Skip to main content

On-demand webinar coming soon...

Press Release

OneTrust Announces EU Regulator Guidance-Based Privacy Templates for GDPR Compliance

May 07, 2018

OneTrust, a global leader in enterprise privacy management software that supports compliance with data privacy regulations – including the EU General Data Protection Regulation (GDPR) – today announces the availability of a new suite of privacy management questionnaire templates.

The templates include a Privacy Impact Assessment Pre-Screen (PIA), a Data Protection Impact Assessment (DPIA), and a Records of Processing (Data Mapping) template based on deep research and regulatory guidance issued by EU Data Protection Authorities (DPA) and the Article 29 Working Party (WP29).

The templates are available as part of the library of more than 30 privacy assessment templates included in OneTrust’s comprehensive privacy management software platform.

With the EU GDPR coming into effect on 25 May 2018, organisations must undergo significant operational reform with how they handle personal data of customers, employees, and vendors and with how they implement thorough record-keeping to demonstrate compliance.

 

Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) Requirements in Article 35 of GDPR

One of these operational requirements is the DPIA addressed in GDPR Article 35, which states:

“Where a type of processing in particular using new technologies … is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.”

OneTrust’s in-house privacy research team analysed and incorporated guidance from well-respected EU regulator-based sources and industry standards to create PIA and DPIA templates. Instrumental sources include: Article 29 Working Party’s group of EU regulators, the German Standard Data Protection Model, the CNIL PIA Manual & GDPR Toolkit, the UK ICO PIA Code of Practice, and ISO/IEC 29134:2017 Guidelines for PIA.

 

Records of Processing (Data Mapping) Requirements in Article 30 of GDPR

A second significant operational and record keeping requirement appears in GDPR Article 30:

“Each controller and, where applicable, the controller’s representative, shall maintain a record of processing activities under its responsibility.”

Although data inventory and mapping is not explicitly mentioned in the GDPR, it is widely recognised that Article 30 requires an organisation to conduct a data inventory and mapping exercise, and most importantly, keep it up-to-date. In creating the Records of Processing (Data Mapping) template to support this requirement, OneTrust’s research team incorporated available guidance including the CNIL’s GDPR Toolkit, the Belgian Privacy Commission’s Recommendation Concerning the Register of Processing Activities, and many additional sources.

“The combination of deep privacy research paired with the enterprise-grade configurability of the OneTrust solution continues to make the OneTrust Privacy Management platform stand out in the market for GDPR and privacy management software,” said OneTrust CEO Kabir Barday, CIPP/US, CIPP/E, CIPM, CIPT. “Our global privacy team continues to conduct daily research into the ever-changing regulatory environment and are committed to offering the industry’s leading, most comprehensive, and easiest-to-use privacy management offering.”

Click here to watch a video overview of the regulatory guidance incorporated in OneTrust’s privacy assessment templates.

More than 100 regulators are expected to attend the Hong Kong International Conference of Data Protection and Privacy Comissioners from 25-29 September. OneTrust is a platinum sponsor of this conference, and is hosting a workshop and social event in tandem with ICDPPC. Registration is available online for both events.

For more information, visit OneTrust or email Info@OneTrust.com.

 

About OneTrust

OneTrust is a global leader in enterprise privacy management software used by more than 1,500 organisations to comply with data privacy regulations across sectors and jurisdictions, including the renowned EU General Data Protection Regulation (GDPR).

OneTrust is among the most widely used global technology solutions to implement a GDPR-based privacy compliance programme. The comprehensive OneTrust platform helps organisations track the full lifecycle of their personal data flows, analyse these data flows against global regulations to understand risks, communicate directly with customers, employees, and vendors to capture consent, handle privacy-related requests, and respond appropriately in the event of an incident.

The multi-lingual software is deployed in an EU cloud or on-premise, and is based on a combination of intelligent scanning, regulator guidance-based questionnaires, and automated workflows used together to automatically generate the record keeping required for an organisation to demonstrate compliance to regulators and auditors.

OneTrust helps organisations implement the requirements of GDPR including Data Protection by Design, Data Protection Impact Assessments (PIA / DPIA), Vendor Management, Incident and Breach Management, Records of Processing (Data Mapping), Consent Management, ePrivacy Cookie Compliance, Data Subject Access, Portability, and Right to Be Forgotten.

