Records of Processing

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

Welcome to the Records of Processing User Guide. Records of processing are needed for maintaining transparency and ensuring compliance with data protection laws and regulations. These records provide a comprehensive inventory of all data processing activities within your organisation, detailing the nature of the data processed, its purpose, the categories of data subjects affected, and any data transfers, particularly international ones. Maintaining an accurate account of these activities is crucial not only for demonstrating compliance with regulatory authorities but also for identifying and mitigating potential risks related to data handling.

The 9ine Platform enables you to systematically organise your records of processing areas and document all related activities through guided forms. It also allows for the integration of any associated risks, issues, lessons, or tasks via 9ine’s Governance Platform, enhancing your data governance practices.

By keeping thorough records, your organisation can better safeguard individual privacy and evidence effective data governance.

Access to Records of Processing (area and activity) is included as part of 9ine’s Privacy Platform licence. For further information contact [email protected]. 

Accessing records of processing (area and activity)

Upon purchasing 9ine’s Privacy Platform and its associated features, users can be granted access to Records of Processing and Records of Processing Activity. Your organisation’s administrator(s) have the option to allocate permission via  User Management, available to administrators in the header.

Records of Processing: Granting access to this feature allows users to create new processing areas but does not automatically grant access to all existing processing areas. Users need to be assigned as owners or members of specific processing areas to gain edit access to those areas and their associated processing activities. A record of processing’s (area) permissions include:

  • Owner
  • Member(s)

Records of Processing Activities: Similarly, access to this feature does not automatically grant rights to view or edit all processing activities. Users must be specifically added as data owners, members, reviewers, attachment reviewers, or notified users for individual activities to gain edit permissions. A record of processing activities permissions include:

  • Owner
  • Member(s)
  • Reviewers
  • Attachment reviewers
  • Notified users 

In addition, any owners, members, notified users, or attachment reviewers of any risks, issues, lessons or tasks are also granted edit access to the record of processing activity but they do not gain access to the record of processing area and the other activities within the area. 

Tip:

For user convenience and when applicable, a user can also be designated as a record of processing area owner or member, granting them access to all activities within that area. 

 

There can only be a single owner of a processing area and activity, but there are no limits to the number of members or notified users. Each attachment and processing activity can also have one reviewer.  Owners can edit and delete their assigned items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.

Warning:

If a DPIA is linked to a record of processing activity, users with access to the DPIA are automatically granted access to the related processing activity. However, their permissions are restricted to viewing and editing only the specific activity linked to the DPIA.

 
 
 

Adding and removing notified users

Adding removing notified users forms

To add a notified user, use the mention function in the “Additional Notes” featur...

To add a notified user, use the mention function in the Additional Notes feature.

  • To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention. 
  • A user can be mentioned at the start, in the middle, or at the end of the entered text. 
  • To remove a user as a notified user, simply delete their name from the relevant note. 
  • Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications. 
  • The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.

 

 
 

Understanding how to create a record of processing area

Begin by clicking New Processing Area, to get started. You will then be presented with a popup which displays four fields:

  • Title
  • Owner
  • Member(s)
  • Next Review Date

Three of the four fields are mandatory when creating a new record of processing area including: title, owner, and next review date. The 9ine Platform automatically sets the next review date to 12 months from today but this can be adjusted based on your individual preferences. 

Calendar Field

When selecting a date, you can manually type in the specified format or click on ...

When selecting a date, you can manually type in the specified format or click on the date in the header to quickly navigate through months or years. The clear button allows you to easily remove any entered date. 

When the date entered in either of the date field lapses, a warning message is displayed. Similarly, lapsed dates are shown in red on the moduleName log.

On entering the required fields, you have three options:

  • Save & Close: Saves the information, creates the area, and returns you to the record of processing log.
  • Save & Create Process: Saves the information, creates the area, and opens a new popup with two additional fields (detailed below).
  • Save & Quickstart Your Process: Saves the information, creates the area, and directs you to the Quickstart workflow (further described below).

Save & Create Process

On clicking Save & Create Process you are presented with two further fields which include the title of processing activity and purpose of processing activity. You then have the option to:

  • Save & Close which saves the processing activity and navigates you back to the area log.
  • Save & Add Another which saves the processing activity but allows you to create another in the area.
  • Save & Add Details which saves the processing activity and navigates you into the full form assessment.
 
