Reference · 4.3

Use cases, and how each one is tested.

The catalogue holds 30 primary governance use cases and two operational suites. Each one states what it proves, the registers it touches, the article of the regulation it answers to, the steps performed in the workspace, and the criteria it is accepted against. They are the same use cases the product is tested against, so the documentation and the test plan are one document.

Where the evidence is a document rather than a record, the template supplied with your subscription is named on the use case.

Governance and inventory

Establish the scope of the management systemDefine the organisations, business units, jurisdictions and processing operations the management system covers, and hold the exclusions with a reason.Articles 3, 5(2) and 24 · POLRegister a privacy relevant entityCreate an entity as a controller, joint controller, processor, subprocessor, recipient, representative, public authority or supervisory authority, reusable across every linked record.Articles 4, 26 to 28 · DPA, JCADetermine the role held for a processing relationshipRecord the role each entity performs for a specific processing activity, so one organisation may hold different roles for different activities.Articles 4(7) to 4(10), 26 and 28 · JCA, DPACreate a processing activityCharacterise one processing operation by purpose, lawful basis, data subjects, personal data, systems, recipients, retention and transfers, and validate it before approval.Articles 5, 6 and 30Separate materially distinct purposesDetect an activity carrying several materially distinct purposes or lawful bases and separate it into independently governed activities, preserving the links that still apply.Articles 5(1)(b), 6 and 6(4)Approve and activate a processing activitySubmit an activity for review, and block activation where critical answers, conditional assessments, agreements or approvals are missing.Articles 5(2), 24 and 25 · DPIA, LIALink systems, assets and data flowsIdentify where personal data is collected, stored, accessed, transferred and deleted, and make each resource traceable to the activities and entities that use it.Articles 5, 25, 30 and 32Generate and maintain the record of processingCompile the approved activities into a controller or processor record of processing, and reflect changes to source records through controlled regeneration rather than manual editing.Article 30

Lawfulness and transparency

Determine the lawful basisSelect and justify the lawful basis for an activity, and trigger the evidence the selected basis requires.Article 6 · LIAPerform a legitimate interests assessmentDocument the purpose, the necessity and the balancing test where legitimate interests are relied upon, and require approval before the activity becomes active.Article 6(1)(f) · LIAEstablish and record valid consentDefine what consent covers, how it was presented, who gave it, when, and how the evidence is retained, tied to the exact purpose and the version of the information shown.Articles 6(1)(a), 7 and 8Withdraw consentRecord a withdrawal, identify every activity depending on that consent, and trigger cessation, deletion, restriction or a review of the basis.Articles 7(3) and 17 · DSRAssess special category or criminal offence dataIdentify processing involving Article 9 or Article 10 data and require the condition, the legal authority and the safeguards before approval.Articles 9 and 10Create or update a privacy noticeProduce the transparency information for one or more activities, covering the collection context, purposes, bases, recipients, transfers, retention and rights.Articles 12 to 14Assess profiling and automated decisionsDetermine whether profiling or solely automated decision making occurs, whether it produces legal or similarly significant effects, and record the safeguards and the information owed.Articles 13 to 15 and 22 · DPIAReview necessity and data minimisationAssess whether each category of personal data is adequate, relevant and limited to the purpose, and raise a remediation where it is not.Articles 5(1)(c) and 25

Risk and controls

Screen an activity for a data protection impact assessmentApply the screening criteria on creation and on change, and either document why an assessment is unnecessary or begin one.Article 35 · DPIAPerform and approve an impact assessmentDescribe the processing, assess necessity and proportionality, identify risks to individuals, define measures, and block activation while unacceptable residual high risk remains.Article 35 · DPIAEscalate for prior consultationWhere high residual risk remains, record the decision to consult the supervisory authority and preserve the submission, the correspondence and the outcome.Article 36 · DPIADefine and link technical and organisational measuresCreate reusable measures and link them to activities, systems, suppliers, risks and assessments, showing whether each is implemented, verified and current.Articles 24, 25 and 32Conduct a privacy by design reviewReview a proposed system, product or material change before implementation, and turn the requirements into controlled actions, design constraints or measures.Article 25Assess a material processing changeEvaluate a change to purpose, data, systems, recipients, suppliers, locations or technology, and identify which linked records need revision and whether reapproval is required.Articles 5(2), 24, 25 and 35(11) · DPIA, TIAEstablish retention and disposal requirementsDefine retention rules by activity, category, purpose and legal requirement, and make expiry trigger deletion, anonymisation, return or a documented extension.Articles 5(1)(e), 13, 14 and 17 · RETVerify disposal or return of personal dataExecute and evidence a scheduled or event driven deletion, anonymisation, return or suppression, confirmed across the systems, the processors and the copies.Articles 5(1)(e), 17 and 28 · RET, DPA

Documents supplied with a subscription

These templates are issued when a register opens. The use cases above cite them by code, so the evidence trail runs from the record to the document that carries it.

JCA · Joint controller arrangement
Allocates responsibilities between joint controllers, names the contact point and states the essence of the arrangement made available to data subjects. Article 26.
DPA · Data processing agreement
The processor contract, with the instructions, confidentiality, security, subprocessing, assistance, return and audit terms Article 28(3) requires.
LIA · Legitimate interests assessment
The purpose, necessity and balancing test relied upon where processing rests on Article 6(1)(f).
TIA · Transfer impact assessment
The assessment of the destination, the safeguard relied upon and the supplementary measures applied to a transfer. Articles 44 and 46.
DPIA · Data protection impact assessment
The description, the necessity and proportionality test, the risks to individuals and the measures adopted. Article 35.
SCC · Standard contractual clauses pack
The Commission clauses with the annexes prepared for completion from the transfer record. Article 46(2)(c).
RET · Retention and disposal schedule
Retention rules by activity, category and legal requirement, with the disposal method for each. Article 5(1)(e).
BRP · Breach response procedure
Triage, awareness time, assessment, notification and communication steps, with the notification forms. Articles 33 and 34.
DSR · Data subject request procedure
Intake, verification, search, decision and response templates for each right. Articles 12 and 15 to 22.
POL · Data protection policy set
The governing policies, the scope statement of the management system and the roles that carry it. Articles 5(2) and 24.