Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

01 Operating guide · service relationships

Build a processor and service register that people can maintain.

A useful register connects a business purpose to the services, contracts, access paths and owners that can act on personal data. Role assessments remain fact- and contract-dependent.

Editorial recordReviewed 20 August 2026Not counsel reviewed
01

Start with twelve fields

  • Service and internal owner
  • Business purpose
  • Personal-data categories
  • Fact-specific role assessment
  • Contract and instruction reference
  • Primary hosting and remote-access locations
  • Sub-processors or connected services
  • Privileged roles
  • Retention and deletion event
  • Export and backup behaviour
  • Exit owner and steps
  • Last review and next review
02

Reconcile against reality

Compare the register with accounts payable, single sign-on applications, browser extensions, integration lists and team spreadsheets. A vendor missing from the register is a discovery question—not an automatic legal conclusion.

03

Review at operating events

  • Before procurement or material configuration change
  • When a new integration or sub-processor appears
  • When data categories, purpose, access or location changes
  • At contract renewal and service exit
  • After a rights request, incident or deletion exercise exposes a gap
04

Evidence to save

Save the current register version, accountable review, contract reference, configuration result and unresolved question. Link to controlled evidence rather than copying sensitive records into the register.

Map common software systems