{"id":798,"date":"2021-11-19T17:42:01","date_gmt":"2021-11-19T17:42:01","guid":{"rendered":"https:\/\/worldprivacylaw.com\/?p=798"},"modified":"2021-11-19T17:42:01","modified_gmt":"2021-11-19T17:42:01","slug":"important-department-wise-compliance-under-gdpr-part-1","status":"publish","type":"post","link":"https:\/\/worldprivacylaw.com\/?p=798","title":{"rendered":"Important Department wise Compliance under GDPR- Part 1"},"content":{"rendered":"\n<p>In today\u2019s article we will discuss the Specific GDPR requirements applicable to the departments of any organisation and they are:-&nbsp;<\/p>\n\n\n\n<p><strong>A)<\/strong><strong> <\/strong><strong>Data Privacy Office&nbsp;<\/strong><\/p>\n\n\n\n<ol><li>Appointment of Data Protection Officer,Chief Privacy Officer and team<\/li><li>Development and implementation of Personal Information Management System (Policies, Manual, Procedures, Templates, Records etc;)<\/li><li>Data Subject Rights Management<\/li><li>Incident\/Breach Management<\/li><li>Risk Management<\/li><li>Training, Awareness &amp; Certifications<\/li><li>Understanding of the prevailing and upcoming data privacy requirements<\/li><li>Internal Audits through independent auditors<\/li><li>Liaison with the Data Protection\/Supervisory Authorities<\/li><li>Create and maintain inventory of PII\/SPI and its processing details in the company<\/li><li>Privacy Impact Assessment<\/li><li>Cross-border personal data transfer impact assessment<\/li><\/ol>\n\n\n\n<p><strong>B)<\/strong><strong> <\/strong><strong>Legal<\/strong><\/p>\n\n\n\n<p>Inclusion of applicable Data Privacy clauses (on personal data processing and cross border personal data transfer) in the agreements with Clients and Service Providers\/Vendors.<\/p>\n\n\n\n<p><strong>C)<\/strong><strong> <\/strong><strong>Company Secretary&#8217;s Office<\/strong><\/p>\n\n\n\n<p>Handle Shareholder personal data as per the common requirements listed in point 2 above<\/p>\n\n\n\n<p><strong>D)<\/strong><strong> <\/strong><strong>Recruitment\/HR<\/strong><\/p>\n\n\n\n<ol><li>Do not collect PII\/SPI which are discriminatory in nature<\/li><li>Do not process PII\/SPI for purposes not required by employment law and staff welfare<\/li><li>Do not take decisions on employees based on &#8220;automated decision making&#8221; solution<\/li><li>Involve a step of manual intervention and review prior to final decision<\/li><li>Policies on publishing content on social media and collaboration platforms<\/li><li>Separate consents and compliance with other DP procedures for processing PII\/SPI of employee&#8217;s spouse and children<\/li><li>Ensure anonymity in collection\/processing of diversity related data<\/li><\/ol>\n\n\n\n<p><strong>E)<\/strong><strong> <\/strong><strong>Finance (Payroll, Tax, Claims Reimbursements, etc;)<\/strong><\/p>\n\n\n\n<p>Ensure high degree of accuracy while collection and processing of PII\/SPI<\/p>\n\n\n\n<p><strong>Abbreviations-<\/strong><\/p>\n\n\n\n<ol><li><strong>PII<\/strong>&#8211; Personally Identifiable Information<\/li><li><strong>SPI<\/strong>&#8211; Sensitive Personal Information <\/li><\/ol>\n\n\n\n<p>Picture credit- https:\/\/kinsta.com<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In today\u2019s article we will discuss the Specific GDPR requirements applicable to the departments of any organisation and they are:-&nbsp; A) Data Privacy Office&nbsp; Appointment [&#8230;]<\/p>\n","protected":false},"author":2,"featured_media":799,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[9],"tags":[],"_links":{"self":[{"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/posts\/798"}],"collection":[{"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=798"}],"version-history":[{"count":1,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/posts\/798\/revisions"}],"predecessor-version":[{"id":800,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/posts\/798\/revisions\/800"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=\/wp\/v2\/media\/799"}],"wp:attachment":[{"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldprivacylaw.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}