 

Quickstart your record of processing activity

Upon selecting the Save & Quickstart Your Process option, you will be redirected to a popup organised by processing areas (departments). The 9ine Platform offers ninety-eight template processing activities split across thirteen processing areas specifically tailored for schools, enabling you to effectively build from a structured foundation.

Upon selecting the relevant processing areas and clicking Next, each area will be displayed at the top in a tabular format. 

Next, select the processing activities you wish to initiate using the Quickstart feature and click Populate. This action will add all selected activities to the relevant department. Activities that have been initiated via the Quickstart feature will be easily identifiable by a distinct icon in the first column. Upon editing and saving a Quickstart assessment, the icon will automatically be removed.

 
 

Creating a new record of processing activity or editing an existing one (including a Quickstart form)

When creating a new record of processing activity from scratch or via the Quickstart workflow or editing an existing activity, you will be navigated to the form and presented with four headers, including:

  • Processing Overview
  • Processing Description
  • Processing Risk
  • Processing Review

To efficiently move through the four steps, you can use the clickable navigation tabs when there are no unsaved changes on the form. However, after making changes, you must navigate using the primary buttons located at the bottom of the page.

The title of the processing activity is consistently displayed at the top of the form, and to the right, a unique reference number is provided. This number is prefixed with RoPA and followed by a unique identifier that cannot be edited. 

Third parties such as data processors will be identified during the discovery phase of populating your organisation’s records of processing. These third parties will often be software vendors or suppliers where there is a transfer of personal data from the organisation to the third party. On the Processing Operation Assessment (Vendor) log, the quick actions menu offers an option to link a Vendor to a record of processing area or activity. Once linked, the details are reflected on both the Vendor log and the respective record of processing activity form.

In the Record of Processing Activity (RoPA) form, users can add a retention by clicking Add Retention or link an existing retention from the dropdown list on the Processing Overview step.

Similarly, through the creation of your organisation’s records of processing, you will carry out a processing risk assessment on step three. As a general rule:

  • Where there are more than two risks identified a DPIA should be considered for completion. 
  • Where there are more than four risks, steps should be taken to create a DPIA and complete the DPIA screening process. 
  • Where an organisation processes a large amount of personal data related to vulnerable data subjects, such as children, a DPIA screening is almost always going to be recommended for each processing activity. 

To mitigate this risk, organisations like schools should create DPIA specifically to offset this risk and in doing so, reduce the weight given to the selection of ‘Vulnerable data subjects’ within the screening process.

Tip:

Tooltips are available throughout the processing risk assessment to guide and support your decision-making process, providing helpful insights and additional context for a more informed and accurate assessment. Similarly, higher processing risks are automatically flagged, helping you quickly identify areas that require additional attention.

 

When a DPIA and RoPA are linked through the DPIA screening process (via the Processing Activity field), or by clicking Save & Begin DPIA on step four of the record of processing activity form, duplicate questions are automatically populated and updated to prevent re-entering the same information.

For example, the DPIA screening step clearly indicates, Any changes made here will also reflect in the associated processing activity.

Tip:

To quickly identify the details of a linked vendor or DPIA, refer to the record of processing activity log.

 
 
 

Selecting data subjects and the associated personal and special category data

Selecting data subjects and the associated personal and special category data

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Proc...

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Processing Operation Assessment, and Incident Management), you can select data subjects along with their associated personal and special category data. On selecting a data subject, their details appear in a pill below the question for easy reference.

Tip:

If a data subject type is not available in the Platform’s default list, you can add it using the +Other function. Any data subjects added this way will be accessible to all users in your organisation for future use.

 

Each data subject appears in the popup when you click Select Personal Data or Select Special Category Data.

When a user adds any Personal Data or Special Category Data in the corresponding pop-up, a Copy To All button becomes visible. This button allows the user to copy the selected data option to all applicable entries, ensuring consistency and efficiency across the forms.

The secondary number displayed in the Answered pill represents the total number of selected data subjects. For example, if one data subject was initially selected and an additional two were chosen, the count would change from 1 to 3.

 

 
 

Creating an associated risk, issue, lesson, or task (Summary of Activities)

Create associated risk

In the top right-hand corner there is a +New button which provides four options: ...

