Data Mapping On the Journey to Accountability
87 24 35k Trainline today Train companies Countries Stations Trainline || Private & Confidential
What does the GDPR say? Recital 82 In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility. Each controller and processor should be obliged to cooperate with the supervisory authority and make those records, on request, available to it, so that it might serve for monitoring those processing operations Categories of data Name and contact details Categories of recipient Security measures Purposes of processing Transfers & safeguards Retention Trainline || Private & Confidential
Data Mapping - a foundational activity Privacy notices Individual rights Data breach DPIAs Privacy by design Minimisation Trainline || Private & Confidential
Practical considerations When to start? When are we finished? Who is involved? How to maintain records? Manual vs automation? Trainline || Private & Confidential
Insights on approach Trainline || Private & Confidential
Benefits Better data Privacy maturity Accountability Quicker response GDPR enablement Trainline || Private & Confidential
Accountability Accountability Appropriate measures Data mapping DPO Privacy by design DPIA Codes of conduct The new accountability principle in Article 5(2) requires you to demonstrate that you comply with the principles and states explicitly that this is your responsibility. Trainline || Private & Confidential
QUESTIONS? Trainline || Private & Confidential