0% found this document useful (0 votes)
15 views4 pages

PIMS and GDPR Implementation Guide

The document outlines a comprehensive roadmap for implementing a Privacy Information Management System (PIMS) and GDPR compliance, detailing stages, activities, deliverables, and timelines. Key stages include gap analysis, documentation, internal audits, certification, and GDPR-specific tasks such as creating data protection policies and handling data breaches. Each stage is associated with specific deliverables and timeframes, ensuring a structured approach to achieving compliance.

Uploaded by

sayedjubed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views4 pages

PIMS and GDPR Implementation Guide

The document outlines a comprehensive roadmap for implementing a Privacy Information Management System (PIMS) and GDPR compliance, detailing stages, activities, deliverables, and timelines. Key stages include gap analysis, documentation, internal audits, certification, and GDPR-specific tasks such as creating data protection policies and handling data breaches. Each stage is associated with specific deliverables and timeframes, ensuring a structured approach to achieving compliance.

Uploaded by

sayedjubed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOC, PDF, TXT or read online on Scribd

PIMS Implementation Roadmap

Stage Primary Deliverable Time Line


Activity
Stage Gap Analysis  ISO 27701 GAP Analysis 3-4 Days
1 and Awareness  ISO 27701 End user awareness
training
Stage PIMS  PIMS Manual 50 Days
2 Documentation  PIMS Scope Definition
 Procedure for Control of
Documents
 Process for Risk Management
 Information Security Policies
 Privacy by Design and by Default
Policy
 Privacy Objectives and Planning
 Process for Internal Audit and
Management Review
 Process for Access Control
Management
 Process for Organization of
Information Security
 Policy for Teleworking and Mobile
Device Policy
 Policy for Human Resource
Security
 Policy for Asset Management
 Policy for Information Classification
 Policy for Information Governance
 Firewall Policy
 Password Policy
 Physical and Environment Security
Policy
 Operation Security Policy
 Communication Security Policy
 Internet & Email Use Policy
 Policy for System Acquisition
Development & Maintenance
 Policy for information Security in
Project Management Policy
 Supplier Relationship Policy
 Incident Response Policy
 Business Continuity Policy
 Compliance Policy
 Procedure for Collecting and
Processing Personal Data
 Procedure for Contracted PII
Processing
 Data Protection and Privacy Policy
 Procedure for PII Disclosure
 Procedure for Privacy Impact
Assessment
 Procedure for Processing Contracts
 Procedure for Records of
Processing
 Procedure for Subcontracted
Processing
 Procedure for Subject Access
Request
 Procedure for Transmission of PII
 Policy for Data Retention
 Procedure for Cross-border
processing or transfers of personal
data
 Cookies Policy
 Procedure for Obligations to PII
Principals
 Data Protection Officer Job
Description
 PII Disclosure Record
 PII Processing Activity Record
 Privacy by Design Principles
 Privacy Impact Assessment Tool
 Procedure for Privacy Notice
 Procedure for Obtaining Valid
Consent
 Procedure for Subject Access
Request
 Procedure for Data Breach
notification & handling
 Procedure for handling Data
Subject Rights
 Inter Company Agreement
Stage Internal Audit &  Conducting PIMS internal audit 10-15 Days
3 MRM  Conducting PIMS management
review meeting
 Assistance during certification
body audit
 Closure of reported findings
Stage ISO 27701  Stage 1 Audit 10-15 Days
4 Certification  Closure of Observation of Stage 1
Audit  Stage 2 Audit
 Closure of Observation of Stage 2
Audit
GDPR Implementation Roadmap
Phases Purpose Timeline
 To create a project plan to implement GDP
Preparing GDPR  To conduct a readiness assessment to find
project. out what tasks you need to perform.
2 Days

 To create an internal Data Protection Policy


Defining for personal data.
Personal Data  To create other top-level policies as
Policy and other needed – e.g., the Data Retention Policy.
top-level  To create awareness among employees
documents. about key GDPR requirements.
 To make a decision with regard to the 10 Days
assignment of a Data Protection Officer,
and make sure the decision is
documented.
 To appoint a Data Protection Officer and
communicate their name to the
Supervisory Authority.
 To implement data subject rights through
Creating an establishing a legal basis for processing.
inventory of  Getting data subjects consent and request 10 Days
processing access.
activities.  Generating and Keeping records of data
subject rights requests.

 Conducting a DPIA on organizations


Data Protection information systems or a product. 2 Days
Impact
Assessment
(DPIA).

 Analyse what personal data is being


Secure personal transferred outside of your company, and
data transfers. when.
 Taking necessary legal and security 8 Days
measures to adequately protect personal
data when personal data is transferred
outside of the company.
 Amending third-party contracts that
Amending third- include processing of personal data to 5 Days
party contracts. become compliant with the GDPR.

 Implement the necessary organisational


Implementing and technical measures to protect the 15-20
security personal data of data subjects. Days
provisions of
personal and
sensitive data.

 Setting up the processes to identify and


Implementation handle personal data breaches.
of controls to  Preparing process of notifications to the 10 Days
handle data Supervisory Authority and data subjects, if
breaches. required, in the case of a personal data
breach.

You might also like