1.
Have you identified all the activities involving personal data in your business or organisation?
2.
Do you have a complete record of your data processing activities (ROPA)?
3.
Do you only collect the data that is necessary?
4.
Do you have an internal process to ensure that requests are identified and processed within a set timeframe?
5.
Do you seek consent before collecting any personal data?
6.
Have you secured the personal data that you process - both digital and printed?
7.
Is someone responsible for managing GDPR compliance within your business or organisation?
8.
Have your business or organisation implemented procedures to manage data breaches?
9.
Do you have control over third-party services that handle personal data on your behalf?
10.
Do you inform individuals about their data’s purpose, use, and retention?