Internal audit: useful when nobody is defending a number
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
A data protection impact assessment is required before high-risk processing starts, not after. The triggers, the sections, and what makes a DPIA defensible.
A data protection impact assessment — a DPIA — is a written analysis of a proposed use of personal data: what you intend to do, why it is necessary, what could go wrong for the people whose data it is, and what you will do to reduce that. Under the GDPR and equivalent regimes it is mandatory before certain kinds of processing begin, and that timing is the part companies get wrong. A DPIA written after launch is not a DPIA; it is a description of a decision already taken.
The point of the exercise is that it can change the plan. An assessment that concludes every proposal is acceptable with no modification has not been done properly, and that pattern is visible across a set of them. If nothing was ever narrowed, shortened, or dropped as a result, the process is decorative.
Ettex Records holds each assessment as a dated record against the processing it covers, with the residual risks and the review trigger as fields rather than paragraphs buried on page nine. That matters because the question that arrives later is never "show me the DPIA" alone — it is "which of these did you accept, and who signed". Ettex does not assess risk, is not a data protection officer, and the thresholds differ by jurisdiction and by regulator guidance; check the rules that apply to you rather than the general description here.
No. It is required for high-risk processing, and a short screening note recording why a full assessment was not needed is the right output for everything else. That screening record is itself worth keeping.
Whoever can accept the residual risk on behalf of the organisation, having taken the data protection officer’s advice where one exists. If the officer disagreed, record the disagreement — overruling advice is permitted, hiding it is not.
There is usually no obligation, and most organisations publish a summary rather than the full document. Publishing something is a strong signal of confidence, and in public-sector contexts it is increasingly expected.
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
Succession planning is a list of roles you cannot afford to lose and what happens if you do. How to build one small enough to maintain and honest enough to use.
A supplier code of conduct sets what you require of the people you buy from. What to include, how to make it enforceable, and why long codes get signed and ignored.