Introduction Business Profile Personal & Sensitive Data Staff Awareness and GDPR Training Lawful Data Processing Consent Privacy Policies and Notices Internal Policies and Procedures Third Party Processing Consider Where Your Data Is Stored Data Retention Data Subject Access Rights Data Subject Requests Right to Data Portability Right to Erasure Right to Rectification Right to Object Data Profiling Processed for Specified, Explicit and Legitimate Purposes Adequate, Relevant and Limited Data Processing Accuracy of Data Restriction of Personal Data Processing Privacy by Design Management Of Electronic And Manual Records Data Protection Officers (DPO) Data Breaches Data Protection Impact Assessments Data Security Policy Transfer of Data outside of the EEA Group Companies International Transfers Introduction Business Profile Personal & Sensitive Data Staff Awareness and GDPR Training Lawful Data Processing Consent Privacy Policies and Notices Internal Policies and Procedures Third Party Processing Consider Where Your Data Is Stored Data Retention Data Subject Access Rights Data Subject Requests Right to Data Portability Right to Erasure Right to Rectification Right to Object Data Profiling Processed for Specified, Explicit and Legitimate Purposes Adequate, Relevant and Limited Data Processing Accuracy of Data Restriction of Personal Data Processing Privacy by Design Management Of Electronic And Manual Records Data Protection Officers (DPO) Data Breaches Data Protection Impact Assessments Data Security Policy Transfer of Data outside of the EEA Group Companies International Transfers Questions Are there clear procedures in place to notify the controller in the prescribed form of any data breach without undue delay after becoming aware of it? NoYesNot ApplicableDoes your organisation have a policy setting out how it will handle data breaches including reporting and incident management? NoYesNot ApplicableIs there clear internal guidance explaining when notification is required and what information needs to be reported? NoYesNot ApplicableAre there procedures in place to notify DPAs and data subjects of a data breach (where applicable)? NoYesNot ApplicableAre data breaches documented? NoYesNot ApplicableAre there cooperation procedures in place between controllers, suppliers and other partners to deal with data breaches? NoYesNot Applicable ResourcesDownload: Data_Breach_Log_Template Are there cooperation procedures in place between controllers, suppliers and other partners to deal with data breaches? NoYesNot Applicable Recommended Actions You should make sure you have the right procedures in place to detect, report and investigate a personal data breach.CompletedNot ApplicableIn ProgressHave you considered data breach insurance cover?CompletedNot ApplicableIn Progress