GDPR Implementation Guide
Overview
Accountable doesn't cover full GDPR Compliance, however it does help with a lot of the administrative elements, as there is a lot of overlap with what is administratively required under HIPAA Compliance.
Once Accountable is implemented for GDPR, annual maintenance is needed, as GDPR compliance has multiple annual requirements.
Accountable does not cover all requirements under GDPR. Below we list all requirements. Those that we cannot cover under Accountable, will be marked with a (Not Covered) or (Partially Covered) tag.
Onboarding
Below is our suggested process for onboarding Accountable. It is a 6-step process:
- (Not Covered) Assign a Data Protection Officer (DPO)
- (Partially Covered) Setup Data Inventory & Mapping
- (Not Covered) Record of Processing Activities (ROPA)
- (Not Covered) Consent & Cookie Management
- Vendor Management
- Send Data Processing Agreements (DPAs)
- Send Vendor Risk Questionnaires
- Create Policies & Procedures
- Privacy Center Implementation
- Invite your Team and Assign Training, Policy & Procedure Attestation, and Incident Reporting Acknowledgement
- Complete a Data Protection Impact Assessment (DPIA)
Additional Implementation
Key Resources
- Best Practices for Maintaining Compliance
- Team Member Training
- Incident Response
- Getting Support
- Sharing your Feedback/Ideas
Additional Resources
Updated 3 days ago
