Appendix C
GDPR Checklist
The chapters in this book break down the data principles, documentation, and obligations you need to be aware of (and carry out) to be compliant with the GDPR. This appendix provides a handy list that shows altogether the activities you must complete to maintain that compliance.
To purchase the GDPR Compliance Pack, which provides all the legal document templates you need to become GDPR compliant, go to www.suzannedibble.com/gdprpack.
Does GDPR apply to me territorially?
If you’re established in the EU — whether you’re a data controller or a data processor— GDPR applies to all your processing of personal data. If you’re established outside of the EU and your processing activities are related to either of the following, GDPR applies to that processing:
- Offering of goods or services (whether or not a payment is made) to data subjects within the EU
- Monitoring behavior of data subjects within the EU
See Chapter 2 for more on the topic of the territorial scope of the GDPR.
Does GDPR actually apply to the data I process?
If you process data that identifies, or is capable of identifying, an individual (including cookies and IP addresses) wholly or partly through automated means or manually as part of a filing system, then GDPR applies except where you are an individual processing the data in the course of a purely personal or household activity.
See Chapter 3 for more on what constitutes personal data.
What data do I process and for what purpose? ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access