Onboarding – Part 5 – Summary
Let’s circle back and take a helicopter look at things
Part 1
Who do we have information about and why?
Part 2
Lawful processing
Part 3
Retention periods
Part 4
Systems & Suppliers
Part 5
How it all fits together and how to keep it up
Repetition for the sake of perfection and ongoing compliance
In this episode we go through the lessons learned to make sure we process personal data for well defined purposes and, by applying lawful grounds for processing and retention periods, learn how to differentiate one Processing Activity from another.
The sleep-well-at-night exercise
Well-defined Processing Activities are the key to being lawful under the GDPR. It limits the “what-ifs” and worries of the people for whom you process data, along with your risk of fines and bad press. It also makes it easier to help you and share valuable data with you. Keep your record of processing activities up-to date and make it a part of your toolbox when deciding on new systems and ways of using data.
And remember – we are always here to help!