The GDPR was enforced across all EU Member States on 25 May 2018. But, it didn’t all end in May 2018.
It’s clear that a continued commitment is needed to ensure policies, processes and procedures are regularly reviewed and actually work in practice.
A continual effort is needed to keep records up to date and to try and ensure the overarching themes of transparency and accountability are met.
A key area is ensuring you have identified a lawful basis for different processing activities, and meeting the requirements of that basis.
In July 2017 the DPN published industry-led Legitimate Interests Guidance, which was updated in April 2018 with cases studies and more examples of where Legitimate Interests may be appropriate.
The DPN’s range of resources provide expert GDPR advice, including: