Why is the record collected?
Name the business purpose, the fields truly needed, who approved the purpose, and how a change in use will be handled.
Data-route worksheet
A privacy-aware implementation begins by mapping why information exists, where it enters, who can use it, where it travels, how it changes, and when it should leave.
Route the record
The PDPC describes data-protection obligations and organisational accountability. This worksheet turns those topics into implementation questions; it does not determine what the law requires for a specific organisation.
Name the business purpose, the fields truly needed, who approved the purpose, and how a change in use will be handled.
List forms, imports, APIs, staff entry, partner delivery, and automated capture. Separate required fields from convenient ones.
Define roles, approval boundaries, privileged access, support access, account removal, and a review cadence.
Choose the authoritative source, correction flow, duplicate rule, audit history, and downstream reconciliation process.
Map vendors, processors, integrations, exports, backups, geographic handling, and the controls the client needs reviewed.
Translate the client's retention decisions into archive, deletion, backup-expiry, and exception behaviour.
Name detection, containment, evidence preservation, escalation, decision ownership, communication, and restoration steps.
Implementation handoff
The client should bring its decisions and adviser guidance. Faith Forge Labs can then express them as access rules, system behaviour, logs, operational cues, test cases, and handoff documentation.
| Owner question | Technical expression | Acceptance evidence |
|---|---|---|
| Who may act? | Roles, permissions, session and account lifecycle | Allowed and denied cases pass |
| Which system is authoritative? | Field contract, update direction, conflict policy | Corrections reconcile across the mapped flow |
| What must be retained? | Lifecycle, archive, deletion, backup boundary | Timed and exception cases behave as approved |
| How are incidents handled? | Logs, alerts, evidence, escalation runbook | A controlled scenario reaches the right owner |