Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Privacy · Annual, and organization wide

The assessment the Act asks you to submit every year

Section 45 requires a data controller to submit a data protection impact assessment to the Commissioner within ninety days of each year end, covering all personal data in its custody, not one project. We build yours from your processing record, rate the risk each activity leaves, and write it so the accountable person can defend every conclusion in it.

Basis
Quoted on agreed scope
Scope
All personal data in your custody
Cadence
Annual, plus material change
Ends with
Assessment and risk register

Who this is for

Every data controller, which is a wider group than most expect

This is not the project-triggered assessment familiar from other regimes. The Act asks for an annual assessment across everything you hold. The Commissioner has said the submission requirement is not yet in effect, and has advised controllers to keep analysing and revising their processing activities in the meantime rather than waiting, so that gaps and risks are found before a return is ever due.

You have never done one

Most organizations have not, because the form has not been prescribed. The work does not depend on the form: the analysis is the same and the return is a presentation of it.

You process at scale or hold sensitive data

Health, financial, biometric or criminal conviction data raises what a risk rating has to justify, and raises the consequence of getting it wrong.

You have a record of processing and nothing built on it

A record lists what you do. The assessment says what risk each activity carries and what is left after your controls. It is the layer above.

What it protects

An annual return, and what it costs to meet it unprepared

The submission requirement is not yet in effect. When the Commissioner prescribes the form, every controller in Jamaica has ninety days from year end, at the same time, competing for the same advisers.

The ninety-day clock, when it starts

An organization with a processing record and a current risk position turns the return into a presentation exercise. One without spends the window doing the analysis, at the point when everybody else is too.

Decisions you cannot defend later

The value of an assessment is that somebody can follow the reasoning a year on. Where a residual risk was accepted, by whom, and on what basis. Without it, a decision that turned out badly looks like nobody made it.

Projects that ship and then have to change

Necessity and proportionality are cheap to answer at design and expensive after launch. An annual cycle that catches them still costs less than one rebuild.

The four stages

What we actually do

1

Start from the processing record

An assessment covering all personal data needs a list of all personal data. Where you have a record of processing, we work from it. Where you do not, that is the first piece of work and we say so rather than assessing what somebody can remember in a workshop.

Activities absent from the record are absent from the assessment, which is how an annual return ends up describing an organization that does not exist.

2

Assess necessity and proportionality per activity

Whether each activity needs the data it takes. This is the question that most often changes something, and the one a template skips fastest.

Fields collected against fields consumed. Retention claimed against retention configured. Recipients listed against recipients who actually receive.

3

Rate the risk to the individual, not to you

Risk to the data subject and risk to the organization point in different directions often enough that conflating them is how an assessment passes something it should have stopped.

Each risk rated against a scale that is written down and travels with the document, so a reader can re-derive the rating rather than take it.

  • Every measure recorded with the risk it reduces and the risk it leaves.
  • A measure with no stated residual is an assertion, and it is recorded as one.
  • Where the residual is accepted, the accountable person is named.
4

Record consultation, including disagreement

Who was consulted, what they said, and what changed as a result. Where a data protection officer or anybody else disagreed with an outcome, that is recorded rather than resolved quietly.

An assessment that shows only agreement tells a regulator nothing about how the decision was made.

What the assessment covers

Per processing activity, and what each part has to establish

Section 45 sets what the assessment has to address. These are the parts that carry the weight.

PartWhat it has to establish
The activityWhat is processed, for what purpose, and under which lawful basis. Taken from the processing record, not from memory.
NecessityWhether the purpose needs this data. An activity that cannot answer this is the finding.
ProportionalityWhether the amount, the retention and the reach are proportionate to the purpose.
Risk to data subjectsWhat could go wrong for the individual, rated against a stated scale.
MeasuresWhat reduces each risk, and the residual each measure leaves.
TransfersAnything leaving Jamaica, with the condition permitting it.
AcceptanceWho accepted the residual risk, and when. An unnamed acceptance is not an acceptance.
Review triggerWhat would require this to be revisited before the next annual cycle.

How we work with your team

Alongside your people, not over them

Built with the people who own the processing

The activity owners answer for necessity and proportionality, not a consultant guessing on their behalf. Our job is to ask the question properly and record the answer so it holds up.

Your accountable person accepts the risk, knowingly

Every residual is presented with what it means before anybody signs. Nobody discovers what they accepted after the fact.

Reusable next year

The assessment is structured so the next cycle updates it rather than repeats it. The first year carries the cost; the years after should not.

What you end up with

A document that answers the follow-up question

What you keep

  • The assessment, covering every activity in your processing record, ready to present in whatever form the Commissioner prescribes.
  • A risk register, each entry with its rating, its measures, its residual and a named owner.
  • The consultation record, including where somebody disagreed.
  • The rating scale, written down and attached, so a third party can re-derive every rating.
  • Review triggers, so material change is caught between annual cycles rather than at the next one.

What this is not

  • Sign-off. The accountable person in your organization accepts the residual risk. We do not, and cannot.
  • A decision to proceed. An assessment informs a decision. It does not make it.
  • Submission on your behalf. The return is the controller's own act, and the form is the Commissioner's to prescribe.
  • Legal advice. Where the question is whether processing is lawful at all, it goes to your counsel with the facts attached.

What changes afterwards

What your organization can do that it could not before

Meet the return when the form is prescribed

As a presentation of analysis you already hold, inside the ninety days.

Show how a decision was reached

Including who accepted a residual risk and on what basis.

Catch a material change between cycles

Because the triggers are written down rather than remembered.

Boundaries

What is not included

Building the processing record

If you do not have one, it is prerequisite work and quoted separately. We will not assess an inventory assembled from memory and call it comprehensive.

Technical testing

Measures are assessed from evidence and configuration. Establishing whether a control actually operates is a control assessment, and it is a different engagement.

Remediation

The assessment says what risk remains and what would reduce it. Reducing it is separate work, and where we do that work the next assessment records that we did.

The record comes first

An assessment covering all personal data is only as complete as the list it starts from. If you do not yet have a processing record, start there, and the assessment becomes a straightforward piece of work on top of it rather than a discovery exercise wearing the wrong name.