Contents Acknowledgement 04 Introduction 05 Collection 08 Lawful Basis 08 Legitimate interests of who? 08 Consent 08 Being transparent about your handling of personal information 09 Ways to provide information 10 Data minimisation (or only collecting what you really need) 10 Use 12 Purpose Limitation (or only use for the reason that you told people) 12 Internal sharing and access 12 Disclosure 14 External Data Sharing 14 Internal Data transfers 15 Being Responsive: handling requests, queries and complaints 15 Contact information 15 Requests for access, correction and deletion 15 Complaints 15 Storage and Security Storage 18 18 Risks of on premises storage 18 Risks of cloud or remote storage 19 Physical Security 19 Cyber Security 19 Managing Data Breaches 20 Identifying a data breach 20 Notification procedures 20 Mitigation measures 20 Staff Training and Awareness Retention and Deletion Data Protection Guidelines for NHRIs Toolkit 21 23 3

Select target paragraph3