Lawful Data Processing

Questions

Please check all the processing activities that apply to your Sales and Marketing Department (Records of Processing Activities)   

  • CRM (Customer Relationship Management)
  • Event marketing
  • Digital marketing
  • Social Media Marketing & Advertising
  • Lead generation
  • Inbound sales management
  • Outbound sales management
  • Voice call recording
  • Customer support
  • Newsletter distribution
  • Quality management
  • Competitor analysis
  • Email marketing
  • Publishing of staff
  • photos and bios on the
  • public website
  • ERP (Enterprise Resource Planning)
  • Contact form available on public website
  • Online customer registration
  • Processing of customer or prospect data for marketing purposes
  • Cookie management
  • Tracking of online user behaviour

Please check all the processing activities that apply to your Human Resources Department (Records of Processing Activities)   

  • Managing personnel fileHealth & safety management
  • Time tracking of employees
  • Staff training
  • Employee on-boarding (hiring)
  • Employee off-boarding (firing)
  • Employee appraisal management
  • Employee anniversary / birthday
  • management
  • Payroll management and archiving
  • Employee benefits management
  • Internal phone book
  • Identity verification records (ID, right to
  • work, PEP & Sanction screening)
  • Holiday planning
  • First aid book (accidents & injuries)

Please check all the processing activities that apply to your IT Department (Records of Processing Activities)   

  • Internet access management and tracking
  • IT Support through desktop sharing software
  • Bring your own device
  • Working from home policy
  • User account and access management to used systems
  • Inventory management
  • Mobile device management and tracking
  • VPN (Virtual Private Network)
  • Use of USB stick and data transfer protocols
  • Phone system management
  • Software development
  • Fraud and insider threat management
  • Email management
  • Calendar management
  • Backups, data archiving and destruction

Please check all the processing activities that apply to Business Management (Records of Processing Activities)   

  • Business continuity planning
  • Board management
  • Investor relations

Please check all the processing activities that apply to your Facilities Department (Records of Processing Activities)   

  • Access control
  • Video surveillance
  • Visitor registration

Please check all the processing activities that apply to your Finance Department (Records of Processing Activities)   

  • Managing receivables and payables (who owes us, whom do we owe)
  • Cash management
  • Electronic payments
  • Payroll management
  • Expense management
  • Management reporting
  • Credit and solvency checks

Please check all the processing activities that apply to your Operations (Records of Processing Activities)   

  • Fleet management (dashcam, tracking, driver licence verification)
  • Logistics (trip recording, managing shippings)
  • Production

Other Processing Activities  

Is there a lawful ground for processing the personal data for each processing activity (Refer to the GDPR Data Mapping Template within the Documents section)?   

  • No
  • Yes
  • Not Applicable

Is there a lawful ground for processing any sensitive personal data for each processing operation?   

  • No
  • Yes
  • Not Applicable

Are the legal grounds for processing personal data recorded?   

  • No
  • Yes
  • Not Applicable

Recommended Actions

We have reviewed the purposes of our processing activities, and selected the most appropriate lawful basis (or bases) for each activity.

  • Completed
  • Not Applicable
  • In Progress

We have checked that the processing is necessary for the relevant purpose, and are satisfied that there is no other reasonable way to achieve that purpose.

  • Completed
  • Not Applicable
  • In Progress

We have documented our decision on which lawful basis applies to help us demonstrate compliance.

  • Completed
  • Not Applicable
  • In Progress

We have included information about both the purposes of the processing and the lawful basis for the processing in our privacy notice.

  • Completed
  • Not Applicable
  • In Progress

Where we process special category data, we have also identified a condition for processing special category data, and have documented this.

  • Completed
  • Not Applicable
  • In Progress

Where we process criminal offence data, we have also identified a condition for processing this data, and have documented this.

  • Completed
  • Not Applicable
  • In Progress