Once you have carried out an audit the next step is to consider whether you are complying with the GDPR principles in order for you to process this data lawfully.
The GDPR sets out a number of principles with which data controllers and processors must comply when processing personal data (Article 5). These principles form the core of the obligations of the data controller and will usually form the basis of any claim that a data controller has not complied with its statutory duties.
A Data Controller is the person or organisation that determines when and how to process personal data – this tends to be in the name of the business
A Data Processor is the person processing the data.
The Principles are:
Not only do you have satisfy the Principles but you must also identify a lawful basis to process Personal data.
To process data you must have a valid lawful basis. Where you are processing special data then you need to satisfy a special condition as well which is explained in the next section under the heading special data.
Looking for Privacy Notice Help?
Buy Your Privacy Notice Online
HR & Health and Safety Support
Tools to help manage and protect your business with online support
HR SERVICES HS SUPPORTHR & Health and Safety Support
Quest provide the tools and work with you remotely to support you and your business
HR SERVICES HS SUPPORTHR & Health and Safety Support
Your personal people solution supporting your business on site
HR SERVICES HS SUPPORT* Please note that all calls may be recorded for training or monitoring purposes.
Email