Gdpr checklist
Gdpr audit questionare
What does this form include?
This form contains 3 sections:
All computer stations left locked when unattended?
- All computer stations left locked when unattended?
- Is customer data restricted to the public?
- Is the location of the work station suitable to allow privacy?
- Are printers / scanners or other machines free from customer data?
- Documents containing personal information is not stored in desk drawers?
- Are desk draws secure?
- Are staff able to justify any physical copies of data they are storing?
- Is there a clear desk policy?
- Are phone calls with customers done in private areas?
- Are Wren computer systems and issued equipment being used to contact customers?
- Are break rooms or other communal areas free from sensitive information?
Who has access to the managers office?
- Who has access to the managers office?
Is sensative information obscured from view in the managers office?
- Is sensative information obscured from view in the managers office?
- Are CCTV signs in appropriate places?
- Is the IT equipment secure?
- Is the server room kept locked?
- Is access to the CCTV footage restricted?
- Are people taking paperwork off site?? Is it done securely ((e.g. in Folders))?
- Are shredders being used to dispose of sensitive documents?
- Are staff aware of any policies or memos relating to data security (Ask two employees)?
- Are Lecterns screens positioned to restrict privacy?
Use this template