These are few steps to ensure your company's compliance with privacy laws:
- Identify category of data subjects (individuals) and category of personal data records in your business.
- Check for legal requirements under applicable personal data protection law.
- Identify lifecycle of personal data in your business. Map the data flow in all business processes within the company.
- Include privacy checkpoints in business process maps.
- Record the lifecycle of processes, which involve personal data. Check it periodically and keep it updated.
- Conduct Data Protection Impact Assessment (DPIA) for processes to identify the level of privacy/security risk.
- Make sure that procurement of services/products is subject to a DPIA, if it involves processing of personal data.
- Adopt appropriate data protection clauses in your agreements, where processing of personal data is involved.
- Respond to data subject requests as early as possible within legal timeline. Read domestic exemptions/exceptions before complying with a request.
- Relevant data protection policies, standards & processes should be drafted and accepted as governing constitution. These policies are your go-to guide for any matter related to protection of personal data.
- Perform data privacy audits and provide recommendations to process/function owners, if required.
- Keep yourself aware about new and upcoming privacy laws and also, on guidance from respective data protection authorities.
- All privacy incidents are security incidents too. Have a strong InfoSec framework to ensure protection of personal data and compliance with privacy laws.
- Most important of all is to train your staff that handles personal data in day-to-day business. Privacy Maturity of your company will determine whether or not you're going to get fined for non-compliance. Successful completion of data privacy trainings should be made mandatory.
Mondelēz | Tata Motors |
1 年So informative and contemporary.?
Head-Group Data Privacy & Protection Practice/Platform
1 年Looks great... Just a add on... Monitoring of privacy laws and their requirements as there is always some changes going on.
CIPM (IAPP), LL.M. Data Protection & Privacy I ISO/IEC27701 LI I Certified in Cybersecurity (ISC2) I Healthcare Essentials: IT and Security (ISC2) I CT-DPO I MBA
1 年Excellent listing of most essential steps to carry forward a privacy program. Thanks for sharing.
Chief Privacy Officer @ Tsaaro Consulting | Data Privacy SME
1 年Thanks for sharing!