Privacy · Quoted on agreed scope
Most records of processing are built in a workshop and describe what people believe happens. We build yours from what the systems can be made to show, mark the entries that could only be established by asking, and leave you something your own people can maintain.
Who this is for
A record of processing is the document every other privacy obligation depends on. Retention cannot be assessed without knowing what is held, a subject access request cannot be answered without knowing where to look, and a breach cannot be scoped without knowing what was in the system.
The Act requires you to know what you process and why. A record is how that is demonstrated, and it is the first thing asked for.
Acquisitions, departed staff, a supplier portal from three years ago. These are the entries that do not appear in a workshop, because nobody in the room remembers them.
If it was assembled in a room without exports, it describes the systems people think about rather than the systems that hold data.
What it protects
A processing record looks like paperwork and behaves like plumbing. Three things become cheap once it exists, and stay expensive until it does.
Without a record, every request starts with finding the systems. With one, it starts with a lookup. Time the last one your organization handled and the difference is the return.
When something is compromised, the first question is what was in it. A record answers that in minutes. Without one, the answer arrives after the notification decision has already had to be made.
Every record surfaces data nobody needs and nobody deleted. That is storage cost, breach exposure and retention risk removed in one pass, and it is usually the part that pays for the work outright.
The four stages
Your administrator runs the extracts and you see the output before it leaves your network. Nothing of ours runs inside your environment, and no credential is handed over.
What each command reads is written down before you agree to it, so the scope is a document rather than a promise.
Exports cannot tell you why data is held or who decided. Those questions are asked, and the answers are recorded as answers.
Every entry in the finished record carries how it was established. A reader can tell which rows rest on a configuration and which rest on somebody's memory, which is the distinction that makes the record usable a year later.
Each processing activity linked to its lawful basis, its retention position and any transfer outside Jamaica. A record that only describes systems answers an architect. A record that carries the obligations answers a regulator.
A procedure your own people run, on a stated cadence, with the extracts that feed it. A record only we can update is a record that is wrong within a year, and the point of building it from exports is that it can be rebuilt the same way.
What gets recorded
These are the fields that make a record answer a question rather than list a system.
| Field | What it answers |
|---|---|
| Activity and purpose | Why the data is held. Activities nobody can justify surface here, and they are usually the oldest. |
| Categories of data subject | Employees, customers, patients, applicants. Changes what obligations attach. |
| Categories of personal data | Including whether anything is sensitive or relates to criminal convictions, which changes whether a data protection officer is required. |
| Systems and locations | Where it actually sits, including the shares and spreadsheets that are not on anybody's system list. |
| Lawful basis | Recorded per activity. Where it is consent, the record of that consent. |
| Retention as configured | Not the policy number. The setting, or the absence of a mechanism. |
| Recipients and transfers | Who else receives it, including processors, and anything leaving Jamaica with the condition that permits it. |
| Source | Export or interview, and the date. This is the field that lets a reader weigh the row. |
How we work with your team
Nothing of ours runs in your environment and no credential is handed over. Your team sees every output before it leaves the network, which also means they learn what the record is made of.
We ask only where an export cannot answer. Nobody sits in a day-long workshop describing systems a configuration could have told us.
The extract commands and the maintenance procedure come with the record, so next year is a refresh your team runs rather than an engagement you buy again.
What you end up with
What changes afterwards
For a request, an incident or a customer question.
With a list and a reason for each, rather than a general intention.
The record is the prerequisite for the section 45 return, so the next obligation starts from work already done.
Boundaries
Your administrator runs every extract. If a system cannot produce one, that is recorded as a limitation rather than worked around.
Establishing that a share holds personnel records is in scope. Establishing what is in each file is not, and anybody offering it at this price is scanning rather than reading.
The gap list says what is missing and what would close it. Closing it is separate work.
Before commissioning anything, ask your administrator for a list of systems holding personal data and the retention setting on each. What comes back, and how long it takes, tells you most of what this engagement would involve.