use 50,000 Words When 500 Will Do?
Why Use 50,000 Words When 500 Will Do? Why Use 50,000 Words When 500 Will Do?
Why Use 50,000 Words When 500 Will Do?
 
Never Sign on the Dotted Line
Never Sign on the Dotted LineNever Sign on the Dotted Line
Never Sign on the Dotted Line
 
Guide to Tort in Construction
Guide to Tort in ConstructionGuide to Tort in Construction
Guide to Tort in Construction
 
Guide for Construction Contract Administrators
Guide for Construction Contract AdministratorsGuide for Construction Contract Administrators
Guide for Construction Contract Administrators
 
Excluding Liability for Latent Defects
Excluding Liability for Latent DefectsExcluding Liability for Latent Defects
Excluding Liability for Latent Defects
 
What's So Great About Construction?
What's So Great About Construction?What's So Great About Construction?
What's So Great About Construction?
 
10 Essentials For An Effective Construction Contract
10 Essentials For An Effective Construction Contract10 Essentials For An Effective Construction Contract
10 Essentials For An Effective Construction Contract
 
How Courts Decide Whose Terms Apply
How Courts Decide Whose Terms ApplyHow Courts Decide Whose Terms Apply
How Courts Decide Whose Terms Apply
 
Construction Contract Review Checklist
Construction Contract Review ChecklistConstruction Contract Review Checklist
Construction Contract Review Checklist
 
Checklist for Trainers & Facilitators
Checklist for Trainers & FacilitatorsChecklist for Trainers & Facilitators
Checklist for Trainers & Facilitators
 

Recently uploaded

Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
amitlee9823
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
dlhescort
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
Matteo Carbone
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 

Recently uploaded (20)

Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 

Checklist for SMEs for GDPR compliance

  • 1. GDPR AUDIT CHECKLIST FOR SMALLER BUSINESSES © 500 Words Ltd, 2018. You may share only provided you keep this notice. You have no licence to adapt. Please tell us if it needs changes. Page 1 Topic Action Y/N/DK Evidence/action GDPR Requirements 1. Awareness  Is everyone aware of GDPR? Read ICO 12 Steps Train staff on GDPR  Have you identified possible compliance issues? You should ensure suppliers are GDPR- compliant by asking them to confirm their security measures. Check contracts include requirements in Article 28(3).  Do you have records of the audit?  Have you completed due diligence on your supply chain? 2. Information audit  What personal data do you hold? GPR requires you to maintain records of your processing activities. GDPR requires you to show how you comply (accountability). Article 9 defines sensitive data.  Is it any of it sensitive data?  Where did it come from?  Where is it stored (device & location)?  Is it encrypted?  Who do you share it with? 3. Communicating privacy info  What does your privacy notice say? GDPR requires you to explain your lawful basis (see 6) for processing data, your data retention periods and the individual’s rights (in plain language). See ICO Privacy Notice Guide  Do you need to update your privacy notice for GDPR?  Is your privacy policy on your website?  Do you need to update your T&C for the new data regulations? 4. Individuals’ rights  Do your data policy cover all rights individuals have? GDPR gives these rights to individuals:  the right to be informed  the right of access  the right to rectification  the right to erasure  the right to restrict processing  the right to data portability  the right to object  the right not to be subject to automated decision -making including profiling  Does your data policy need updating?  Do you delete personal data?  Do you provide data electronically or in a commonly used format? 5. Access requests  Do your procedures allow you to (1) handle requests for information in the new timescales and (2) provide the correct information? GDPR gives a month to comply (was 40 days). Mostly compliance is without charge.
  • 2. GDPR AUDIT CHECKLIST FOR SMALLER BUSINESSES © 500 Words Ltd, 2018. You may share only provided you keep this notice. You have no licence to adapt. Please tell us if it needs changes. Page 2 Topic Action Y/N/DK Evidence/action GDPR Requirements 6. Lawful basis  What is the lawful basis for your processing of data? Lawful bases for necessary processing are:  Clear consent  Contract  Legal obligation eg as employer  Vital interests (protect life)  Public task  Legitimate interests See ICO Guide on lawful processing  Do you have fair processing notices?  Where is that stated?  Have you updated your privacy notice to explain it? 7. Consent  Have you reviewed how you seek, record and manage consent? Consent must be freely given, specific, informed and unambiguous. It cannot be inferred from silence, inactivity or pre-ticked boxes. Do not rely on implied consent. Separate consent requests from other T&C. Simplify unsubscribing. See ICO Consent Guidance  If someone joins your email list do they know the content you will send?  Can you prove their consent?  Do your existing consents meet the GDPR standards? Free choice + positive opt-in  Can they unsubscribe easily? 8. Children  Does your data verify the ages of individuals? GDPR requires specific protection for children’s (below 16YO) personal data and requires parental consent if a child. Your privacy notice should be understandable to children.  Do you need a procedure to get parental consent? 9. Data breaches  Do you have procedures to (1) detect, (2) report and (3) investigate a data breach? GDPR requires you to notify breaches to ICO if it is likely to result in a risk to rights and freedoms of individuals within 72 hours. 10. Privacy Impact Assessment  Has everyone read the ICO Code of Practice on Privacy Impact Assessments? GDPR requires privacy by design. You may need a Data Privacy Impact Assessments. See ICO PIA Guidance Do you know how & when you will implement any DPIA? 11. Data Protection Officers  Do you need a DPO to check compliance? GDPR requires a DPO if you are a public authority, carry out large regular monitoring or large scale processing of specific personal data.  Who is our DPO (or equivalent)? 12. International  If you work across EU member states, who is your lead data protection supervisory authority? Lead authority is where your main establishment is.