-
Privacy notice
Hello
Gdpr question,
I made a data audit and a retention policy (which include confidentiality and privacy )
Do I also need a privacy audit ? It seems to repeat the same thing as retention policy. Can I just ask parents to sign that they read and agree my retention policy?
Just can't see the difference!
Thanks
-
The audit is what you do for your own purposes (although it can be requested to be seen) so you can get an overview of all the data you collect, why, who you share it with, where it is stored, for how long and how you dispose of it. It is not for parents to see (unless they request it) but ICO would refer to it if you ever had a data breech or complaint. It is suggested that it is the very first thing you do in the process. You write the other documents based on what you find out when you audit your own business.
-
-