1. What data do we collect and manage?
  2. Why do we collect this data?
  3. How do we source this data?
  4. What is our legal basis for holding this data?
  5. How do we minimise risk for people whose data we hold?
  6. How do we secure this data?