GDPR IRL - Policy Mapping
GDPR IRL - Policy Mapping
GDPR IRL - Policy Mapping
5(1)
GDPR - 1 24(2) G
91(1)
GDPR - 2 5(1) G
GDPR - 3 5(1) G
GDPR - 4 5(1) G
5(1)
GDPR - 5 G
30(1)(2)(3)
6 (4)
GDPR - 6 13(3) G
14(4)
GDPR - 7 5(1) G
8(2)
GDPR - 8 G
12(1)
9(2)
GDPR - 9 G
10 (1)
GDPR - 10 6(1) G
5(1)
GDPR - 11 6(4) G
25(2)
35(1)(7)(9)
6 (4)
GDPR - 12 7 (1)(2) G
8 (1)
7 (3)
GDPR - 13 18 (1)(3) G
19
21(1)(3)(4)
GDPR - 14 9 G
12(1)(2)(3)(4)(5)(6)
GDPR - 15 13(1)(2) G
14 (1)(2)
12(1)(2)(3)(4)(5)(6)
GDPR - 16 22(1)(2)(3)(4) G
GDPR - 17 12(1)(2)(3)(4)(5)(6) G
13 (1)(2)
GDPR - 18 14(3) G
21(4)
GDPR - 19 15 (1)(2)(3)(4) G
16
GDPR - 20 G
19
16
GDPR - 21 G
19
17(1)(2)
GDPR - 22 19 G
GDPR - 23 20(1) G
GDPR - 24 21(2) G
21(6)
GDPR - 25 89(2) G
GDPR - 26 24(3) G
GDPR - 27 25(1) G
GDPR - 28 27(1) G
28(1)(2)(3)(4)(5)(9)
GDPR - 29 29 G
32(4)
GDPR - 30 31(1) G
GDPR - 31 32(1) G
33(1)
GDPR - 32 G
34(3)
GDPR - 33 33(5) G
GDPR - 34 36(1) G
33(1)(2)(3)
GDPR - 35 G
34(1)(2)
37(1)(5)(7)
GDPR - 36 G
38(2)(4)(5)
GDPR - 37 39(1)(2) G
GDPR - 38 44-49 G
GDPR - 39 89(1) G
Request
Data Privacy Policies and procedures
Policies and procedures for collection and use of sensitive personal data (including
biometric and genetic data)
Documented legal basis for processing personal data (MSA with Data Controller,
etc.)
Please provide the most recent Data Protection Impact Assessment
Please provide evidence to support how valid consent is obtained. (How is consent
obtained from data subjects prior to processing their data?)
Please provide policies records of the transfer mechanism used for cross-border
data flows (e.g., standard contractual clauses, binding corporate rules, approvals
from regulators)
This should be defined within the "GDPR Compliane Policy", however more than likely is
going to be Not Applicable, but this should still be defined.
Not Applicable
See 4.1.3 Data Protection by Design
See Section 4.12 within the sample GDPR Policy and the incident response policy within
the Information Security Templates.
Not Applicable
See Section 4.12 within the sample GDPR Policy and the incident response policy within
the Information Security Templates.
See Governance within the sample GDPR Policy.
Not Applicable