- How would you describe your GDPR preparedness?
- Already compliant
- On target to be compliant by May 25th 2018
- Project underway but suffering difficulties
- Barely started
- Haven’t started
The Trust does not meet any of these descriptions in relation to GDPR preparedness. I can confirm that work to prepare us is on-going and will continue.
- Have you identified all your data processing partners?
- Yes
- No
- Unsure
c) Unsure- It is not possible for us to confirm or deny whether all processing partners have been identified as if there are ones we are unaware of we wouldn’t know.
- Do you have contracts in place with all your data processing partners?
- Yes
- No
- Unsure c) Unsure- As above it is not possible for us to confirm or deny this. Part of the work the Trust is undertaking for GDPR is looking to update agreements where needed, but this is on-going.
- Do you use a third party to provide data erasure or destruction services on your end of life IT infrastructure?
- Yes
- No (ICT have advised that they do not use any such third parties)
- Unsure
- If you use a third party, do you have a contract in place with them?
- Yes
- No
- Unsure
- Not Applicable
- How have you assessed ‘sufficient guarantees’ from this company? (Please tick all that apply)
- In writing from them
- Via Contract Terms
- Relevant accreditation
- Independent Assessment/Audit
- Not Applicable
- Does this contract include clarification on process for dealing with: (Please tick all that apply)
- Breach Notification?
- Subject Access Requests
- Changes in processing activities which require a DPIA
- Not Applicable
- If you use a third party what is their name?
Not Applicable
- How regularly do you or an independent third party, audit this company?
- Never
- Every 6 months
- Every 12 months
- Irregularly but over 12 months
- Unsure
- Not Applicable