DATA PRIVACY SERVICES
Client Centre
Your team, your priorities and your next steps.
Latest team updates
SeptemberYour September compliance review is ready. We will discuss the outstanding actions during our monthly DPO call.
YOUR APPOINTED DPO
George Harris
Data Privacy Services
george@dataprivacyservices.co.ukDeputy DPO Hayley Harris
Your service centres
Data protection KPIs
Record the current monthly position, using annual totals where the KPI guidance requires them. Task completion supports the review; it does not automatically prove a KPI has been achieved.
| KPI and guidance | Current | Target | Status | Associated tasks |
|---|---|---|---|---|
Total Personal Data BreachesGuidance & review notesTarget should always be zero. Record number of breaches as and when they occur. | At most | Not recorded | Monitor through the relevant register or review | |
Reportable Breaches (ICO)Guidance & review notesTarget should always be zero. Record number of breaches as and when they occur. | At most | Not recorded | Monitor through the relevant register or review | |
Open Subject Access RequestsGuidance & review notesTarget should be a maximum of three. Record outstanding number on a monthly basis | At most | Not recorded | Monitor through the relevant register or review | |
SARs Within Deadline (%)Guidance & review notesTarget should be 100%. Record percentage based upon those completed during the period. | At least | Not recorded | Monitor through the relevant register or review | |
Open FOI RequestsGuidance & review notesTarget should be a maximum of two. Record outstanding number on a monthly basis | At most | Not recorded | Monitor through the relevant register or review | |
FOI Request Within Deadline (%)Guidance & review notesTarget should be 100%. Record percentage based upon those completed during the period. | At least | Not recorded | Monitor through the relevant register or review | |
Open Data Handling ComplaintsGuidance & review notesTarget should be a maximum of one. Record outstanding number on a monthly basis | At most | Not recorded | Monitor through the relevant register or review | |
Data Handling Complaints Within Deadline (%)Guidance & review notesTarget should be 100%. Record percentage based upon those completed during the period. | At least | Not recorded | Monitor through the relevant register or review | |
DPIAs CompletedGuidance & review notesTarget based upon an approximation of four per annum. Record number completed within the period. | At least | Not recorded | ||
DPIAs OutstandingGuidance & review notesTarget should be no greater than two. Record number outstanding based upon identified requriements. | At most | Not recorded | Monitor through the relevant register or review | |
Data Protection Policy Reviews Completed (%)Guidance & review notesTarget set to 100% of all policies reviewed annually. Record percentage as reviews are undertaken. | At least | Not recorded | ||
Third-Party Processor Risk Assessments Completed (%)Guidance & review notesTarget set to 100% of all third party processors. Record percentage as assessments are undertaken. | At least | Not recorded | ||
High Risk ProcessorsGuidance & review notesTarget should be minimal, suggest no more than 4. Record number as and when identified. | At most | Not recorded | Monitor through the relevant register or review | |
Article 28 Agreements - Data Sharing (%)Guidance & review notesTarget should be 100%. Record percentage based upon those completed during the period. | At least | Not recorded | ||
Mandatory Training Completion (%)Guidance & review notesTarget should be 100%. Record percentage based upon those completed during the period. | At least | Not recorded | ||
Phishing Failure Rate (%)Guidance & review notesTarget should be less than 5%. Record as and when phishing tests are completed. | At most | Not recorded | Monitor through the relevant register or review | |
Information Security IncidentsGuidance & review notesTarget is flexible but base it on no more than five in a 12 month period. Record as and when they occur. | At most | Not recorded | Monitor through the relevant register or review | |
Records Past Retention DateGuidance & review notesReview this measure with the appointed DPO. | At most | Not recorded | Monitor through the relevant register or review | |
Privacy Notices Reviewed (%)Guidance & review notesTarget 100% of all Privacy Policies or Notices reviewed within a 12 month period. Record status. | At least | Not recorded | ||
RoPA Review Completion (%)Guidance & review notesTarget 100% completion of the ROPA review per 12 month period. Assess status and record. | At least | Not recorded | ||
AI Systems Assessed (%)Guidance & review notesTarget all systems (100%) to have a risk assessment. Record any deviation. | At least | Not recorded | ||
Internal Audits CompletedGuidance & review notesTarget one internal audit per year. | At least | Not recorded | ||
Internal Audit Partial or Non-Compliance RecommendationsGuidance & review notesTarget no more than five areas of partial or non-compliance findings from the internal audit. | At most | Not recorded | Monitor through the relevant register or review | |
Data Transfers Outside of the UK and EUGuidance & review notesTarget no more than five transfers outside of the UK, EU or appointed adequate countries. Record existing status and any changes. | At most | Not recorded | Monitor through the relevant register or review | |
Transfer Risk Assessments Completed (%)Guidance & review notesTarget 100% of the required transfer risk assessments to be completed, record where there are noted outstanding requirements. | At least | Not recorded | ||
Risk Log in PlaceGuidance & review notesTarget the completion of the risk log. | At least | Not recorded | ||
Data Protection Risk Log ReviewsGuidance & review notesTarget at least a quarterly review of the risks so 4. Update accordingly. | At least | Not recorded | ||
Data Protection Risk Closures (%)Guidance & review notesTarget 25% of all risks to be closed during the 12 month period. Update as risks are closed. | At least | Not recorded | Monitor through the relevant register or review | |
Data Protection Residual High Risks (%)Guidance & review notesTarget a maximum of 10% of residual risks to be classified as High or Critical | At most | Not recorded | Monitor through the relevant register or review |
DPO client record
Organisation
- Organisation name
- Example Organisation Ltd
- Address
- Not recorded
- Service level
- Enhanced
- Appointed DPO
- George Harris
- Deputy DPO
- Hayley Harris
Client contacts
- Main contact
- Not recorded
- Main contact email
- Not recorded
- Main contact mobile
- Not recorded
- Deputy contact
- Not recorded
- Deputy contact email
- Not recorded
- Deputy contact phone
- Not recorded
ICO registration
- ICO registration number
- Not recorded
- ICO registration expiry date
- Not recorded
Finance
- Method of payment
- Not recorded
- Main finance contact
- Not recorded
- Main finance email
- Not recorded
Data subject access register
Record the request and coordinate the response with your DPO. Use a reference rather than sensitive personal details in this preview.
| Reference | Received | Owner | Status | Reviewed deadline |
|---|
No requests recorded.