GDPR Change Management Projects

Written on 29/10/2024. Posted in Uncategorised.

What data protection controls need to be considered for GDPR Change Management Projects?

Some people are surprised to hear that GDPR often does not require Data Protection Impact Assessments (DPIAs) for projects. Read our article about DPIAs and high risk processing for more details.

Internally, you are likely to need to update / review / create:

  1. Records of Processing entry or entries, for the reasons of processing personal data.
  2. Legitimate Interest Assessment, if Legitimate Interest is your legal basis, when you’re not using vital interest, public task, legal obligation, contract or consent.
  3. Consent logs if consent is your legal basis which is typically only needed for some unsolicited direct marketing processing and Cookies.
  4. GDPR Checklist (for Articles 2.5 and 25) to evidence you have considered principles and other controls.
  5. Security risk assessment (Article 32)

Whenever engaging vendors, you should also have:

  1. Vendor security risk assessment and due diligence.
  2. “Data Processing Agreement” as part of the contract (Article 28).
  3. “International Restricted Transfer Safeguards” for internationally transferring data (e.g. EU adequacy, IDTA or EU Standard Contractual Clauses with UK addendum).

Want to know more about GDPR Change Management Projects?

Send us a message. We’re always happy to help.