1. Understanding obligations
It may not be expected, nor desirable, that everyone in the firm would take responsibility for responding to a data subject rights request or data breach, but it is important that every staff member knows what these events look like so that the matter can be promptly referred internally to the appropriate person.
Awareness is an ongoing obligation and refresher training required to keep staff up to date with, and conscious of, requirements.
Checklist
- Has a person with appropriate seniority been appointed to drive GDPR compliance in the firm?
- Are staff aware of data protection requirements?
- Are staff aware of the consequences of failure to comply with data protection requirements?
- Have staff completed appropriate data protection and information security training?
- Are your staff able to recognise and appropriate handle to a data subject access request?
- Are your staff able to recognise and appropriate handle a data security breach?
- Are staff trained in data protection matters?
Right column
GDPR Guidance
Browse other Law Society guidance on the General Data Protection Regulation (GDPR) through the links below.
- 1. Understanding obligations
- 2. Being accountable
- 3. Communicating with staff and service users
- 4. Data subject rights
- 5. Data Subject Access Requests (DSARs)
- 6. Lawful basis for processing personal data
- 7. Consent
- 8. Processing Children's Data
- 9. Data Breach Protocol
- 10. Data Protection Impact Assessment
- 11. Data Protection Officer
- Considering appointing a DPO - issues to consider