The rules and principles which apply
Effective data protection compliance requires organisations to maintain accurate records of their personal data processing activities and to undertake appropriate risk assessments where processing presents risks to the rights and freedoms of individuals. These records demonstrate accountability, support informed decision making, and provide evidence of compliance with the UK GDPR and the Data Protection Act 2018.
Article 5 (2) of the UK GDPR established the accountability principle, requiring firms not only to comply with data protection principles but also to demonstrate that compliance.
Article 25 UK GDPR requires firms to adopt a ‘data protection by design and default’ approach which means that data protection should be built into your processing activities from the outset and that, unless an individual chooses otherwise, the least privacy-intrusive settings or options should apply automatically. In practice, this means carefully considering privacy risks and appropriate safeguards when designing or changing any process, system, product, service or procedure that involves personal data and in particular carrying out documented risk assessments where the processing may pose a higher risk to an individuals rights and freedoms.
Article 30 UK GDPR requires that certain firms maintain a formal record of their processing activities, known as the ROPA. All firms who have more than 250 employees must maintain a ROPA, however there is a limited exemption for firms who employ less than 250 employees who may not need to document all processing activity, particularly where the activity is infrequent and not likely to result in a risk to the rights and freedoms of individuals. In practice most SME broking firms will however be processing personal data frequently for core business purposes and therefore this exemption is not likely to apply to the firm’s core processing activities, but it may exclude infrequent activities such as conducting an employee engagement survey for example. In practice even if you may be exempt from documenting some processing activities the ICO still states that it is best practice for firms to do so.
Many firms choose to combine their ROPA with their Data Asset Register (DAR) into one single document, there is no requirement under the UK GDPR that stipulates that these should be held separately provided the combined register satisfies the requirements of Article 30 UK GDPR .
Firms must also complete certain risk assessments, particularly where the processing may have a higher risk of impacting an individual’s rights and freedoms, when transferring data outside of the UK, and where the firm relies upon the lawful basis of legitimate interest for any processing activity.
It is also best practice for firms to maintain a record keeping policy not only to enable firms to maintain its records for legal and regulatory purposes but also to inform data retention schedules ensuring that data is not kept for longer than is necessary.
Failure to maintain adequate records or undertake appropriate risk assessments may expose the organisation to regulatory action, enforcement measures, financial penalties, and reputational damage.
How this may affect firms
Documentation should be proportionate to the size, nature, complexity, and risks associated with the firm’s processing activities and may typically include the following:
- Record of Processing Activities (ROPA)
- Data Asset Register (DAR)
- Data Protection Impact Assessments (DPIA)
- Legitimate Interest Assessments (LIA)
- Transfer Risk Assessments (TRA)
- Record Keeping Policy
This is in addition to the firm’s overarching policies and procedures in relation to data protection and information security and governance records such as outcomes monitoring, audits, decisions, and action logs.
Senior Management retains overall responsibility for ensuring:
- appropriate records are maintained and that they remain accurate and current
- new processing is assessed before implementation.
- Identified risks are record and managed
- Reviews are completed at scheduled intervals.
The DPO (where appointed) or the SMF who has been given the responsibility for data protection compliance, should provide advice, monitor compliance, and review and approve assessments where appropriate, and ensure that the firms senior managers and governing body are kept appropriately informed.
Firms may also seek to periodically review its data protection documentation through internal audit, management reviews, and other routine monitoring to ensure documentation demonstrates on-going compliance with UK GDPR, reviews should confirm that:
- Records remain accurate
- Processing reflects documented practices
- Risk assessments remain valid
- Mitigation measures remain effective
- Legal developments have been considered and any changes implemented
Combined Record of Processing Activities (ROPA) and Data Asset Register (DAR)
Many firms, particularly SME’s combine their ROPA and DAR into one register as this can have a number of benefits and efficiencies such as:
- Reducing duplication of information
- Improving consistency across records
- Simplifying maintenance and review
- Providing a single source of truth for data governance
- Facilitating risk assessments, DPIA’s, retention reviews and audit activity
Typically, a combined register will commonly include:
- Asset name
- Processing activity
- Business Owner / Responsible SMF
- Purpose of processing
- Data subjects
- personal data held
- special category/criminal offence data held
- recipients (who data is shared with)
- data processers used
- international transfers
- retention schedule
- technical and organisational measures (Security Controls)
- Where there is any linked risk assessment (DPIA/LIA/TRA)
- Link to privacy notice
- Link to processor contracts
- Review Date
A mature compliance framework often treats the combined register as the central data governance record, with other compliance documents linked to it. Each processing activity or data asset can reference the relevant supporting documentation, making it easier to demonstrate compliance during monitoring exercises, audit activity, or regulatory inspections.
We have included a template combined data asset register at Download Document CORE26 , which firms can personalise to their arrangements.
We have also included further information on the various risk assessments required in Section K.6.1.1