Important Department wise Compliance under GDPR- Part 1

In today’s article we will discuss the Specific GDPR requirements applicable to the departments of any organisation and they are:- 

A) Data Privacy Office 

  1. Appointment of Data Protection Officer,Chief Privacy Officer and team
  2. Development and implementation of Personal Information Management System (Policies, Manual, Procedures, Templates, Records etc;)
  3. Data Subject Rights Management
  4. Incident/Breach Management
  5. Risk Management
  6. Training, Awareness & Certifications
  7. Understanding of the prevailing and upcoming data privacy requirements
  8. Internal Audits through independent auditors
  9. Liaison with the Data Protection/Supervisory Authorities
  10. Create and maintain inventory of PII/SPI and its processing details in the company
  11. Privacy Impact Assessment
  12. Cross-border personal data transfer impact assessment

B) Legal

Inclusion of applicable Data Privacy clauses (on personal data processing and cross border personal data transfer) in the agreements with Clients and Service Providers/Vendors.

C) Company Secretary’s Office

Handle Shareholder personal data as per the common requirements listed in point 2 above

D) Recruitment/HR

  1. Do not collect PII/SPI which are discriminatory in nature
  2. Do not process PII/SPI for purposes not required by employment law and staff welfare
  3. Do not take decisions on employees based on “automated decision making” solution
  4. Involve a step of manual intervention and review prior to final decision
  5. Policies on publishing content on social media and collaboration platforms
  6. Separate consents and compliance with other DP procedures for processing PII/SPI of employee’s spouse and children
  7. Ensure anonymity in collection/processing of diversity related data

E) Finance (Payroll, Tax, Claims Reimbursements, etc;)

Ensure high degree of accuracy while collection and processing of PII/SPI

Abbreviations-

  1. PII– Personally Identifiable Information
  2. SPI– Sensitive Personal Information

Picture credit- https://kinsta.com