Introduction Business Profile Personal & Sensitive Data Staff Awareness and GDPR Training Lawful Data Processing Consent Privacy Policies and Notices Internal Policies and Procedures Third Party Processing Consider Where Your Data Is Stored Data Retention Data Subject Access Rights Data Subject Requests Right to Data Portability Right to Erasure Right to Rectification Right to Object Data Profiling Processed for Specified, Explicit and Legitimate Purposes Adequate, Relevant and Limited Data Processing Accuracy of Data Restriction of Personal Data Processing Privacy by Design Management Of Electronic And Manual Records Data Protection Officers (DPO) Data Breaches Data Protection Impact Assessments Data Security Policy Transfer of Data outside of the EEA Group Companies International Transfers Introduction Business Profile Personal & Sensitive Data Staff Awareness and GDPR Training Lawful Data Processing Consent Privacy Policies and Notices Internal Policies and Procedures Third Party Processing Consider Where Your Data Is Stored Data Retention Data Subject Access Rights Data Subject Requests Right to Data Portability Right to Erasure Right to Rectification Right to Object Data Profiling Processed for Specified, Explicit and Legitimate Purposes Adequate, Relevant and Limited Data Processing Accuracy of Data Restriction of Personal Data Processing Privacy by Design Management Of Electronic And Manual Records Data Protection Officers (DPO) Data Breaches Data Protection Impact Assessments Data Security Policy Transfer of Data outside of the EEA Group Companies International Transfers Questions Is your organisation aware of the rights of a data subjects? NoYesNot ApplicableIs your organisation able to comply with the rights of data subjects in GDPR?NoYesNot Applicable Recommended Actions Your organisation should familiarise itself with the new rights of data subjects set out in GDPR.CompletedNot ApplicableIn Progress