Excerpt 1
DATA PROCESSING REGISTER
General information Date added — Person responsible — Business function — Name and details of joint controller — Description of data — Source of data — Data subject or class — Data type — Where is the data stored? — In what format is the data stored? — Internal security measures — Who has access? — Purpose of data processing — Automated decision making? (including profiling) — Data processing impact assessment? — Lawful ground(s) for processing? — Record of lawful ground(s) for processing — Are all rights available to individuals? — How long is data retained? — Who is the data shared with or transferred to? — Where is the third party located? — If data destination is outside the EEA, how has adequate protection been achieved? — How is the data protected in transit? — Do we monitor the third party's use of the data? — How do we do this? — Date of last monitoring — Does the third party transfer/share the data with anyone else? — Who do they share it with? — What is the purpose of the transfer (or data sharing)? — Has our authorisation been obtained? — Relevant documents, eg contract with processor, DPIA, LIA — Any other comments?



