You are on page 1of 12

Page |1

LOGO OF CLIENT

Please print this page and store no digital copies while doing audits, team will share the outputs based on
this extensive audit in a PDF non-editable format at the end of engagement. The sections reserved for
notes shall capture remarks/notes and eliminate any PI/PD in them. This document once printed will be
recalled using a CODE (DAY-MONTH-FRUIT) such as SUNSEPMANGO. Once the objective met this will
be destroyed on the day of final handover and no copy will be retained by either parties.

RAKESH JHA FIP CIPPE CIPM


PRIVACY CONSULTANT
RAKESH.JHA@AAROH.COM.QA
www.aaroh.com.qa

Guidelines
We will help you to establish GDPR (EU General Data Protection Regulations) compliance via understanding
your obligations, what your current processes are and identifying any gaps. Undertaking a data protection audit is
essential to achieving compliance. This checklist is intended to provide a starting point, rather than providing an
exhaustive audit.

COPYRIGHT © 2018 PV GLOBAL


Page |2

Note that the ticks in the processor column relate to direct obligations on data processors. However, while not all
obligations apply to data processors, they should understand the requirements on controllers as they will be
responsible for helping their controllers to deliver on many of them. Some obligations may be triggered by the size
of the organisation.

1. Personal data

2. Scope of application

3. Lawful grounds for processing

COPYRIGHT © 2018 PV GLOBAL


Page |3

4. Transparency requirements

Note : PV01

5. Other data protection principles and accountability

COPYRIGHT © 2018 PV GLOBAL


Page |4

Note : PV02

6. Data subject rights

COPYRIGHT © 2018 PV GLOBAL


Page |5

Note : PV03

7. Data security

COPYRIGHT © 2018 PV GLOBAL


Page |6

Note : PV04

8. Data breaches

COPYRIGHT © 2018 PV GLOBAL


Page |7

Note : PV05

9. International data transfers (outside EEA)

COPYRIGHT © 2018 PV GLOBAL


Page |8

Note : PV06

10. Other controller obligations

COPYRIGHT © 2018 PV GLOBAL


Page |9

11. Other processor obligations

COPYRIGHT © 2018 PV GLOBAL


P a g e | 10

Risk and Pending Observations : PV07

COPYRIGHT © 2018 PV GLOBAL


P a g e | 11

Audited by :
Start Date :
End Date :

COPYRIGHT © 2018 PV GLOBAL


P a g e | 12

Page left blank purposefully, use for any rough schema or drawings.
END OF DOCUMENT 12/12

COPYRIGHT © 2018 PV GLOBAL

You might also like