STRUCTURED PLANNING OF THE GDPR
As of May 25, 2018, the General Data Protection Regulation (DSGVO or GDPR) applies to the processing of personal data in the member states of the European Union. The GDPR brings with it numerous new requirements, in particular also increased documentation obligations. For companies, the regulation has significant consequences, as in addition to claims for damages, there are now also significant penalties for violations of the GDPRO.
Is your company already prepared? What measures are still missing for the GDPR implementation?
The documentation obligation includes, among other things:
- Creation of a binding data protection policy
- Sensitization, education and training of employees
- Compliance with data protection principles such as lawfulness, purpose limitation, etc. Fulfillment of information obligations
- Documentation of declarations of consent
- Creation and ongoing updating of a procedure directory
- Procedures for compliance with data subject rights, e.g., information and deletion
- If necessary, a data protection impact assessment
- Implementation of the “Privacy by Design / Privacy by Default” principles
- Implementation of appropriate state-of-the-art technical and organizational data security measures
- Fulfillment of notification obligations in the event of data protection breaches
- Management and control of processors, e.g. contracts, confidentiality agreements, audit rights, certifications
- Appointment of a data protection officer if required
- Planning and conducting audits
Our approach: Structured approach to implementation
A documented and structured approach, e.g. in the form of a data protection management system, provides a significantly improved starting position in the event of damage or an audit by the authorities. Penalties can be reduced by this precaution if necessary or converted into a warning.
The SEC4YOU GDPR Readiness Check is a survey of the maturity level with regard to the requirements of the General Data Protection Regulation and the national adaptations and defines the measures still to be implemented. For this purpose, we rely on norms and standards that are considered “state of the art” and adapt the required measures to the customer environment in a targeted manner. Relevant regulation articles are compared with existing measures, from which a list of additional measures required to comply with the General Data Protection Regulation is derived.
Part of the reporting is a management-ready summary that enables management to initiate the further necessary steps in a prioritized manner.
Results from the SEC4YOU GDPR Readiness Check are:
- Assessment of existing processes according to the GDPR
- Customer-specific recommendation for the implementation of a data protection management system
- Prioritized catalog of measures of open activities
Further information:
Y O U R A D V A N T A G E S
- Fast maturity measurement of the GDPR requirements
- You receive a management report as a basis for decision-making
- Prioritized catalog of measures
- Recommendation regarding a data protection management system
Questions about the GDPR Readiness Check?
Would you like to speak with an expert?