Reference · 4.3
Use cases, and how each one is tested.
The catalogue holds 30 primary governance use cases and two operational suites. Each one states what it proves, the registers it touches, the article of the regulation it answers to, the steps performed in the workspace, and the criteria it is accepted against. They are the same use cases the product is tested against, so the documentation and the test plan are one document.
Where the evidence is a document rather than a record, the template supplied with your subscription is named on the use case.
Governance and inventory
Lawfulness and transparency
Risk and controls
External parties and transfers
Operational suites
Documents supplied with a subscription
These templates are issued when a register opens. The use cases above cite them by code, so the evidence trail runs from the record to the document that carries it.
- JCA · Joint controller arrangement
- Allocates responsibilities between joint controllers, names the contact point and states the essence of the arrangement made available to data subjects. Article 26.
- DPA · Data processing agreement
- The processor contract, with the instructions, confidentiality, security, subprocessing, assistance, return and audit terms Article 28(3) requires.
- LIA · Legitimate interests assessment
- The purpose, necessity and balancing test relied upon where processing rests on Article 6(1)(f).
- TIA · Transfer impact assessment
- The assessment of the destination, the safeguard relied upon and the supplementary measures applied to a transfer. Articles 44 and 46.
- DPIA · Data protection impact assessment
- The description, the necessity and proportionality test, the risks to individuals and the measures adopted. Article 35.
- SCC · Standard contractual clauses pack
- The Commission clauses with the annexes prepared for completion from the transfer record. Article 46(2)(c).
- RET · Retention and disposal schedule
- Retention rules by activity, category and legal requirement, with the disposal method for each. Article 5(1)(e).
- BRP · Breach response procedure
- Triage, awareness time, assessment, notification and communication steps, with the notification forms. Articles 33 and 34.
- DSR · Data subject request procedure
- Intake, verification, search, decision and response templates for each right. Articles 12 and 15 to 22.
- POL · Data protection policy set
- The governing policies, the scope statement of the management system and the roles that carry it. Articles 5(2) and 24.