The checklist will give you an insight about where your organisation is with data protection from a data privacy and technical security perspective. The checklists form part of the Best Practice library which includes contextualised guidance, documents and resources on specific areas of data processing. The checklists form part of the ICO Accountability Framework which helps organisations with their governance and corporate risk management where it relates to data protection. The checklists cover all aspects of the framework, enabling you to assess against organisation baselines:
- Leadership & Oversight
- Risk Management (DPIA's)
- Policies & Procedures
- Individual Rights
- Contracts & Data Sharing
- Transparency
- Training & Awareness
- Records Management
- Monitoring Verification & Reporting (Data Breaches, SARs and FOI's)
- Response & Enforcement (SARs and FOI's)
Supplier Due Diligence
The Supplier Due Diligence checklist covers basic questions when starting on third party supplier due diligence. It links to the Supplier Due Diligence Best Practice Area which discusses the responsibilities of the controllerwhen using a processor. There is help and advice about how to go about asssessing the risk when sending data to a third party processor, and our supplier due diligence form which can be sent to new suppliers for assessment - we can help you assess the risk. If you receive a completed form, then emailAnswer a sample Supplier Due Diligence checklist question:
DPE customers can get started on completing the Supplier Due Diligence checklist here: