General Data Protection Regulation (GDPR)

  1. Principles of Data Processing
    1. Lawfulness, Fairness, and Transparency
      1. Meaning of Lawfulness
        1. Compliance with Other Laws
        2. Ensuring Fair Processing
          1. Reasonable Expectations
            1. Avoiding Deception
              1. Power Imbalances
              2. Transparency Requirements
                1. Clear and Plain Language
                  1. Accessible Information
                    1. Proactive Communication
                  2. Purpose Limitation
                    1. Specified, Explicit, and Legitimate Purposes
                      1. Clear Purpose Definition
                        1. Legitimate Purpose Assessment
                        2. Restrictions on Further Processing
                          1. Compatible Use Test
                            1. Exceptions for Further Processing
                          2. Data Minimisation
                            1. Adequacy Requirement
                              1. Relevance Requirement
                                1. Limitation to Necessary Data
                                  1. Regular Review of Data Holdings
                                  2. Accuracy
                                    1. Keeping Data Up to Date
                                      1. Verification Processes
                                        1. Rectification of Inaccurate Data
                                          1. Data Quality Management
                                          2. Storage Limitation
                                            1. Retention Periods
                                              1. Purpose-Based Retention
                                                1. Business Needs Assessment
                                                2. Criteria for Data Deletion
                                                  1. Automated Deletion Systems
                                                    1. Manual Review Processes
                                                  2. Integrity and Confidentiality
                                                    1. Protection Against Unauthorised Processing
                                                      1. Access Controls
                                                        1. Authentication Mechanisms
                                                        2. Safeguarding Against Accidental Loss or Damage
                                                          1. Backup Systems
                                                            1. Disaster Recovery
                                                              1. System Resilience
                                                            2. Accountability
                                                              1. Demonstrating Compliance
                                                                1. Evidence of Compliance
                                                                  1. Compliance Monitoring
                                                                  2. Documentation and Record-Keeping
                                                                    1. Processing Records
                                                                      1. Policy Documentation
                                                                        1. Training Records