A typical activity to examine
A development team receives a client database extract for troubleshooting and shares access with a specialist contractor.
Questions for the responsible team
Use these prompts to describe your own operation. They are examples, not a finding about your organisation.
- Is real personal data needed, or could the task use synthetic or reduced information?
- Who approves access, copying and use outside the original task?
- How are client instructions, contractor access and deletion confirmed at handover?
A useful first work package
Define a project information-handling checklist, review the subcontractor and environment boundaries, and test the exit process.
Ownership and scope
Delivery managers, engineering, security and commercial owners supply the instructions and make implementation decisions. A privacy review does not certify the software or replace the customer’s own obligations and approvals.
Common questions
Does this industry label determine our legal obligations?
No. The activities, people, roles, geography and applicable sector requirements need review.
What should we bring to an initial discussion?
Describe one important activity, the teams and providers involved, the records already available and the question you need to resolve. Use examples with unnecessary personal details removed.
Discuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Industry examples