Entity ensures regulatory requirements regarding user consent are met prior to processing personal data
Entity maintains an inventory of categories of personal information collected along with its usage, sources and specific purposes for collection as per regulatory requirements (“Record of Processing Activities”) and reviews it on an annual basis
Entity has a documented Data Protection policy which includes staff members’ responsibilities with handling personal data as per the company’s regulatory requirements
Entity has a documented Data Retention Policy, and makes it available for all staff on the company employee portal.
The Entity has implemented physical and/or logical labelling of information according to the documented Data Classification Policy
Entity has established an Information Security Awareness training, and its contents are available for all staff on the company employee portal.