
Review/Update/Creation of a third-party vendor management process:
Review/update of the existing third-party vendor assessment process, or creation of such a due diligence process, to ensure your vendors are fully compliant with any Privacy, Compliance and other Regulatory requirements and that the process is simple, accessible and leaves a documented trail of the assessment and its results and that there are periodic reviews in order to maintain compliance of your vendors.
Performance of PIAs and DPIAs and creation of processes to conduct them within your organization:
A Privacy Impact Assessment (PIA) is a process to ensure and enable privacy by design in an organization. PIAs are carried out especially for assessing organizational privacy risk when a new business process is implemented, modified or updated; during business acquisitions, and/or when a product is launched. Also PIAs are not just limited when something new is being implemented, but also when despite the business processes remaining the same, when other circumstances are changing, such as when the business organization is expanding to a different jurisdiction.
A Data Protection Impact Assessment (DPIA) is a process of documentation with an aim to identify and mitigate potential threats/risks associated with the processing of data subjects´ personal data by an organization. Companies must conduct DPIAs especially during the processing of sensitive personal data, while processing large-scale of data subjects’ personal data, and during automated decision-making.
Identification and creation of ROPAs:
The Record of Processing Activities (ROPA) is a requirement in many Privacy regulations all over the world.
Identification of any processing activities, IT systems processing personal data, roles and responsibilities of the staff managing and having access to those systems, collecting all that information and turning it into an organized inventory (either creating a specific template for your company, or leveraging any Privacy tool you might have already acquired).
Periodic review of the ROPAs, as well as keeping a n updated copy for audit purposes.
Reviewing/updating/creating a process to help your organization comply with the Data Subjects´ Privacy Rights:
A Data Subject Access Request (DSAR) is a request addressed to the organization that gives individuals a right to access information about personal data the organization is processing about them and to exercise that right easily, at reasonable intervals, to verify the lawfulness of the processing.
Individuals have other rights they can exercise, like the right to modify their personal data to keep it accurate, the right to object to the processing of their personal data, the portability right, the right of deletion, etc.
Having a process to address any enquiries of individuals exercising their Privacy rights is paramount for any organization and these rights no longer apply exclusively to GDPR territories, but more and more countries are adopting the same approach regarding the rights of individuals towards their personal data.
Reviewing your existing process, updating it if necessary and, should you not have a process yet, designing and implementing one that allows your company to comply with the established procedures for addressing those data subjects´ requests, within the given deadlines and documenting the necessary steps, as well as training your staff to respond to such queries in a compliant manner.
Reviewing/updating/creating a process to help your organization comply with the appropriate data retention and deletion periods:
Review and update of your data retention and data deletion policies and processes, to comply with the applicable Privacy or sectoral regulations. Should you not have the necessary data retention and data deletion policies and processes, creation and implementation of a process, liaising with the appropriate IT providers to guarantee your IT systems comply with the retention and deletion policies and training your staff.
Reviewing/updating/creating a process to help your organization react and manage any data incidents or data breaches in a compliant way:
Review and update of your data incident/data breach management policies and processes, to comply with the applicable Privacy or sectoral regulations. Should you not have the necessary data incident and data breach policies and procedures in place, creation and implementation of such policies and procedures, establishing the notification process to Privacy or other authorities (like Banking or Health Authorities) and to data subjects affected by a data breach, creating a list of case studies to help you determine when you have a data incident or a breach and when you have the duty to notify any of the relevant authorities and/or data subjects and training your staff to detect and alert of any attempts to breach your systems (like phishing, malware, insider threats, etc.) and to react to data incidents or breaches in a compliant way.