01 Bounded operating templates
Structure the work. Keep the evidence elsewhere.
Six field structures for designing and reviewing internal workflows. They are not prescribed forms, legal advice or a substitute for an approved case, incident or evidence system.
02 Choose the operating moment
Six records that connect decisions to systems.
Open a template to inspect its recommended fields, evidence boundary and source mapping. Start with the gap surfaced by the readiness assessment.
01Product owner + Legal / PrivacyNotice surface record
Connect a collection moment to the exact notice, fields, purpose, choice and destinations a person encountered.
Notice surface record
Connect a collection moment to the exact notice, fields, purpose, choice and destinations a person encountered.
Before launch, after a field or purpose change, and during a periodic collection-surface review.
- 01Surface + journey
URL, app screen, offline step, audience, language and trigger.
- 02Notice version
Version ID, approved copy, display date and evidence of what was rendered.
- 03Data + purpose
Each collected field, whether required, and the specific purpose it supports.
- 04Choice state
Legal route assessed, affirmative action if consent is relied on, and withdrawal path.
- 05Destinations
Systems, teams, integrations and service providers that receive the data.
- 06Test + review
Keyboard/language test, finding, accountable approver and next review event.
Do not paste personal data or live credentials into this record. Link to redacted evidence in an approved internal location.
02Operations + IT / Security + Legal / PrivacyProcessor and service register
Keep the contract, role assessment and live technical relationship for each service on one reviewable record.
Processor and service register
Keep the contract, role assessment and live technical relationship for each service on one reviewable record.
At procurement, renewal, integration change, incident, rights exercise and service exit.
- 01Service + owner
Service, internal business owner, purpose and personal-data categories.
- 02Role assessment
Fact-specific role conclusion, assumptions and decision owner.
- 03Contract record
Agreement/DPA version, instruction and safeguard references, renewal date.
- 04Architecture
Regions, remote support, sub-services, integrations and privileged roles.
- 05Lifecycle
Retention event, delete/export behaviour, backup residual and exit method.
- 06Evidence + gaps
Latest review, test result, unresolved question, owner and due event.
A vendor label does not determine the legal role. Verify what the parties decide and do in the real arrangement.
03Operations + Product / EngineeringRetention-by-event schedule
Translate a lifecycle decision into start events, end events, exceptions and system actions engineers can test.
Retention-by-event schedule
Translate a lifecycle decision into start events, end events, exceptions and system actions engineers can test.
When a dataset, purpose or system is introduced, changed or prepared for deletion automation.
- 01Record class
Dataset, system, purpose, accountable owner and sensitivity.
- 02Start event
Observable event that starts the clock and system-of-record timestamp.
- 03End event
Duration or condition, with its decision basis and approving role.
- 04Exception
Hold reason, authoriser, scope and next review date.
- 05System action
Delete, anonymise or restrict across primary, replica, export and backup copies.
- 06Proof of outcome
Synthetic test, run log, failure queue, residual search and sign-off.
This is not a universal retention schedule. Sectoral, contractual and other applicable requirements need separate review.
04Legal / Privacy + OperationsRights request operating record
Give a request a bounded intake, verification, search, decision, action and response trail.
Rights request operating record
Give a request a bounded intake, verification, search, decision, action and response trail.
When designing or exercising the workflow; use only an approved, access-controlled case system for real requests.
- 01Request channel
Published route, received timestamp, request type and acknowledgement.
- 02Proportionate verification
Checks used, why they were necessary and how excess copies are avoided.
- 03Search plan
Systems, service providers, owners, identifiers and residual locations.
- 04Decision record
Action, exception or limitation, evidence considered and accountable approver.
- 05Execution
Correction/export/erasure steps, failures, processor follow-up and validation.
- 06Response + closure
Response date, secure delivery, grievance route and lessons for the next exercise.
Never use this public preview to record a real identity, request or case detail. It has no submission or storage function.
05IT / Security + Legal / Privacy + OperationsBreach evidence timeline
Separate signals, awareness, known facts, affected-person communication, Board updates and recurrence work.
Breach evidence timeline
Separate signals, awareness, known facts, affected-person communication, Board updates and recurrence work.
During tabletop exercises and within the organisation’s approved incident system for a real event.
- 01Signal log
Alert, reporter/provider, received time, handler and preserved source.
- 02Awareness decision
Decision time, criteria, decision-maker, uncertainty and rationale.
- 03Known-facts register
Confirmed, suspected, unknown, source and last-updated timestamp.
- 04Communication tracks
Affected-person and Board content, approvals, send evidence and corrections.
- 05Measures
Containment, recovery, evidence preservation and provider actions.
- 06Recurrence record
Root factors, remediation owner, test, residual risk and closure review.
Rule 7’s timing sequence requires fact-specific legal and incident judgement. A template cannot determine awareness or notification duties.
06Founder + control ownersEvidence pack index
Track where current, redacted proof lives without centralising sensitive artefacts in another uncontrolled copy.
Evidence pack index
Track where current, redacted proof lives without centralising sensitive artefacts in another uncontrolled copy.
For a readiness review, tabletop, audit preparation or control-owner handover.
- 01Control + claim
What the evidence is meant to show and which control it supports.
- 02Artefact reference
Approved location, file/version identifier and sensitivity classification.
- 03Owner + reviewer
Person accountable for freshness and person who challenged it.
- 04Coverage
System, population, time window and known exclusions.
- 05Test result
Procedure, date, outcome, sample and unresolved finding.
- 06Lifecycle
Review event, superseded-record handling and authorised access.
An index aids retrieval; it does not prove that evidence is accurate, complete or legally sufficient.
03 Safe use sequence
Draft, challenge, test, then govern.
- 01
Draft with synthetic dataClarify the fields and owner before touching a live record.
- 02
Challenge the assumptionsReview role, purpose, exception and system coverage.
- 03
Exercise the workflowTest retrieval, failure handling and residual copies.
- 04
Move into an approved systemApply access, retention, audit and review controls.
04 Start from evidence
Not sure which record comes first?
Answer ten bounded questions using evidenced, partial, unknown or gap. The result recommends work; it does not grade legal compliance.