{"id":12156,"date":"2017-09-29T15:31:10","date_gmt":"2017-09-29T15:31:10","guid":{"rendered":"https:\/\/www.process.st\/templates\/gdpr-checklist-for-businesses\/"},"modified":"2024-03-21T12:35:35","modified_gmt":"2024-03-21T12:35:35","slug":"gdpr-checklist-for-businesses","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/gdpr-checklist-for-businesses\/","title":{"rendered":"GDPR Checklist for Businesses"},"content":{"rendered":"\n<section id=\"intro-to-gdpr-checklist-for-businesses\">\n <h2>Intro to GDPR Checklist for Businesses:<\/h2>\n <div class=\"image-content\">\n  <figure>\n   <a href=\"https:\/\/ps-attachments.s3.amazonaws.com\/fab1c65c-0ed8-4814-b47c-64863fdfaad7\/o8HV9vLNEeYNk501Mk9Pdg.png\" alt=\"Intro to GDPR Checklist for Businesses:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/ps-attachments.s3.amazonaws.com\/fab1c65c-0ed8-4814-b47c-64863fdfaad7\/o8HV9vLNEeYNk501Mk9Pdg.png\"> <\/a><!-- No caption -->\n  <\/figure>\n <\/div>\n <div class=\"text-content\">\n  <p>This GDPR checklist for businesses is <strong>built on the basis of official ICO guidelines and recommendations<\/strong>.&nbsp;<\/p>\n  <p>Using this checklist will help you structure your business to adhere to the GDPR.<\/p>\n  <p>It is important to note, however, that <strong>an independent consultant should be sought to assist your compliance<\/strong> and you shouldn't rely solely on this checklist.<\/p>\n  <p>For many large companies, you won\u2019t have to run this checklist only once, but many times. Different teams or wings of the company will need to analyze their activities for non-compliant structures or processes.&nbsp;<\/p>\n  <p>All data entered into the form fields throughout the checklist will be saved in the <a href=\"https:\/\/www.process.st\/help\/docs\/template-overview\/\" rel=\"nofollow noopener\" target=\"_blank\">template overview<\/a> tab so that the appointed Data Protection Officer can monitor the responses and information from each team.<\/p>\n  <p>This is designed to help large companies <strong>create a system of oversight quickly and easily<\/strong>.<\/p>\n  <p>Watch the video below for an introduction to GDPR or read our accompanying article: <a href=\"http:\/\/process.st\/gdpr-compliance\" rel=\"nofollow noopener\" target=\"_blank\">How to Be GDPR Compliant: A Guide for SaaS and Beyond<\/a>.<\/p>\n <\/div>\n <div class=\"video-content\">\n  <div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/XVBHishpew8?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n  <div class=\"description\">\n   What is the GDPR?\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"record-checklist-details\">\n <h2>Record checklist details<\/h2>\n <div class=\"text-content\">\n  <p>Use this section to <strong>record the details of who is completing the checklist<\/strong> and why.&nbsp;<\/p>\n  <p>You can edit this section to include form fields specific to your business.<\/p>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Person responsible for following this checklist <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"email-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Email of the responsible person <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Data Protection Officer <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"email-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Email of DPO <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Company <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Team, if applicable <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"date-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Date of beginning the process <\/label>\n   <div class=\"date-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button>\n   <\/div>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"make-your-team-or-company-aware-of-gdpr\">\n <h2>Make your team or company aware of GDPR<\/h2>\n <div class=\"text-content\">\n  <p>It is important to <strong>make sure other members of your team or organization are aware of GDPR<\/strong> and its potential ramifications.&nbsp;<\/p>\n  <p>Stressing the importance of these changes to data regulations will help to encourage compliance throughout the team or organization.&nbsp;<\/p>\n  <p>You could <strong>call a meeting to present the risks of GDPR<\/strong> and the steps needed to ensure compliance or you could <strong>use the email widget below to notify people<\/strong> within the team or organization that the process of adhering to the GDPR is beginning.&nbsp;<\/p>\n <\/div>\n <div class=\"text-content\">\n  <p><strong>Use the form field below<\/strong> to document the steps you took to provide awareness throughout the company.<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Steps taken for awareness <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"document-information-held-by-the-company\">\n <h2>Document information held by the company<\/h2>\n <div class=\"text-content\">\n  <p>It is important to make sure all activities related to data are well documented.&nbsp;<\/p>\n  <p>To begin, document:<\/p>\n  <ul>\n   <li>What personal data you hold<\/li>\n   <li>Where that data came from<\/li>\n   <li>Who that data is shared with<\/li>\n   <li>Why that data remains held<\/li>\n  <\/ul>\n  <p>Documenting this information places you <strong>in line with the GDPR's accountability principle<\/strong>.<\/p>\n  <p><strong>Use the form fields below<\/strong> to briefly summarize each of these concerns.&nbsp;<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> What data is held? <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Where did that data come from? <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Who is that data shared with? <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Why is that data held? <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"review-existing-privacy-notices\">\n <h2>Review existing privacy notices<\/h2>\n <div class=\"text-content\">\n  <p><strong>The GDPR requires certain changes to privacy notices<\/strong> and these should be reviewed alongside your existing practices.&nbsp;<\/p>\n  <p>The privacy&nbsp;notices codes of practice can be found here: <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/privacy-notices-transparency-and-control\/\" rel=\"nofollow noopener\" target=\"_blank\">Privacy Notices, Transparency and Control<\/a>. &nbsp;<\/p>\n  <p>When you collect data you normally inform the subject who you are and how you intend to use the data. This is common practice.&nbsp;<\/p>\n  <p>Under the GDPR you will need to add a few more elements:<\/p>\n  <ul>\n   <li>Explain your lawful basis for processing the data<\/li>\n   <li>Explain your data retention periods<\/li>\n   <li>Explain the individual's rights in regards to the complaints process to the ICO.&nbsp;<\/li>\n  <\/ul>\n  <p>The GDPR states that this information must be delivered in <strong>a concise fashion with clear and easy to understand language<\/strong>.&nbsp;<\/p>\n  <p>Use the form field below to note the specific changes you need to, and intend, to make.&nbsp;<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Required changes to privacy notices <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"check-your-procedures-protect-individuals-rights\">\n <h2>Check your procedures protect individuals' rights<\/h2>\n <div class=\"text-content\">\n  <p>The GPDR confers a series of rights and freedoms to individuals in respect to their data.&nbsp;<\/p>\n  <p>It is your responsibility to make sure your company's actions allow for the fulfillment&nbsp;of these rights.<\/p>\n  <p><strong>The following rights should be respected<\/strong>:<\/p>\n  <ul>\n   <li>The right to be informed;<\/li>\n   <li>The right of access;<\/li>\n   <li>The right to rectification;<\/li>\n   <li>The right to erasure;<\/li>\n   <li>The right to restrict processing;<\/li>\n   <li>The right to data portability;<\/li>\n   <li>The right to object; and<\/li>\n   <li>The right not to be subject to automated decision-making including<br>\n    profiling.<\/li>\n  <\/ul>\n  <p><strong>Devise a series of example cases and work through each scenario<\/strong> to understand exactly how the company will respond to these requests.&nbsp;<\/p>\n  <p>If you do not already have procedures which protect these rights, <strong>it is important to create those procedures<\/strong>.<\/p>\n  <p><strong>Use the form field below<\/strong> to link to where these documented processes can be found. You can use Process Street to document your procedures.<\/p>\n <\/div>\n <div class=\"url-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Web address of procedures <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"prepare-for-subject-access-requests\">\n <h2>Prepare for subject access requests<\/h2>\n <div class=\"text-content\">\n  <p>The GDPR provides individuals greater rights in regards to accessing their data.&nbsp;<\/p>\n  <p>Your company must provide appropriate means to access that data. This could be simply responding to access requests as and when they arrive, or you may consider creating a system whereby customers can access their own records.&nbsp;<\/p>\n  <p>How you choose to implement this depends on the specific conditions within your company.<\/p>\n  <p><strong>The ICO provides the following guidelines<\/strong>:<\/p>\n  <ul>\n   <li>In most cases you will not be able to charge for complying with a<br>\n    request.<\/li>\n   <li>You will have a month to comply, rather than the current 40 days.<\/li>\n   <li>You can refuse or charge for requests that are manifestly unfounded<br>\n    or excessive.