| Awareness | Identify and involve key people |
| Data Protection Officer (DPO) | Appoint someone to be responsible for compliance Act on their guidance |
| Lawful Basis for Processing Data | Identify why you hold personal data and how long you will hold it for |
| Accountability | Put on record how you comply with GDPR principles |
| Privacy Information | What changes need to be made to your Privacy Policy to comply with the GDPR? How will these changes be publicised? |
| Information | Describe the data and basis for holding it, eg for: Employees Customers Suppliers Stakeholders Identify data partners: Who do we get data from? Who do we send data to? |
| Individual Rights | Understand the new rights of individuals Ensure Privacy by Design How do you obtain consent? How do you erase records/delete data? |
| Subject Access Requests | Where do you look for data? How quickly can you respond? |
| Consent | Do you have clear, opted-in permission to hold and use this data? |
| Children | Do you hold children’s data and, if so, do you understand the new requirements? |
| Data Breaches | Understand what a breach is Report breaches to the ICO within 72 hours Understand when to report breaches to data subjects |
| Data Protection by Design | Understand what data your systems store Understand how your systems store data Understand where suppliers’ responsibilities end Understand data partners’ processes & use of data Fix any identified gaps in your protection of data |
| International | If you operate in more than one EU state, identify your data protection Supervisory Authority. |