Backed by the founders of Manhattan Associates (NASDAQ: MANH) and AirWatch ($1.54B acq. by VMware), OneTrust is co-headquartered in London, UK and Atlanta, GA with a fast-growing global team of privacy and technology experts surpassing 200 employees.


You may also like

eBook

Privacy Management

Understanding data transfers under the GDPR ebook

In the ebook, we delve into the fallout from Schrems II and explore how organizations based in Europe can best navigate international data transfers under the GDPR.

June 05, 2024

Learn more

Webinar

Privacy Management

Navigating data privacy in 2024: Global regulatory updates & compliance strategies

Join our webinar for a comprehensive overview of the latest global data privacy regulations and updates impacting businesses in 2024 and how to prepare.

March 20, 2024

Learn more

Infographic

Privacy Management

OneTrust announces partnership with Europrivacy

Learn how OneTrust and Europrivacy's partnership can help your organization achieve GDPR compliance and build trust with your customers.

December 06, 2023

Learn more

Webinar

Technology Risk & Compliance

Demonstrating GDPR compliance with Europrivacy criteria: The European Data Protection Seal

Join our webinar to learn more about the European Data Protection Seal and to find out what the key advantages of getting certified.

November 30, 2023

Learn more

Webinar

Privacy Management

Revisiting the ICO Data Protection Practitioner's Conference: Addressing your top challenges

Join OneTrust and KPMG UK to discuss the challenges of employee SARs, managing your breach response with third parties, and incident management.

October 25, 2023

Learn more

Infographic

Privacy & Data Governance

Understanding the EU Data Boundary

Download our free infographic and get the information you need to understand the EU Data Boundary and how to properly handle data in the European Union.

September 22, 2023

Learn more

Webinar

Privacy Management

Privacy in practice: PIA & DPIA with PA Consulting

Join OneTrust and PA Consulting as we discuss what makes an effective PIA, best practices, and the benefits of automation.

September 21, 2023

Learn more

Webinar

Privacy & Data Governance

Privacy in practice for data mapping: With PA Consulting and Syngenta

Join OneTrust and panelists from PA Consulting and Syngenta as we explore practical ways to build an effective data mapping program, best practices, and the need for automation.

September 14, 2023

Learn more

Webinar

Governance & Policy Management

EU-US DPF: What next for UK businesses?

Join our expert webinar as we discuss the upcoming UK-US DPF Extension and what UK businesses need to prepare to become DPF-certified.

September 06, 2023

Learn more

Webinar

Privacy Management

Unpacking the EU-US DPF

In this webinar, we cover the new EU-US Data Privacy Framework (EU-US DPF) and what privacy program managers need to know for post-Schrems II data transfers.

June 28, 2023

Learn more

Infographic

Privacy & Data Governance

The 3 priorities of the French DPO: Gain visibility, take action, automate

Download our infographic and learn about the 3 priorities of the French DPO.

May 30, 2023

Learn more

Webinar

Privacy Management

GDPR turns 5: Celebrating data protection

Northern Europe panel - Join our panel of experts as they recap the GDPR, its key concepts, and what it means for organizations and compliance. 

May 25, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Tech: Key considerations of Privacy by Design and AI in tech

Join our panel of experts as we discuss the impact GDPR had on the tech industry during the past five years, the importance of privacy by design, and what to expect with AI and regulation.

May 25, 2023

Learn more

Webinar

Privacy Management

5 years of GDPR: Milestones, challenges, and opportunities

Eastern European panel - Watch our webinar as we look back on 5 years of the GDPR, AI, and their impact on Europe, the world, and your organization.

May 24, 2023

Learn more

Webinar

Privacy & Data Governance

Global Panel — GDPR & Healthcare: current regulatory guidance and enforcement

In this live webinar, our expert panel examines the first five years of the GDPR, how it changed the healthcare industry, and the changing global regulatory landscape.

May 24, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Retail: building customer loyalty and trust with consent and privacy

Join us for a live panel as we discuss GDPR's impact on the retail and eCommerce industry and how companies evolved to meet the global regulatory landscape.

