The overall objective of the ARC project is enabling the Irish and Croatian DPAs in raising awareness about GDPR compliance among SMEs in Ireland and Croatia, as well as providing direct guidance to these businesses on practical implementation of the personal data protection laws.

Challenge

Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka-AZOP) and Data Protection Commission Ireland during their every day work noticed that there is still a lot of ambiguities in the application of the GDPR by the SMEs. These findings are also supported by a large number of written queries and even greater number of phone calls which this two authorities receive on daily basis. It is essential to emphasize that SMEs are still struggling with the implementation of the GDPR and sometimes do not even know how to begin in order to align their business activities with the GDPR requirements.

SME GDPR Compliance Toolkit 


This toolkit is a digital transformation of the DPC GDPR Readiness Checklist Tools. It provides a collaborative and scalable GDPR compliance solution using Microsoft 365 Excel or Google Sheets and is designed to assist Small to Medium-sized Enterprises (SMEs) to map, record, assess, review, and demonstrate the personal data that they currently hold and process, the lawful basis on which the data was collected, and the retention period for each category of data.

The use of the toolkit will help you identify and document where immediate remedial actions are required and to upload and attach all supporting evidence in one place in order to be compliant with the GDPR. Most importantly the toolkit is updateable and you can share comments, track changes and request approvals to get the feedback you need to meet and improve all your GDPR compliance processes and procedures.

The toolkit helps organisations to work collaboratively with a scalable solution to achieve GDPR compliance, including providing helpful weblinks to relevant GDPR guidance and articles and to ensure you understand and meet accountability and transparency requirements and most importantly are able to demonstrate this. See GDPR Articles 12, 13 and 14, also: https://www.dataprotection.ie/en/organisations/know-your-obligations/transparency