5-point privacy checklist to get you started, no matter where you are in your privacy journey:
1.
What types of data do you collect?
Can you also justify why you collect each type of data? It needs to be documented. UK and EU data protection laws require this.
2.
How do you use the data you collect?
Can you explain how the data is used, and where it is stored? Records for data processing are required.
3.
Do you have a privacy policy?
Is your policy accurate? If you have a website, does the policy mention cookies?
4.
If an email account or system was compromised, what would you do?
Don't panic! This event could be classed as something called a 'data breach'. Get a process in place to protect and secure the data.
5.
Has a customer or client ever asked for a copy of their data?
This is a perfectly legal request. Can you answer them with confidence and also provide them with the correct types of data?