May 23, 2023

Learn more

eBook

Privacy Management

Getting started with GDPR compliance

This eBook covers the fundamental information you need to know in order to get your GDPR compliance program started and how OneTrust helps. 

May 23, 2023

Learn more

Infographic

Privacy Management

Comparing the FADP, Revised FADP, and the GDPR

Download our infographic to see how the Revised FADP compares with its original version and the GDPR.

May 23, 2023

Learn more

Webinar

Privacy Management

Global Panel — GDPR & Finance: Staying ahead of the regulatory and cyber landscape

How has the GDPR affected the financial industry? Join our live panel as we examine how it companies evolved to meet the regulatory challenges and what can be done to stay ahead of the curve.

May 22, 2023

Learn more

Webinar

Privacy Automation

OneTrust and Deloitte UK - Data transfers: Assessments & safeguards

OneTrust's Center of Excellence and Deloitte UK will discuss data transfers and GDPR compliance, covering the UK stance, ICO/EDBP guidance, and more.

April 04, 2023 1 min read

Learn more

eBook

Privacy Management

The 3 Priorities for DPOs in France: Gain Visibility, Take Action, Automate eBook | Resources | OneTrust

French DPOs should take three priorities into account when building their data protection and compliance programs and processes in 2023.

February 21, 2023

Learn more

Webinar

Privacy & Data Governance

Data Protection in Financial Services Week: Government keynote and international transfers

This session will examine some key issues and recent developments on international data transfers with contributions from key EU, UK, and US regulators.

February 07, 2023

Learn more

Webinar

Consent & Preferences

Belgian DPA approves TCF action plan: Where we go from here

Belgian DPA approves IAB Europe’s action plan to correct its Transparency & Consent Framework (TCF) violations of the GDPR.

January 12, 2023

Learn more

Webinar

Privacy & Data Governance

Keeping pace with the changing regulatory landscape: UK And EU updates webinar

Learn more about the privacy updates for the UK and the EU, what to expect in the coming year, and how to manage regulatory change.

August 15, 2022

Learn more

Webinar

Ethics & Compliance

GDPR and the EU Whistleblower Protection Directive webinar

Join this webinar to learn how to review your whistleblowing processes to comply with the EU Whistleblower Protection Directive, the GDPR and others.

July 06, 2022

Learn more

Webinar

Privacy & Data Governance

4 years of GDPR

Watch our webinar on the last 4 years of GDPR compliance and trends for the future.

May 05, 2022

Learn more

Webinar

Privacy Management

Privacy rights poland: Enhance Your DSAR process with automation, discovery & redaction

As part of our Privacy Automation webinar series, we discuss why it's important to automate DSAR fulfillment and the latest regulatory trends. 

April 03, 2022

Learn more

Webinar

Privacy & Data Governance

Know your laws: Comparing CCPA & CPRA vs. GDPR

Watch this free webinar and see how the CCPA and CPRA compare with the GDPR.

January 04, 2022

Learn more

Checklist

Privacy & Data Governance

Transfer Impact Assessment (TIA) checklist

This Transfer Impact Assessment checklist provides an overview of the key steps you can take as you perform a TIA.

December 01, 2021

Learn more

Infographic

GDPR's 8 fundamental data subject rights

Download our GDPR's 8 Fundamental Data Subject Rights infographic and learn more about the individual rights guaranteed under the EU's major privacy law. 

August 27, 2021

Learn more

eBook

Privacy & Data Governance

The ultimate guide to GDPR compliance

Download this eBook to get an ultimate guide to understanding the GDPR and implementing steps towards compliance.

August 26, 2021

Learn more

eBook

Privacy & Data Governance

The Ultimate PIA and DPIA eBook

Download The Ultimate PIA and DPIA eBook to understand, develop, and implement an efficient PIA and DPIA process for your privacy program.

July 22, 2021

Learn more

eBook

Privacy & Data Governance

10 steps to meeting the GDPR Article 30 requirement

Download this eBook and learn how to leverage data mapping for your GDPR Article 30 compliance program. 

July 22, 2021

Learn more

Checklist

Privacy & Data Governance

GDPR compliance checklist

Download our GDPR compliance checklist for recommendations on improving your organization's privacy program. 

June 11, 2021

Learn more