GDPR: Where Do I Start? - Articles

Articles

25Sep

GDPR: Where Do I Start?

You’ve determined that your company needs to comply with the GDPR, but deciding on where to begin can be daunting. This section of the GDPR Portal will outline four compliance phases that will take your from square one to implementation and beyond.

PLAN – Take the important first step of bringing together key stakeholders from across your organization to create awareness and accurately assess your compliance needs.

  1. Build Your Team

Identify Stakeholders

Create Awareness

Get Buy-in

  1. Consider Compliance Needs

Conduct Data Inventory

Data Flow Mapping

DO – Once you have designated your team and identified the compliance needs of your organization work to design and put in place appropriate policies and procedures.  

C. Design & Implement Policies and Procedures

                                                Consent

                                                Cross Border Transfers

                                                Respondent/Data Subject Rights

                                                Technical & Administrative Safeguards

                                                Data Necessity, Retention, Disposal

                                                Data Integrity

                                                Data Security & Breach Response Planning

TEST – Review the policies and procedures your organization adopted by testing and evaluating their effectiveness.

D. Evaluate and Improve Policies and Procedures

                                                Impact Assessments

                                                Audits

IMPLEMENT & DOCUMENT – If your new policies and procedures are effective, fully implement them and document compliance! If not, revisit the plan, do, and check steps to improve upon what you tried.

E. Demonstrate Compliance

                                                Ongoing record keeping

                                                Audit trail

Disclaimer: The information provided by the Insights Association is for informational purposes only and not for the purpose of providing legal advice. Please contact your attorney to obtain advice on specific issues or questions.

About the Author

Related

Can You Still Safely Ask Demographic Questions?

Can You Still Safely Ask Demographic Questions?

Some insights professionals and clients are wondering, with the federal government directives agains...

Read More >
Concerns About CFPB Approach to Data Privacy

Concerns About CFPB Approach to Data Privacy

A proposal from the Consumer Financial Protection Bureau (CFPB) could unfairly apply restrictions in...

Read More >
Federal Privacy Legislation Laid Out for Congress Would Respect Consumers and Promote Informed Decision-Making

Federal Privacy Legislation Laid Out for Congress Would Respect Consumers and Promote Informed Decision-Making

In comments to the House Energy & Commerce Committee, the Insights Association (IA) recommended “a ...

Read More >
Utah H.B. 418 Added Consumer Data Correction Right

Utah H.B. 418 Added Consumer Data Correction Right

Utah Governor Spencer Cox (R) signed H.B. 418 into law on March 27, 2025, adding a correction right ...

Read More >
Fighting for You: March 2025 Legislative and Regulatory Update

Fighting for You: March 2025 Legislative and Regulatory Update

March blew in like a lion for the insights industry, but it shows no signs of leaving like a lamb, a...

Read More >
Maryland Considers Data Broker Tax and Registry - H.B. 1089 and S.B. 904

Maryland Considers Data Broker Tax and Registry - H.B. 1089 and S.B. 904

The Maryland Building Information Guardrails Data Act (H.B. 1089, S.B. 904) would tax the gross inco...

Read More >
Members only Article - Please login to view