Data protection impact assessment: when you need one and what it must show
A data protection impact assessment is required before high-risk processing starts, not after. The triggers, the sections, and what makes a DPIA defensible.
A lone working policy covers people who work without direct supervision. What to assess, what check-in actually works, and the failure mode nobody plans for.
A lone working policy covers anyone who works without close or direct supervision — a care worker visiting homes, an engineer on a client site, a shop assistant closing alone, a researcher in a building at ten at night. Lone working is not illegal anywhere and rarely needs to be prohibited. What it needs is a decision, written down, about which tasks are acceptable alone, what happens if the person does not report back, and who is going to notice.
The failure nobody plans for is the end of the day, not the middle. A worker who finishes a final visit at six and drives home has left the arrangement, and if the check-out step does not exist, nobody discovers a problem until the next morning. Most lone-working systems have a start and no end.
Ettex Records keeps the lone working register as dated records — who is out, where, expected back when, checked in at what time — so an overdue check-in is a visible state rather than something a colleague has to remember to wonder about. The written policy belongs with the health and safety policy it sits under. Ettex is not a lone-worker alarm system: there is no panic button, no automated escalation and no location tracking, and where the risk warrants those, buy a dedicated device. What this replaces is the whiteboard nobody updated and the text message nobody read.
You can, and for genuinely high-risk tasks you should. As a blanket rule it usually fails: people work alone anyway because the job requires it, and now they do so outside a system rather than inside one.
For low-risk lone working with reliable signal, often yes, provided someone is actually expecting the call and knows what to do if it does not come. The phone is not the control; the person waiting for it is.
Home workers are lone workers, though the risk profile is different — display screen setup, isolation and the difficulty of noticing a problem matter more than physical danger. A short, separate section usually covers it better than forcing them into the field-visit arrangement.
A data protection impact assessment is required before high-risk processing starts, not after. The triggers, the sections, and what makes a DPIA defensible.
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
Succession planning is a list of roles you cannot afford to lose and what happens if you do. How to build one small enough to maintain and honest enough to use.