First step in getting prepared to meet GDPR requirements is analyzing each and every company process from the perspective of its involvement into working with personal client data (emails, passwords, Credit Card data) and other GDPR related aspects. Judging from our experience, this stage lasts from one to three months, depending on the company size.
We started to analyze the Company’s workflow, assets and processes in late December 2017.
We worked with every department and person in the Company, who has access to clients personal data – security, legal, IT, marketing and other departments potentially involved in working with users’ data. Among the number of GAPs we have found, there were GDPR violations in site Privacy Policy, Cookie usage and user data management procedures, being one of the primary points to be addressed for GDPR.
Due to company size, it took us approximately 2 months to point out all the violations of GDPR data regulation.