|
|
|
xi | |
|
|
|
xii | |
|
|
|
xiv | |
|
|
|
xvi | |
| Preface |
|
xvii | |
|
1 What is the General Data Protection Regulation (GDPR)? |
|
|
1 | (17) |
|
|
|
3 | (1) |
|
|
|
3 | (2) |
|
The link to previous legislation |
|
|
5 | (1) |
|
The European Data Protection Board and national Supervisory Authorities |
|
|
5 | (1) |
|
Who has to comply with GDPR? |
|
|
6 | (1) |
|
|
|
7 | (1) |
|
The penalties for Data Breaches |
|
|
8 | (3) |
|
GDPR compliance as an ongoing journey |
|
|
11 | (1) |
|
|
|
11 | (2) |
|
|
|
13 | (5) |
|
|
|
18 | (13) |
|
GDPR terms --- people or entities |
|
|
18 | (1) |
|
GDPR terms --- types of personal data |
|
|
19 | (1) |
|
|
|
20 | (2) |
|
|
|
22 | (1) |
|
GDPR terms - the principles of GDPR |
|
|
23 | (1) |
|
GDPR terms --- lawful basis |
|
|
23 | (1) |
|
GDPR terms --- subject rights |
|
|
23 | (3) |
|
|
|
26 | (5) |
|
3 The GDPR Articles and Recitals |
|
|
31 | (52) |
|
|
|
31 | (3) |
|
The GDPR Articles explained "in a nutshell" |
|
|
34 | (49) |
|
4 Applying GDPR to your organisation |
|
|
83 | (18) |
|
How does GDPR apply to my business? |
|
|
83 | (4) |
|
|
|
87 | (1) |
|
|
|
88 | (10) |
|
|
|
98 | (3) |
|
5 Data Controllers, Data Processors and the Data Protection Officer |
|
|
101 | (16) |
|
|
|
102 | (1) |
|
|
|
103 | (7) |
|
|
|
110 | (3) |
|
|
|
113 | (1) |
|
Data Protection Officer (DPO) |
|
|
114 | (3) |
|
6 Analysing what personal data you hold |
|
|
117 | (17) |
|
|
|
117 | (4) |
|
Special categories of information |
|
|
121 | (5) |
|
|
|
126 | (1) |
|
What does GDPR mean by identified? |
|
|
126 | (4) |
|
Personal data in the case study organisation |
|
|
130 | (1) |
|
Deciding what information can be used to identify a person |
|
|
130 | (2) |
|
Fill in the personal data grid for your organisation |
|
|
132 | (2) |
|
7 Privacy Policies and Notices |
|
|
134 | (13) |
|
Why do I need a Privacy Policy? |
|
|
134 | (1) |
|
What information should a privacy document contain? |
|
|
134 | (3) |
|
How should privacy information be presented? |
|
|
137 | (1) |
|
Deciding what your privacy document includes |
|
|
138 | (2) |
|
Benefits of a Privacy Policy |
|
|
140 | (1) |
|
|
|
140 | (1) |
|
Creating a Privacy Notice/statement |
|
|
140 | (3) |
|
|
|
143 | (4) |
|
8 Recording your processing activities |
|
|
147 | (23) |
|
Why do I need to map the data? |
|
|
150 | (1) |
|
Is a Data Flow Analysis or Data Audit compulsory? |
|
|
151 | (1) |
|
|
|
151 | (1) |
|
Understanding how dataflows in an organisation |
|
|
151 | (2) |
|
|
|
153 | (12) |
|
|
|
165 | (2) |
|
Data Protection Impact Assessment (DPIA) |
|
|
167 | (2) |
|
|
|
169 | (1) |
|
9 Sharing information electronically |
|
|
170 | (15) |
|
|
|
171 | (7) |
|
|
|
178 | (5) |
|
|
|
183 | (1) |
|
|
|
184 | (1) |
|
Email security and the data governance policy |
|
|
184 | (1) |
|
|
|
185 | (8) |
|
|
|
185 | (1) |
|
|
|
186 | (3) |
|
Planning how to deal with a breach |
|
|
189 | (3) |
|
|
|
192 | (1) |
|
|
|
193 | (10) |
|
|
|
194 | (1) |
|
The GDPR data security requirement |
|
|
195 | (1) |
|
What does data security mean? |
|
|
195 | (1) |
|
Identify data security risks |
|
|
195 | (1) |
|
Put in place data security measures |
|
|
196 | (1) |
|
Physical security measures |
|
|
197 | (1) |
|
|
|
197 | (2) |
|
Testing your security measures |
|
|
199 | (1) |
|
|
|
199 | (1) |
|
|
|
200 | (1) |
|
Keeping yourself "cyber safe" |
|
|
200 | (3) |
|
12 Retaining and deleting data |
|
|
203 | (9) |
|
|
|
203 | (2) |
|
|
|
205 | (1) |
|
|
|
205 | (1) |
|
|
|
206 | (1) |
|
|
|
206 | (5) |
|
Retaining data from dashcams/helmet cams/CCTV |
|
|
211 | (1) |
|
13 An individual's rights under GDPR |
|
|
212 | (19) |
|
Providing information to individuals |
|
|
212 | (1) |
|
|
|
212 | (2) |
|
Individual's data access options |
|
|
214 | (1) |
|
|
|
215 | (9) |
|
Freedom of Information Act |
|
|
224 | (3) |
|
Accessing educational and medical records |
|
|
227 | (2) |
|
Individuals' rights - exemptions |
|
|
229 | (2) |
|
|
|
231 | (9) |
|
|
|
231 | (1) |
|
What should the training include? |
|
|
232 | (5) |
|
Guidance on handling, retaining, sharing and deleting data |
|
|
237 | (1) |
|
Details of how the organisation uses marketing including direct under GDPR |
|
|
238 | (1) |
|
|
|
238 | (1) |
|
|
|
238 | (2) |
| Gdpr resource links |
|
240 | (5) |
| Index |
|
245 | |