- Right to information: This right requires you to be transparent about how you use the information collected from customers or users. Usually, you provide this information in the privacy policy of your website, update this document to provide clear and concise information about your usage of the personal data.
- Right to access data: When a customer or user requests you to send their data, you should send it them in commonly used format like CSV.
- Right to correct or rectify data: In case of inaccurate data, you must let your clients or users rectify it.
- Erasure of data or Right to be forgotten: When there is no compelling reason to continue processing of the data, your clients or users may request to remove or delete it. ?
- Restrict data processing: As per this right individuals can request companies to stop processing their data. In that situation, companies can store the data but not allowed to process.
- Right to portability: Individuals should be allowed to access and reuse their personal information for their own purposes.
- Right to object: Individuals can object on their data usage including in fields like research, marketing, and statistics.
- Right pertaining to automatic decision making, including profiling: This defines the conditions in which you can use automated decision making and profiling. Plus, it also explains about the requirements to be met such as explicit consent of individuals.
- Conduct a data audit: To make sure that you are safely handling the data from your customers or users, you should figure out a different aspect of this process.
- Define a clear and precise privacy policy: This document is where you describe the procedure on data collection, usage, storage and other processes. Define everything clearly pertaining to individuals? data handling. ?
- Implement SSL certification: Those websites that use HTTPS send data through an encrypted connection. So, if you have a SSL certificate, you have taken a step ahead to adhere to GDPR. In absence of HTTPS, your website sends encrypted data which may be intercepted in transit. ??
- Determine and document a clear process in case of a data breach: The new law requires that data controlled should establish a procedure to be followed in case of data breach. According to the regulation, data controller is obliged to report the data breach within 72 hours to authorities.
- Processing of data collected from children: Organizations which collect information from children need to take consent from their parents or guardians before processing their data legally. According to the law, children with a minimum age of 16 years can give their own consent for data processing. Mention information in your privacy policy precisely and in a way that 16 year child can understand.



