Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Compliance Checklist #1

Open
20 of 39 tasks
paulca opened this issue Apr 24, 2018 · 0 comments
Open
20 of 39 tasks

Compliance Checklist #1

paulca opened this issue Apr 24, 2018 · 0 comments

Comments

@paulca
Copy link
Contributor

paulca commented Apr 24, 2018

Infrastructure

  • Set up new stack inside VPC
  • Migrate stack to new infrastructure inside VPC
  • Update public policy pages

Documents

  • Terms of Service
    • initial draft from legal team
    • initial team feedback
    • legal team review
    • final version review and signoff
  • Shortform terms for easier reading
    • initial internal draft
    • legal team signoff
  • Privacy Policy
    • initial internal draft
    • legal team review
  • Data Retention Policy
    • initial internal draft
    • legal team review
  • Security Policy
    • initial internal draft
  • Third parties
    • initial internal draft
    • descriptions and contact details for full list

Features

  • An opt-in / data privacy page for our customers (tempted to offer granular control over where their data ends up. Don't want to be in Hubspot? No problem! But maybe not)
  • Opt-in / terms page pre-signup
  • Opt-in / terms page for existing users
  • A new "Consent" question type
  • Ability for organisers to add organiser info, address, data protection officer details, retention policy, third-party lists etc.
  • anyone should be able to drop their email address into a form and get a link to all the data we hold for them. This would solve the ticket retrieval thing once and for all too. Perhaps there should also be a way to delete or request deletion of this data.
  • a “delete my account” feature
  • improvements to T&Cs feature — either by changing the flow so that it’s shown on the ticket rather than the order, or I guess the consent question type might cover this

Internal policies

  • 2FA everywhere
  • purge any copies of databases containing customer data from employee machines
  • General company equipment audit
  • General company email audit
  • Identify and appoint a data protection officer and provide details

Training

  • Research and produce GDPR guide for event organisers (link)
  • GDPR Seminar from legal expert specific to event organisers for employees and customers (link)
    • Documentation on the above with link to recording.
  • GDPR training event for all employees
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant