CHECKLISTS Flashcards
What should be reviewed regarding the data subject’s right to privacy?
- Regularly conduct privacy impact assessments,
- implement privacy by design in all new products,
- ensure data subject rights are accessible and easily exercised,
- establish and maintain privacy policies that are communicated to all stakeholders, and
- secure personal data using encryption and other security measures.1
How can you ensure data processing is lawful, fair, and transparent?
- Ensure processing is done on lawful grounds (e.g., consent or legitimate interest).
- Ensure privacy notices are clear, concise, and accessible.
- Regularly update privacy policies to reflect current practices.
- Train employees on lawful and ethical handling of personal data.
- Maintain records of all data processing activities for transparency.12
What steps ensure compliance with the principle of purpose limitation?
- Clearly define and document the purpose for collecting personal data.
- Process data only for the intended purpose or obtain consent for any changes.
- Regularly review data processing to ensure compliance with the stated purpose.
- Inform data subjects of any changes in purpose.23
How can an organization demonstrate adherence to the principle of data minimization?
- Collect only the data necessary for the intended purpose.
- Regularly review and update data collection practices to avoid excessive data gathering.
- Implement tools to reduce or anonymize data where possible.
- Limit access to personal data to authorized personnel.4
What considerations are important when collecting family details?
- Communicate clearly why family details are needed.
- Ensure the collection reason is relevant and lawful.
- Obtain consent if family information is not directly related to the individual.
- Document how family data is processed, stored, and secured.4
How do you ensure the accuracy of personal data throughout its lifecycle?
- Implement processes to maintain accurate and up-to-date data.
- Enable data subjects to review and correct their information.
- Conduct regular audits to check data accuracy.
- Correct or delete inaccurate or outdated data immediately upon discovery.5
What measures should be in place to comply with storage limitations?
- Establish data retention policies.
- Do not store data longer than necessary.
- Implement automated tools for deletion or archiving after the retention period.
- Regularly review data storage practices for obsolete data.
- Securely delete or anonymize unneeded personal data.6
What are the key points to check when auditing consent as a lawful basis for processing?
- Confirm data subjects provided clear, explicit consent.
- Ensure consent requests are specific, informed, and unambiguous.
- Maintain records of how and when consent was obtained.
- Offer an easy way for data subjects to withdraw consent.
- Regularly review and refresh consent, especially for ongoing processing.7
What aspects should be examined when auditing data processing based on the performance of a contract?
Verify processing is necessary to fulfill contractual obligations to the data subject. Document the contractual terms justifying data processing. Ensure processing relates only to contract requirements. Communicate clearly with data subjects about how their data is used regarding the contract. Document requests for pre-contractual steps and how data is processed.8
What factors should be considered when auditing data processing under the legal obligation basis?
Identify the specific legal obligation necessitating data processing. Ensure processing is necessary for compliance. Document the relevant laws or regulations. Clearly communicate to data subjects why their data is processed to meet legal requirements. Regularly review processing to ensure ongoing compliance.9
What points should be verified when auditing processing based on vital interests?
Confirm processing is necessary to protect the life or physical integrity of the data subject or another person. Document situations where vital interests justify processing (e.g., emergencies). Limit processing to what’s strictly necessary to protect vital interests. Consider less intrusive methods before relying on this basis. Communicate transparently with the data subject, if possible, especially after the event.10
What should an audit focus on when processing is based on public interest or official authority?
Confirm processing is necessary for a task in the public interest or as part of official authority. Document the public interest or legal mandate. Ensure processing is proportionate and strictly necessary for public interest tasks. Keep records of official authority or public mandate for transparency. Communicate with data subjects how their data will be processed under this basis.11
When auditing data processing related to tasks of a public authority, what should be reviewed?
Ensure processing is carried out by or on behalf of a public authority. Confirm processing is necessary for the specific public authority task. Document the public authority task justifying processing. Consider data subject rights and ensure processing doesn’t infringe upon them unnecessarily. Ensure transparency about how the data subject’s data is used for public authority tasks.12
What are the key considerations when auditing data processing based on functions of a public nature?
Confirm processing is necessary for performing a function in the public interest. Document the function of a public nature justifying processing. Review the extent to which processing is necessary and proportionate to the public function. Communicate with the data subject about the public nature of the processing. Ensure data subjects are informed about the reasons for processing and the public benefit.13
How should an audit approach data processing justified by legitimate interests?
Verify a Legitimate Interests Assessment (LIA) was conducted. Confirm a balance between the data controller’s legitimate interests and data subject rights and freedoms. Ensure the legitimate interest and LIA outcomes are documented. Communicate to data subjects that processing is based on legitimate interests and allow objections. Ensure processing doesn’t cause unwarranted harm or prejudice to the data subject.14
What considerations are relevant when auditing data processing for research or artistic purposes?
Confirm processing is for historical, statistical, journalistic, literary, artistic, or scientific research. Ensure safeguards are in place to protect data subject rights (e.g., anonymization or pseudonymization). Review whether the data is necessary for research or artistic purposes. Document the research or project objectives justifying processing. Where possible, obtain consent or communicate clearly about the data’s use for these purposes.15
What should an audit verify regarding further processing of data?
Confirm any further processing aligns with the original purpose for which the data was collected. Document reasons for further processing and how they align with the original purpose. Obtain fresh consent or assess another lawful basis if the purpose changes. Communicate with the data subject about any further processing for new purposes.16
What should be assessed when a child’s data is being processed?
Verify that verifiable consent was obtained from the child’s parent or guardian. Ensure a record of parental/guardian consent is kept, including how and when it was obtained. Confirm the processing protects and advances the child’s rights and best interests. Provide parents or guardians with clear information about how their child’s data will be processed. Regularly review consent to ensure continued validity, especially if the child reaches the age of majority.17