Annual GDPR Compliance Assessment
in progressProgress
Questions (5)
Do you have a designated Data Protection Officer (DPO)?
Describe your data processing activities and legal basis for each.
Our main data processing activities include: 1) Customer account management (contractual necessity), 2) Analytics for product improvement (legitimate interest with opt-out), 3) Marketing communications (explicit consent)...
What technical and organizational measures (TOMs) do you implement for data security?
We implement industry-standard TOMs including: encryption at rest (AES-256) and in transit (TLS 1.3), role-based access control, regular security audits, employee training programs, incident response procedures...
How do you handle data subject access requests (DSARs)?
Do you transfer personal data outside the EU/EEA? If so, what safeguards apply?
Consider adding: Transfer Impact Assessments (TIAs) are conducted for each third-country transfer...