Viewee
Start free
Pricing
Sign in
← Legal and assurance

Requirements

RequirementWhat it means for VieweeOwner (Instinct / Alex+Cain / External assessor)EffortStatusEvidence neededSource URL
Map controller/processor roles by processing activityViewee is likely processor for care-provider tenant feedback and controller for its own leads, customer contacts, staff and service analytics. Confirm role per purpose rather than for the company as a whole.Alex+CainHDo nowRole/data-flow map and contract positionhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/
Data protection principles and accountabilityProcess lawfully, fairly and transparently; limit purpose and data; keep accurate; retain no longer than needed; secure it; be able to demonstrate compliance.Alex+CainHDo now and ongoingPolicies, ROPA, decisions, audits and control evidencehttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
Records of processing activities (Article 30)Maintain electronic controller and processor records covering contacts, purposes, categories, recipients, transfers, retention and security measures; record lawful basis and special-category condition.InstinctHDo now; update before launchROPA with controller and processor tabs, version/review recordhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/documentation/
Choose and document lawful basisFor each Viewee-controlled purpose choose an Article 6 basis before processing. Do not default to consent; document legitimate-interest assessments where relied on. Customers determine bases for tenant processing, supported contractually by Viewee.Alex+CainHDo nowLawful-basis register, LIAs/consent records as applicablehttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/
Special-category data and DPA 2018 conditionFeedback may reveal health, disability, ethnicity, religion, sexuality or other special-category data. Identify an Article 9 condition and, where required, a DPA 2018 Schedule 1 condition and appropriate policy document.Alex+CainHBefore real feedback dataSpecial-category assessment, condition record, appropriate policy documenthttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/special-category-data/
Complete DPIA before high-risk processingScreen every major processing operation. A DPIA is mandatory where processing is likely high risk; resident health/vulnerability data, monitoring/profiling, large-scale special-category data or novel AI may trigger it. Consult ICO before processing if high residual risk cannot be reduced.Alex+CainHDo now, before design locksDPIA with necessity/proportionality, risks, controls, consultation and approvalhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/
Privacy by design and defaultBuild minimisation, role access, tenant isolation, restricted defaults, pseudonymisation, retention/deletion and auditable support access into product and outreach admin.Alex+CainHDuring build before launchDesign decisions, threat model, acceptance tests, configuration defaultshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-by-design-and-default/
Transparent privacy informationGive concise, accessible notices at collection covering identity, purposes, bases, recipients, transfers, retention, rights, complaints and automated decisions. Separate/clear notices may be needed for site visitors, prospects and product users.InstinctMBefore data collection/launchPublished privacy notices and version/change loghttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/
Controller-processor contracts (Article 28)Customer DPA must state subject/duration, nature/purpose, data types/categories and controller rights; processor clauses must cover instructions, confidentiality, security, subprocessors, rights assistance, breach/DPIA help, deletion/return and audits.Alex+CainHBefore pilot/customer dataSigned DPA/order terms, instruction record, audit/assistance processhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/
Subprocessor governanceObtain prior specific/general written authorisation, notify changes and flow equivalent Article 28 obligations to each subprocessor; remain liable to customer for subprocessor performance.Alex+CainHBefore vendors process personal dataSubprocessor register, notices/approvals, vendor DPAs and review evidencehttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/
International transfer controlsMap every access/storage/support transfer outside the UK. Use adequacy regulations or an appropriate safeguard such as IDTA/Addendum plus transfer risk assessment and supplementary measures where required.Alex+CainHBefore vendor selection/launchTransfer register, SCC/IDTA/Addendum, TRA and vendor location evidencehttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/
Appropriate technical and organisational securityUse measures appropriate to risk, including access control/MFA, encryption, availability/resilience, backup/restore, logging, vulnerability management, incident response and regular testing/evaluation.Alex+CainHBuild now; prove when liveSecurity architecture, policies, scans/pen test, restore test, access/log reviewshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/
Personal data breach processDetect, triage and document every breach. Controllers notify ICO without undue delay and where feasible within 72 hours unless unlikely to risk people; notify affected people without undue delay for high risk. Processors notify controllers without undue delay.Alex+CainHBefore real personal dataIncident/breach plan, breach log, decision template, tabletop exercisehttps://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
Data subject rights operating processSupport access, rectification, erasure, restriction, portability, objection and automated-decision rights. Verify identity, log deadlines, search/export/delete accurately, and assist customer controllers for tenant requests.Alex+CainHDesign now; test before launchRights procedure, request log, tested export/correction/deletion workflowshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/
Retention and secure deletionSet purpose-specific retention periods for feedback, audit logs, backups, outreach data and support records; implement deletion/anonymisation and deal with backups.Alex+CainHDo now; automate before launchRetention schedule, deletion design/tests and disposal logshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/documentation/
Data quality and minimisationCollect only data needed, prevent unnecessary free text where possible, let customers correct data and avoid copying live personal data into development/test.Alex+CainMDuring designField-level data specification, validation, test-data policy and reviewshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
DPO assessment and UK representative checkDocument whether a DPO is legally required (eg large-scale regular monitoring or large-scale special-category processing). UK-established Viewee does not need a UK representative for that establishment, but reassess expansion.Alex+CainMDo now; revisit at scaleDPO decision record and review triggerhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-officers/
ICO data protection feeUse ICO self-assessment and register/pay unless exempt; keep details current and renew.Alex+CainLDo nowICO registration/fee outcome and renewal recordhttps://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/
Vendor due diligence and ongoing assuranceAssess cloud, analytics, email/outreach, AI and support vendors for role, location, security, retention, training use, incident terms, deletion and audit evidence before sharing data.Alex+CainHBefore vendor commitmentDue diligence questionnaire, risk decision, contract and annual reviewhttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
Children/vulnerable adults and accessibility risk reviewResidents are vulnerable adults and feedback may concern people lacking capacity. Although UK GDPR has no separate vulnerable-adult regime equivalent to children, fairness, accessibility and risk controls must reflect the audience.Alex+CainMDuring designUser research, accessible notices/consent support, safeguarding escalation boundarieshttps://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/