- what is a legitimate basis for collecting the data (contractual, consent, law-based)
- has consent of data subjects been given in compliance with GDPR
- how, by whom and for how long the data will be processed
- who, when and what actions will take in case data breach would happen
- how to maintain records of processing activities
- how to minimise processing of data
- how to incorporate data protection in all processing activities
- how to ensure data portability
- performs automated decision making in regard to the natural persons (profiling)
- core activities consist of operations which require regular and systematic monitoring of data subjects
- processes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or sex life or sexual orientation
- identify all data flows in organization and corresponding business process owners
- define the scope of the compliance Project, appoint Project manager
- choose professional outsource law counsel, IT support
- identify and implement activities needed to comply, such as (the list is not exhaustive):
- review internal and external privacy policies,
- assess the process of obtaining and recording consent,
- evaluate processor or subprocessor agreements,

















































