Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Privacy · Quoted on agreed scope

A processing record that matches your systems

Most records of processing are built in a workshop and describe what people believe happens. We build yours from what the systems can be made to show, mark the entries that could only be established by asking, and leave you something your own people can maintain.

Basis
Quoted on agreed scope
Input
System exports, then interviews
Ends with
Record, data map, gap list
Refresh
On an agreed cycle

Who this is for

Anybody who has been asked where the data is and could not answer quickly

A record of processing is the document every other privacy obligation depends on. Retention cannot be assessed without knowing what is held, a subject access request cannot be answered without knowing where to look, and a breach cannot be scoped without knowing what was in the system.

You are preparing for an obligation

The Act requires you to know what you process and why. A record is how that is demonstrated, and it is the first thing asked for.

You inherited systems nobody documented

Acquisitions, departed staff, a supplier portal from three years ago. These are the entries that do not appear in a workshop, because nobody in the room remembers them.

Your existing record was built from memory

If it was assembled in a room without exports, it describes the systems people think about rather than the systems that hold data.

What it protects

The record is infrastructure, and everything else runs on it

A processing record looks like paperwork and behaves like plumbing. Three things become cheap once it exists, and stay expensive until it does.

Answering a subject access request

Without a record, every request starts with finding the systems. With one, it starts with a lookup. Time the last one your organization handled and the difference is the return.

Scoping an incident

When something is compromised, the first question is what was in it. A record answers that in minutes. Without one, the answer arrives after the notification decision has already had to be made.

Retiring what you should not hold

Every record surfaces data nobody needs and nobody deleted. That is storage cost, breach exposure and retention risk removed in one pass, and it is usually the part that pays for the work outright.

The four stages

What we actually do

1

Extract what the systems can show

Your administrator runs the extracts and you see the output before it leaves your network. Nothing of ours runs inside your environment, and no credential is handed over.

What each command reads is written down before you agree to it, so the scope is a document rather than a promise.

  • Account and mailbox inventories, and where each sits.
  • File share and storage locations, with their access groups.
  • Database and application inventories, and the integrations between them.
  • Retention and deletion settings as configured, not as written.
2

Interview only for the gaps

Exports cannot tell you why data is held or who decided. Those questions are asked, and the answers are recorded as answers.

Every entry in the finished record carries how it was established. A reader can tell which rows rest on a configuration and which rest on somebody's memory, which is the distinction that makes the record usable a year later.

3

Map it to obligations

Each processing activity linked to its lawful basis, its retention position and any transfer outside Jamaica. A record that only describes systems answers an architect. A record that carries the obligations answers a regulator.

4

Hand over the maintenance

A procedure your own people run, on a stated cadence, with the extracts that feed it. A record only we can update is a record that is wrong within a year, and the point of building it from exports is that it can be rebuilt the same way.

What gets recorded

Per processing activity, and why each field is there

These are the fields that make a record answer a question rather than list a system.

FieldWhat it answers
Activity and purposeWhy the data is held. Activities nobody can justify surface here, and they are usually the oldest.
Categories of data subjectEmployees, customers, patients, applicants. Changes what obligations attach.
Categories of personal dataIncluding whether anything is sensitive or relates to criminal convictions, which changes whether a data protection officer is required.
Systems and locationsWhere it actually sits, including the shares and spreadsheets that are not on anybody's system list.
Lawful basisRecorded per activity. Where it is consent, the record of that consent.
Retention as configuredNot the policy number. The setting, or the absence of a mechanism.
Recipients and transfersWho else receives it, including processors, and anything leaving Jamaica with the condition that permits it.
SourceExport or interview, and the date. This is the field that lets a reader weigh the row.

How we work with your team

Alongside your people, not over them

Your administrators run every extract

Nothing of ours runs in your environment and no credential is handed over. Your team sees every output before it leaves the network, which also means they learn what the record is made of.

Interviews are short and targeted

We ask only where an export cannot answer. Nobody sits in a day-long workshop describing systems a configuration could have told us.

You get the method, not just the document

The extract commands and the maintenance procedure come with the record, so next year is a refresh your team runs rather than an engagement you buy again.

What you end up with

A record you can maintain, and the gaps it found

What you keep

  • The record of processing activities, every entry sourced and dated.
  • A data map showing systems, flows, transfers and retention as configured.
  • A gap list: activities with no lawful basis recorded, transfers with no agreement, retention with no mechanism, systems with no owner.
  • A maintenance procedure and the extract commands that feed it, so your own people can rebuild it.

What this is not

  • Automated discovery across your network. We work from what your administrators export. Nothing scans and nothing is installed.
  • Classification of individual documents. We establish where categories of data live, not what is in a particular file.
  • An assessment. A record describes. Whether your controls work is a different engagement, and we say so rather than letting the record imply it.

What changes afterwards

What your organization can do that it could not before

Answer where the data is, immediately

For a request, an incident or a customer question.

Delete what you should not hold

With a list and a reason for each, rather than a general intention.

Build the annual assessment on top

The record is the prerequisite for the section 45 return, so the next obligation starts from work already done.

Boundaries

What is not included

Anything requiring access to your systems

Your administrator runs every extract. If a system cannot produce one, that is recorded as a limitation rather than worked around.

Unstructured content at document level

Establishing that a share holds personnel records is in scope. Establishing what is in each file is not, and anybody offering it at this price is scanning rather than reading.

Remediation of the gaps

The gap list says what is missing and what would close it. Closing it is separate work.

Most of the answer already exists in exports

Before commissioning anything, ask your administrator for a list of systems holding personal data and the retention setting on each. What comes back, and how long it takes, tells you most of what this engagement would involve.