What you learn:
- Identify required records and retention periods
- Understand privacy and data protection considerations
- Apply cross-border compliance practices
- Prepare for internal and external audits
Description:
Proper recordkeeping supports compliance and protects both employees and organizations. This module reviews data retention, privacy considerations, and reporting requirements across jurisdictions. You will explore templates for consistent documentation and audit readiness.
The course emphasizes practical steps to maintain accurate records while respecting privacy and confidentiality concerns.
Overview
Under GDPR and UK GDPR, organizations must protect personal data collected in harassment incidents. This includes incident reports, witness statements, and related communications used for investigation and remediation.
Purpose limitation and data minimization are essential. Collect only information that is necessary to understand and resolve the case. Clearly state the lawful basis for processing and document the purpose for which data is used.
Transparency and accuracy matter. Provide a privacy notice to data subjects, keep records current, and restrict processing to defined purposes and timeframes.
- Identify categories of personal data
- Assign data controller and processor roles
- Document processing activities and retention needs