• Does your company collect personal data about your customers and/or employees?

  • When collecting personal data, does your company clearly inform the individual the purpose(s) for which it will be collected, used or disclosed and obtain his or her consent?

  • Do you limit the use of personal data collected to only purposes that you have obtained consent for?

  • Do you make reasonable effort to verify that the personal data kept are accurate and complete (i) prior to any use to make a decision that affects the individual or (ii) prior to disclosure?

  • Have you assessed the personal data protection risks within your organisation and put in place personal data security policies?

  • Do you remove personal data no longer needed for business or legal purposes?

  • Do you transfer personal data overseas?

  • Have your company yet to appoint a Data Protection Officer (“DPO”)?