<\/li>\n   <li>If you refuse a request, you must tell the individual why and that<br>\n    they have the right to complain to the supervisory authority and to<br>\n    a judicial remedy. You must do this without undue delay and at the<br>\n    latest, within one month.<\/li>\n  <\/ul>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Document how your existing system deals with subject access requests <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Document the proposed changes to the system for processing subject access requests <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"identify-the-lawful-basis-for-your-processing-activity\">\n <h2>Identify the lawful basis for your processing activity<\/h2>\n <div class=\"text-content\">\n  <p>The ICO provides<strong> 6 key lawful justifications<\/strong> for processing activity:<\/p>\n  <ul>\n   <li>6(1)(a) \u2013 Consent of the data subject<\/li>\n   <li>6(1)(b) \u2013 Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract<\/li>\n   <li>6(1)(c) \u2013 Processing is necessary for compliance with a legal obligation<\/li>\n   <li>6(1)(d) \u2013 Processing is necessary to protect the vital interests of a data subject or another person<\/li>\n   <li>6(1)(e) \u2013 Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller<\/li>\n   <li>6(1)(f ) \u2013 Necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests, rights or freedoms of the data subject<\/li>\n  <\/ul>\n  <p>Whenever you are processing data, <strong>your documentation for that process should make clear upon what justification it is based.&nbsp;<\/strong><\/p>\n  <p>Use the form field below to identify your different processing activities and which lawful justification applies to each.&nbsp;<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Lawful justifications of processing activity <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"review-how-you-seek-record-and-manage-consent\">\n <h2>Review how you seek, record, and manage consent.<\/h2>\n <div class=\"text-content\">\n  <p>Consent plays a big role in the GDPR and <strong>its outline should be understood by all members of the team.&nbsp;<\/strong><\/p>\n  <p>The Data Protection Officer and other key decision makers in regards to data security and access should read the ICO's consultation paper: <a href=\"https:\/\/ico.org.uk\/media\/about-the-ico\/consultations\/2013551\/draft-gdpr-consent-guidance-for-consultation-201703.pdf\" rel=\"nofollow noopener\" target=\"_blank\">GDPR Consent Guidance<\/a>.<\/p>\n  <p>Below are <strong>three checklists from the ICO<\/strong> to guide you through your consent management.<\/p>\n <\/div>\n <div class=\"text-content\">\n  <h5>Asking for consent<\/h5>\n <\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> (Subtasks) <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      1\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We have checked that consent is the most appropriate lawful basis for processing\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      2\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We have made the request for consent prominent and separate from our terms and conditions\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      3\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We ask people to positively opt in\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      4\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We don\u2019t use pre-ticked boxes, or any other type of consent by default\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      5\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We use clear, plain language that is easy to understand\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      6\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We specify why we want the data and what we\u2019re going to do with it\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      7\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We give granular options to consent to independent processing operations\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      8\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We have named our organisation and any third parties\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      9\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We tell individuals they can withdraw their consent\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      10\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We ensure that the individual can refuse to consent without detriment\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      11\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We don\u2019t make consent a precondition of a service\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      12\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     If we offer online