The Audit Function.

Slides:



Advertisements
Similar presentations
Quality Management.
Advertisements

Every Solution Consultancy ISO 9001:2008 Certification IMPLEMENTATION Web:
Training on Data Protection Roles of the Data Protection Office.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Presenting The Broker-Dealer Certification Tool The Compliance Department Inc. Broker Dealer Compliance Consultants Compliance SCORE Powered by Keane BRMS.
1 Internal Controls. 2 Example Internal Control Manual  Focused Assessment Exhibit 4A  /trade/trade_programs/audits/focused.
Information Security IBK3IBV01 College 3 Paul J. Cornelisse.
Can you conduct DSE risk assessments for under £10 each? ADVISA can! ADVISA makes DSE risk assessments quick & affordable, at a fraction of the cost of.
Organizing a Privacy Program: Administrative Infrastructure and Reporting Relationships Presented by: Samuel P. Jenkins, Director Defense Privacy Office.
Information Sharing & Corporate Governance Dave Parsons, Information Governance Manager, City of Cardiff Council.
The EU General Data Protection Regulation Frank Rankin.
Eyes Wide Open A little about us…..
Data Protection Officer’s Overview of the GDPR
Accountability & Structured Privacy Management
By: Ms Peterlia Ramutsheli
GS-R-3 vs. ISO 9001:2008 Requirements - 4
ISO 14001: 2004 Environmental Management Review Presentation
BSBWOR301 Organise personal work priorities and development
Data protection headaches: GDPR, brexit AND perimeter risk
Deployment of a DPO Niamh Gavin AIB Data Protection Legal
Presentation to GTMC on GDPR
Auditing Cloud Services
GDPR Awareness and Training Workshop
TOPS TSA MD
the heart of health and safety
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
The EU General Data Protection Regulation (GDPR)
GDPR Overview Gydeline – October 2017
GDPR IS A DATA PROTECTION GAME CHANGER
GDPR support January GDPR support January 2018.
GDPR Overview Gydeline – October 2017
Managing performance What is it? Why? How?.
Bob Siegel President Privacy Ref, Inc.
GDPR - Individual’s Rights
GENERAL DATA PROTECTION REGULATION (GDPR)
Cyberforum 2018 March 8, 2018 Los Angeles GDPR & SECURITY
GDPR - New Data Protection Regulation
GDPR – The Role of the Data Protection Officer (DPO)
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
Software for ambitious enterprises
Data protection reform – update from the ICO
Information Governance
The Public Sector Equality Duty
The GDPR & Schools - An Introduction -
SELECT COMMITTEE ON TRADE & INTERNATIONAL RELATIONS
GDPR – Practical Implementation Managing contracts, procurement and relationships with suppliers Terry Brewer Chief Executive.

Quality Department
General Data Protection Regulation
Dealing with your GDPR Challenges
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
GDPR - New Data Protection Regulation
Data Mapping On the Journey to Accountability
GDPR enforcement begins
Our New Integrated Business Management System [“IMS”]
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
How to conduct Effective Stage-1 Audit
The Public Sector Equality Duty
General Data Protection regulation (GDPR)
GDPR PERSONDATAFORORDNINGEN I PRAKSIS
What Governors need to know about GDPR
What is an Internal Audit
Data Mapping & Data Subject Rights
Data Protection What can I do? GDPR Principles General Data Protection
General Data Protection Regulation “11 months in”
THE IMPACT OF DATA PROTECTION RULES ON CORPORATE INFO SECURITY AND INCIDENT RESPONSE MANAGEMENT – The Energy sector CEER Cybersecurity Workshop Massimo.
GDPR Workshop – Partnerships for Jewish Schools
A. Šidlauskas Mykolas Romeris University (LITHUANIA)
Presentation transcript:

The Audit Function

Why Do We Need To Audit GDPRiS? What are the tasks of the DPO? To inform and advise the organisation and its employees about their obligations to comply with the GDPR and other data protection laws. To monitor compliance with the GDPR and other data protection laws, including managing internal data protection activities, advise on data protection impact assessments; train staff and conduct internal audits. To be the first point of contact for supervisory authorities and for individuals whose data is processed (employees, customers etc).

What Does An Audit Involve? This is an opportunity to “stop the clock” For the school manager to periodically check data protection activities and to facilitate understanding For the DPO to check that all aspects of compliance requirements have been met To identify any gaps and enable schools to address those needs

SCHEDULE AUDIT REQUIREMENTS- The school manager and DPO can set audit reminder dates

SEE PROGRESS- The school manager and DPO can see the progress of audits

WHAT CAN BE AUDITED? The supplier (Data processor) mapping

WHAT CAN BE AUDITED? The supplier (Data processor) data sharing agreements and security questions

WHAT CAN BE AUDITED? Departmental Questionnaires Including: Leadership School-Wide Support Reviews and Improvements

WHAT CAN BE AUDITED? Privacy Impact Assessment Questionnaires

WHAT CAN BE AUDITED? Staff Self Assessment Questionnaires (SAQ’S)

Identify Any System Gaps- The School Manager and DPO will ensure that all responses reflect GDPR compliance. The reports will also help school managers and DPOs identify any gaps in their compliance journey (if non compliant responses are made). Highlighting the gaps that exist and needs to be filled- enables the school to focus on work and resources required to achieve and maintain compliance.

REPORTS – will be available List of staff SAQ replies Suppliers/Services Data mapping query Internal Review Suppliers documentation/ uploads Breaches List of training documents