Ten steps
Ten steps to help you to create a GDPR plan
Law firms as data controllers
Personal data you hold for your employees and clients, and what counts as personal data
Create a record of data processing
Examples of audit and data processing records, lawful, fair and transparent processing
Marketing
From collecting data via your website to direct marketing
Client confidentiality
Exemptions when dealing with personal data
AML and data protection
AML obligations and personal data
Data retention
Retention periods and how you will erase or dispose of personal data
Sharing data
List all the organisations that you share data with on a regular basis
Data protection officers
Identify your data protection lead, whether or not they require a Data Protection Officer
Security
Appropriate technical and organisational measures in relation to processing personal data
Reporting personal data breaches
Notifying the Information Commissioner’s Office of a personal data breach
Requests for copies of personal data
Requests for access to personal data from clients, third parties and others
Appendix 1 - Consent
Only rely on consent if there is no other legal processing condition that you can identify
Example of a data protection policy
Word version of a sample data protection policy
Example of Privacy Notice
Word version of a sample privacy notice