Context:
Having a well rounded set of data protection policies is not only required by the GDPR but is good business practice.
Considerations:
Your data protection policies should not be a one time activity. Ensure that they are reviewed regularly to make sure they continue to be fit for purpose.
Make sure to communicate the policy and to train your staff so that they understand and abide by the policies set out by your organisation.
How to:
Have a set of data protection policies that cover the broad data protection principles that the GDPR underpins.
- lawful, fair and transparent processing
- Used for the specified, legitimate purpose
- Relevant and limited to only what is necessary
- Accurate and up to date
- Retained only for as long as it necessary
- Appropriately secured
References:
- GDPR Recitals: 74
- GDPR Articles: 24, 5