The Office of the Data Protection Commissioner has moved from awareness to enforcement. Registration alone no longer signals compliance.
Organisations should maintain a record of processing activities, a defensible lawful basis for each activity, and retention schedules that are actually observed.
Data protection impact assessments are mandatory for high-risk processing, including large-scale profiling and processing of sensitive categories.
Vendor contracts require processor clauses. In practice, this is where most gaps appear during audits.
This article is general commentary and does not constitute legal advice. For advice on your specific circumstances, please contact the firm.
Book a Consultation