1. Roles & Responsibilities
-
Data Protection Lead
-
Staff compliance
-
Third-party processors under contract
2. Data Inventory & Classification
Maintain records of data categories and access rights.
3. Access Control
Role-based access, strong passwords, MFA.
4. Encryption
Data encrypted at rest and in transit.
5. Third-Party Agreements
All processors must sign a DPA.
6. Incident Response
Breach detection, containment, reporting to NDPC.
7. Retention & Deletion
Data deleted or anonymized after retention period.
8. Training
Regular staff training and awareness programs.
9. Audits
Annual internal audit on data protection.
10. Policy Review
Reviewed yearly or when major changes occur.