Collect only needed data, shorten retention, restrict roles. Remove unnecessary fields from forms/systems.
Controller sets purposes/means; processor acts on behalf. Contracts must define security, purpose, duration, and instructions.
Notify the Authority as soon as possible, typically within 72 hours; assess impact and inform affected persons.
Include controller identity, purposes, legal basis, transfers, retention, and data subject rights. Add current contact and request channels.
Controllers must respond within 30 days. Requests should be filed in writing or via registered channels with verified identity; deadlines run from proper receipt.