services directly to children, we only seek consent if we have age-verification and parental-consent measures in place\n    <\/div><\/li>\n  <\/ul>\n <\/div>\n <div class=\"text-content\">\n  <h5>Recording consent<\/h5>\n <\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> (Subtasks) <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      1\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We keep a record of when and how we got consent from the individual\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      2\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We keep a record of exactly what they were told at the time\n    <\/div><\/li>\n  <\/ul>\n <\/div>\n <div class=\"text-content\">\n  <h5>Managing consent<\/h5>\n <\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> (Subtasks) <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      1\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We regularly review consents to check that the relationship, the processing and the purposes have not changed\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      2\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We have processes in place to refresh consent at appropriate intervals, including any parental consents\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      3\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We consider using privacy dashboards or other preference-management tools as a matter of good practice\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      4\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We make it easy for individuals to withdraw their consent at any time, and publicise how to do so\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      5\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We act on withdrawals of consent as soon as we can\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      6\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     We don\u2019t penalise individuals who wish to withdraw consent\n    <\/div><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"assess-whether-ageverification-is-needed\">\n <h2>Assess whether age-verification is needed<\/h2>\n <div class=\"text-content\">\n  <p>Within the GDPR, consent is of great importance. However, not all individuals online have the capacity to give consent.&nbsp;<\/p>\n  <p>You need to assess your policies to see whether you need to put systems in place to protect children who are unable to consent to the gathering or processing of their data.&nbsp;<\/p>\n  <p><strong>The ICO gives the following guidance<\/strong>:<\/p>\n  <p style=\"padding-left: 30px;\"><em>If your organization offers online services (\u2018information society services\u2019) to children and relies on consent to collect information about them, then you may need a parent or guardian\u2019s consent in order to process their personal data lawfully. The GDPR sets the age when a child can give their own consent to this processing at 16 (although this may be lowered to a minimum of 13 in the UK). If a child is younger then you will need to get consent from a person holding \u2018parental responsibility\u2019.<\/em><\/p>\n  <p>You must take steps to ensure children can understand your requests for consent and that consent of a person holding parental responsibility has been granted.&nbsp;<\/p>\n  <p><strong>Use the form field below<\/strong> to document the changes you believe your organization will need to make.<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Steps to protect the data of children <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"make-sure-you-have-procedures-in-place-for-data-breaches\">\n <h2>Make sure you have procedures in place for data breaches<\/h2>\n <div class=\"text-content\">\n  <p>You need to make sure your procedures cover the<strong> detection, reporting, and investigating of data breaches<\/strong> and the risks to personal data.&nbsp;<\/p>\n  <p>In the case of a breach, the company must inform the relevant regulatory body within 72 hours of finding out about it. Best practice is to inform the regulatory body as soon as is possible.<\/p>\n  <p>The same applies to the individuals you hold data on. <strong>The company must contact any individuals to make them aware that their data has been breached<\/strong> if this is seen to pose a danger to their rights or freedoms.&nbsp;<\/p>\n  <p>There are a few exceptions:<\/p>\n  <ul>\n   <li>If the data has been encrypted to the point of being unintelligible.<\/li>\n   <li>If the data controller has taken the necessary steps to make sure the breach doesn\u2019t put rights or freedoms at risk.<\/li>\n   <li>If it would involve a disproportionate amount of effort to inform each individual. In this scenario a public announcement would suffice.<\/li>\n  <\/ul>\n  <p><strong>Use the form field below<\/strong> to link to your relevant procedures. You can use Process Street to document, manage, and run these processes.<\/p>\n <\/div>\n <div class=\"url-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Data breach procedures <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"perform-the-required-assessments\">\n <h2>Perform the required assessments<\/h2>\n <div class=\"text-content\">\n  <p>There are a series of standard assessments you should carry out to <strong>make sure you are delivering privacy by design<\/strong>.&nbsp;<\/p>\n  <p>The GDPR refers to Privacy Impact Assessments (PIAs) as Data Protection Impact Assessments (DPIAs) and makes these DPIAs mandatory in certain circumstances.&nbsp;<\/p>\n  <p><strong>The ICO Gives the following guidance<\/strong>:<\/p>\n  <p>A DPIA is required in situations where data processing is likely to result in<br>\n   high risk to individuals, for example:<\/p>\n  <ul>\n   <li>where a new technology is being deployed;<\/li>\n   <li>where a profiling operation is likely to significantly affect<br>\n    individuals; or<\/li>\n   <li>where there is processing on a large scale of the special categories<br>\n    of data.<\/li>\n  <\/ul>\n  <p>It is recommended that you read the <a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1595\/pia-code-of-practice.pdf\" rel=\"nofollow noopener\" target=\"_blank\">ICO guidance document on PIAs<\/a> and the guidance from the <a href=\"http:\/\/ec.europa.eu\/newsroom\/just\/item-detail.cfm?item_id=50083.\" rel=\"nofollow noopener\" target=\"_blank\">Article 29 Working Party<\/a>.<\/p>\n  <p><strong>Use the form field below<\/strong> to upload your Data Protection Impact Assessment.<\/p>\n <\/div>\n <div class=\"file-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Data Protection Impact Assessment <\/label>\n   <div class=\"file-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"appoint-a-data-protection-officer\">\n <h2>Appoint a Data Protection Officer<\/h2>\n <div class=\"text-content\">\n  <p>If you haven't already appointed a Data Protection Officer, now is the time to do so.&nbsp;<\/p>\n  <p>If you are running this checklist for the first time for your whole organization then you likely do not have a Data Protection Officer at this point in time.&nbsp;<\/p>\n  <p>If you are running this checklist as a smaller team within a larger organization, this checklist is likely feeding data back to your Data Protection Officer already.&nbsp;<\/p>\n  <p>The ICO tells us <strong>we need to formally appoint a Data Protection Officer if certain conditions apply<\/strong>:<\/p>\n  <ul>\n   <li>a public authority (except for courts acting in their judicial capacity);<\/li>\n   <li>an organisation that carries out the regular and systematic monitoring of individuals on a large scale; or<\/li>\n   <li>an organisation that carries out the large scale processing of special categories of data, such as health records, or information about criminal convictions.<\/li>\n  <\/ul>\n  <p>Guidance from the Article 29 Working Party can be found here: <a href=\"http:\/\/ec.europa.eu\/newsroom\/just\/item-detail.cfm?item_id=50083.\" rel=\"nofollow noopener\" target=\"_blank\">Article 29 Working Party Overview<\/a>.<\/p>\n  <p><strong>The specific report on Data Protection Officers can be found as a PDF hosted below.<\/strong><\/p>\n <\/div>\n <div class=\"text-content\">\n  <p><strong>Use the form fields below<\/strong>, if applicable, to name your new Data Protection Officer and why they were selected.<\/p>\n <\/div>\n <div class=\"text-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> New Data Protection Officer <\/label> <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Rationale for DPO appointment <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Reason for why the company needs a DPO <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"identify-your-supervisory-authority\">\n <h2>Identify your supervisory authority<\/h2>\n <div class=\"text-content\">\n  <p>If your organization operates in more than one EU member state, it is important to identify which organization will act as your lead data protection supervisory authority.<\/p>\n  <p><strong>The ICO gives the following guidance<\/strong>:<\/p>\n  <p style=\"padding-left: 30px;\">The lead authority is the supervisory authority in the state where your main establishment is. Your main establishment is the location where your central administration in the EU is or else the location where decisions about the purposes and means of processing are taken and implemented.<\/p>\n  <p style=\"padding-left: 30px;\">This is only relevant where you carry out cross-border processing \u2013 ie you have establishments in more than one EU member state or you have a single establishment in the EU that carries out processing which substantially affects individuals in other EU states.