Truste GDPR Readiness Assessment Sample
Truste GDPR Readiness Assessment Sample
Truste GDPR Readiness Assessment Sample
Sample
About the Assessment: This high-level readiness assessment is designed to help companies understand the core obligations of the
European Union's General Data Protection Regulation (GDPR), and determine which business processes they will need to review and
implement in preparation for the GDPR. This version of the Assessment is based on the final version of the GDPR which was formally
adopted by Parliament on April 14, 2016. The GDPR is scheduled to take effect in Spring 2018.
Note - This sample contains one section of the full TRUSTe GDPR Readiness assessment. To access the full 70+ question template, or find
out about our other privacy assessment templates, contact your TRUSTe Representative.
Q#
Question
Possible
Responses
Compliant
Response
Remediation Recommendation
Section 1 - Transparency
Review general and specific Privacy Notices to ensure the following information is provided to individuals in advance of collecting personal information from
them.
A Privacy Notice is a comprehensive, outward-facing statement explaining the
organization's privacy policies and practices.
Yes
No
Yes
Yes
No
Yes
Include in the Privacy Notice the identity of and contact information for the
controller or the controller's representative, as well as the contact details of
the data protection officer (if any).
Q#
Question
Possible
Responses
Compliant
Response
Remediation Recommendation
Yes
No
N/A, this
assessment does
not relate to
information
processed based
on individuals'
consent
Yes
No
Yes
No
N/A, we do not
share or otherwise
disclose
individuals'
personal
information to third
parties
Yes
Yes
Explain in the Privacy Notice the purpose for collecting personal information,
including sensitive information, from individuals. The Notice should include a
description of how personal and/or sensitive information collected from
individuals will be used, including whether individuals' personal information will
be disclosed to third parties and a description of communications or other
contact an individual may receive by providing their personal information.
Disclosures of consumer privacy and sharing practices are key in building
trust in an organization. An organization's Privacy Notice that explains to
individuals and visitors how it uses and shares their personal information
helps achieve transparency and build user trust.
No
Q#
Question
Possible
Responses
Yes
No
N/A, we do not
share or otherwise
disclose
individuals'
personal
information to third
parties
Yes
No
Yes
No
Compliant
Response
Remediation Recommendation
No
Yes
Yes
The Privacy Notice should describe choices available to individuals about how
their personal information is used, including any choice programs whereby an
individual may indicate preferences about whether their personal information
is disclosed to third parties and preferences regarding the frequency, subject
matter, and/or format of communications.
Q#
Question
Possible
Responses
Compliant
Response
Remediation Recommendation
Yes
No
Yes
Websites:
Make the link conspicuous by using type that is larger than the surrounding
text, set in a contrasting color, or use symbols that call attention to it;
Put a conspicuous link to the Privacy Notice on the homepage and all pages
that collect personal information from individuals;
Format the Privacy Notice so that it can be printed as a separate document.
Mobile apps:
Provide a link to the Privacy Notice from the applications app store listing, so
that the Notice is accessible prior to downloading and installing an application;
Provide a link to the Privacy Notice from within the application. Typically, a
Privacy Notice can be found when accessing the app's settings.
10
Yes
11
Yes
No
Yes
Q#
Question
Possible
Responses
12
Yes
No
13
14
15
Yes
In the event that individuals are not informed in
No
advance of processing activities, are individuals
N/A, notice is
provided specific information about how their
provided prior or at
information is processed within a reasonable time
the time of
after the information has been collected and
personal
before the information is processed?
information
collection
Yes
No
Compliant
Response
Remediation Recommendation
Yes
The Privacy Notice should appear in the language(s) in which the organization
conducts business. For example, if the organization's services support
English, French, and German, the Privacy Notice should be available in those
languages.
Yes or N/A
Yes
Yes
Q#
Question
Possible
Responses
Compliant
Response
Remediation Recommendation
Tired of managing assessments in a spreadsheet? Schedule a demo of TRUSTe Assessment Manager, an online / interactive
system that streamlines the process of conducing and managing privacy assesments and PIAs.