May 2018 is almost two years behind us.
So, can you now answer the following questions?
- What personal data do we process?
- Do we have a data classification in place that allows us to filter Personal Identifiable Information?
- Does this classification allow a distinction between data that must legally be kept versus "I want to be forgotten" data?
- Is the classification an automated process?
- How do we
- Where are these data stored?
- Usually not only in online processes but also in Test, Development environments. What about backups and archives?
- How shall we deal we future requests for "data portability"?
- Who has access to these data?
- Do you have an INDEPENT DPO? A what? A Data Protection Officer?
- Do our processes that handle PII produce the required documentation so we can prove our commitment ?
- Do our processes that handle PII produce the required documentation so we can prove our commitment ?
If you are unsure, let us help you to accompany towards a GDPR friendly environment. We'll turn this into is an opportunity, not a sunk cost.