Privacy · Annual, and organization wide
Section 45 requires a data controller to submit a data protection impact assessment to the Commissioner within ninety days of each year end, covering all personal data in its custody, not one project. We build yours from your processing record, rate the risk each activity leaves, and write it so the accountable person can defend every conclusion in it.
Who this is for
This is not the project-triggered assessment familiar from other regimes. The Act asks for an annual assessment across everything you hold. The Commissioner has said the submission requirement is not yet in effect, and has advised controllers to keep analysing and revising their processing activities in the meantime rather than waiting, so that gaps and risks are found before a return is ever due.
Most organizations have not, because the form has not been prescribed. The work does not depend on the form: the analysis is the same and the return is a presentation of it.
Health, financial, biometric or criminal conviction data raises what a risk rating has to justify, and raises the consequence of getting it wrong.
A record lists what you do. The assessment says what risk each activity carries and what is left after your controls. It is the layer above.
What it protects
The submission requirement is not yet in effect. When the Commissioner prescribes the form, every controller in Jamaica has ninety days from year end, at the same time, competing for the same advisers.
An organization with a processing record and a current risk position turns the return into a presentation exercise. One without spends the window doing the analysis, at the point when everybody else is too.
The value of an assessment is that somebody can follow the reasoning a year on. Where a residual risk was accepted, by whom, and on what basis. Without it, a decision that turned out badly looks like nobody made it.
Necessity and proportionality are cheap to answer at design and expensive after launch. An annual cycle that catches them still costs less than one rebuild.
The four stages
An assessment covering all personal data needs a list of all personal data. Where you have a record of processing, we work from it. Where you do not, that is the first piece of work and we say so rather than assessing what somebody can remember in a workshop.
Activities absent from the record are absent from the assessment, which is how an annual return ends up describing an organization that does not exist.
Whether each activity needs the data it takes. This is the question that most often changes something, and the one a template skips fastest.
Fields collected against fields consumed. Retention claimed against retention configured. Recipients listed against recipients who actually receive.
Risk to the data subject and risk to the organization point in different directions often enough that conflating them is how an assessment passes something it should have stopped.
Each risk rated against a scale that is written down and travels with the document, so a reader can re-derive the rating rather than take it.
Who was consulted, what they said, and what changed as a result. Where a data protection officer or anybody else disagreed with an outcome, that is recorded rather than resolved quietly.
An assessment that shows only agreement tells a regulator nothing about how the decision was made.
What the assessment covers
Section 45 sets what the assessment has to address. These are the parts that carry the weight.
| Part | What it has to establish |
|---|---|
| The activity | What is processed, for what purpose, and under which lawful basis. Taken from the processing record, not from memory. |
| Necessity | Whether the purpose needs this data. An activity that cannot answer this is the finding. |
| Proportionality | Whether the amount, the retention and the reach are proportionate to the purpose. |
| Risk to data subjects | What could go wrong for the individual, rated against a stated scale. |
| Measures | What reduces each risk, and the residual each measure leaves. |
| Transfers | Anything leaving Jamaica, with the condition permitting it. |
| Acceptance | Who accepted the residual risk, and when. An unnamed acceptance is not an acceptance. |
| Review trigger | What would require this to be revisited before the next annual cycle. |
How we work with your team
The activity owners answer for necessity and proportionality, not a consultant guessing on their behalf. Our job is to ask the question properly and record the answer so it holds up.
Every residual is presented with what it means before anybody signs. Nobody discovers what they accepted after the fact.
The assessment is structured so the next cycle updates it rather than repeats it. The first year carries the cost; the years after should not.
What you end up with
What changes afterwards
As a presentation of analysis you already hold, inside the ninety days.
Including who accepted a residual risk and on what basis.
Because the triggers are written down rather than remembered.
Boundaries
If you do not have one, it is prerequisite work and quoted separately. We will not assess an inventory assembled from memory and call it comprehensive.
Measures are assessed from evidence and configuration. Establishing whether a control actually operates is a control assessment, and it is a different engagement.
The assessment says what risk remains and what would reduce it. Reducing it is separate work, and where we do that work the next assessment records that we did.
An assessment covering all personal data is only as complete as the list it starts from. If you do not yet have a processing record, start there, and the assessment becomes a straightforward piece of work on top of it rather than a discovery exercise wearing the wrong name.