<\/p>\n  <p>For more information, you can <strong>review the two documents uploaded below<\/strong> created by the Article 29 Working Party:<\/p>\n <\/div>\n <div class=\"text-content\">\n  <p><strong>Use the form fields below<\/strong> to record the important information.<\/p>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Record your main establishment <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n <div class=\"textarea-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Record your lead supervisory authority <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"sources\">\n <h2>Sources:<\/h2>\n <div class=\"text-content\">\n  <ul>\n   <li><a href=\"https:\/\/ico.org.uk\/media\/for-organisations\/documents\/1624219\/preparing-for-the-gdpr-12-steps.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Preparing for the General Data Protection Regulation (GDPR): 12 Steps to Take Now - ICO<\/a><\/li>\n   <li><a href=\"http:\/\/ec.europa.eu\/newsroom\/just\/item-detail.cfm?item_id=50083.\" rel=\"nofollow noopener\" target=\"_blank\">Article 29 Working Party - European Commission<\/a>&nbsp;<\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"related-checklists\">\n <h2>Related Checklists:<\/h2>\n <div class=\"text-content\">\n  <ul>\n   <li><a href=\"https:\/\/www.process.st\/checklist\/iso-9000-structure-template\/\" rel=\"nofollow noopener\" target=\"_blank\">ISO 9000 Structure Template<\/a><\/li>\n   <li><a href=\"https:\/\/www.process.st\/checklist\/pci-compliance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">PCI Compliance Checklist<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Intro to GDPR Checklist for Businesses: This GDPR checklist for businesses is built on the basis of official ICO guidelines and recommendations.&nbsp; Using this checklist will help you structure your business to adhere to the GDPR. It is important to note, however, that an independent consultant should be sought to assist your compliance and you [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":12157,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"\ud83d\udd12","cover_icon_url":"","tasks_count":"16","template_description":"Run this GDPR checklist to implement GDPR adherence in your organization or team using ICO recommended approaches.","template_id":"mx6pWBirQIXJowxrdrBEqg","task_0":"Intro to GDPR Checklist for Businesses:","task_slug_0":"intro-to-gdpr-checklist-for-businesses","task_1":"Record checklist details","task_slug_1":"record-checklist-details","task_2":"Make your team or company aware of GDPR","task_slug_2":"make-your-team-or-company-aware-of-gdpr","task_3":"Document information held by the company","task_slug_3":"document-information-held-by-the-company","task_4":"Review existing privacy notices","task_slug_4":"review-existing-privacy-notices","task_5":"Check your procedures protect individuals' rights","task_slug_5":"check-your-procedures-protect-individuals-rights","task_6":"Prepare for subject access requests","task_slug_6":"prepare-for-subject-access-requests","task_7":"Identify the lawful basis for your processing activity","task_slug_7":"identify-the-lawful-basis-for-your-processing-activity","task_8":"Review how you seek, record, and manage consent.","task_slug_8":"review-how-you-seek-record-and-manage-consent","task_9":"Assess whether age-verification is needed","task_slug_9":"assess-whether-ageverification-is-needed","task_10":"Make sure you have procedures in place for data breaches","task_slug_10":"make-sure-you-have-procedures-in-place-for-data-breaches","task_11":"Perform the required assessments","task_slug_11":"perform-the-required-assessments","task_12":"Appoint a Data Protection Officer","task_slug_12":"appoint-a-data-protection-officer","task_13":"Identify your supervisory authority","task_slug_13":"identify-your-supervisory-authority","task_14":"Sources:","task_slug_14":"sources","task_15":"Related Checklists:","task_slug_15":"related-checklists","task_16":"","task_slug_16":"","task_17":"","task_slug_17":"","task_18":"","task_slug_18":"","task_19":"","task_slug_19":"","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[5,7,16],"tags":[],"class_list":["post-12156","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-featured","category-miscellaneous","category-quality-assurance"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/12156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=12156"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/12156\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/12157"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=12156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=12156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=12156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}