KVKK starter checklist
What an organisation new to compliance should look at on the first pass.
Items · 15
- Have the units that process personal data been listed?
- Has it been written which data categories each unit processes?
- Has a purpose been written for every processing activity?
- Has a legal ground been identified for every purpose?
- Has it been established whether special category data is processed?
- Have transfers outside the organisation been listed?
- Do contracts with processors contain data processing terms?
- Has a retention period and its basis been written for every data category?
- Has the privacy notice been prepared and published?
- Has processing that relies on explicit consent been separated out?
- Has a channel been defined for data subject requests?
- Has the VERBIS obligation been assessed?
- Is it written down what happens in a data breach?
- Are access rights recorded?
- Have employees been briefed?