In the top right corner there is a +New button which provides four options: New Risk, New Issue, New Lesson, and New Task.  

For more detailed information on the specific logs, please refer to their individual user guides:

When creating a risk, issue, lesson, or task the details are automatically added to the Summary of Activities table.

 
 

Utilising the additional notes and attachments features

Utilising the additional notes and attachments features

The “Additional Notes” feature allows you to maintain a single repository of info...

The Additional Notes feature allows you to maintain a single repository of information related to a moduleName. You can add multiple notes at once using the Save Note function. These notes are saved without the need to click the primary Save at the bottom of the page.

When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated.

Tip:

Individual notes can only be edited or deleted by the user who originally created the note. However, users have the option to add comments to notes created by others.

 

Additional formatting functionality is provided in the additional notes feature. If entering large volumes of data, click the Full Screen or Expand Popup options.

Warning:

  • For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity. 
  • If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled. 
  • Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.
 

The Attachments feature allows you to upload files or images using your native file explorer. You can upload up to five attachments at once. 

  • Maximum file size: 10MB
  • A maximum of five files can be uploaded at a time
  • Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
  • The file name cannot contain special characters :/?<>|"\ #+&'~

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete.

 
 

Understanding how to use the record of processing area and activity logs

When creating a new record of processing area or activity, or editing an existing one, the details entered are added to the respective log. Each area and activity are automatically assigned a unique reference number (starting with ROP and ROPA) that cannot be edited.

To view only the areas you are responsible for, use the My Areas toggle in the top right-hand corner of the area log. This will filter and display items where you are the owner or member. A similar My Activities toggle is available on the record of processing activity page. This will filter and display items where you are the owner, member, notified user, or approver.

Understanding how to use the log (forms)

Default sorting is applied to the Ref No., which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order. 

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View.

You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login. 

Tip:

  • The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile.
  • The sequence order in the View popup does not update to reflect the order created through your dragging and dropping actions.
 

To focus on a specific moudueName, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition. 

  • To quickly clear any filters, click the Clear Filters button in the popup. 
  • You can also apply a temporary filter without clicking Save Filter.
  • To revert back to your saved filter, click Reset.
  • Similarly, you can select data points and click Apply
  • Without saving your filter options.
 

Moving a record of processing activity to a different area

To move a record of processing activity to a different area in the 9ine Platform, you must either have the relevant permissions or submit a request for approval if you lack them. If you have the necessary permissions (i.e., you are the owner or a member of the area the activity is being moved to), you can move the record directly.

If you do not have these permissions, you will see a Request button. The owners of the new area will receive an in-Platform notification to approve or reject the request. While the record of processing activity is in the move state, editing and quick functions for that activity will be disabled.

 
 

Downloading records of processing

Downloading Forms

To download a moduleName(s) and its activities click the Download button located in the top right-hand corner of the moduleName log. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My moduleName functions.  Upon clicking Download, the export is processed in the background. Once complete, you will receive both an in-platform notification and an email notification. The exported file is provided in XLS format.

On the moduleName log, You have three download options available:

  • Log - Downloads in XLS format.
  • Advanced - Downloads in XLS format.
  • Form (available in the quick actions menu) - Downloads in DOCX format.
 
 

Understanding the quick actions for a record of processing area

The record of processing area log provides a range of quick-access functions within the menu options, including:

  • Create Process - This allows you to directly create a new processing activity associated with the area.
  • Quickstart Process - Opens the Quickstart feature.
  • Add Member(s) - Opens a members popup to quickly grant users access to the processing area.
  • Close - Marks a record of processing area and all its associated processing activities, risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen
    Marks a closed processing area as Open and restores all associated items. Related activities are returned to Open status. Associated tasks are returned to Not Started, while linked risks, issues and lessons are returned to Open status.
  • Delete - Marks a record of processing area and all its associated processing activities, risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.

 
 

Understanding the quick actions for a record of processing activity

The record of processing activity log provides a range of quick-access functions within the menu options, including:

  • Add Note - Opens the processing activity form directly on the Additional Notes feature. 
  • Add Member(s) - Opens a members popup to quickly grant users access to the processing activity.
  • Move - Allows the user to move a processing activity from one area to another.
  • Duplicate - Duplicates the processing activity and all associated risks, issues, lessons, and tasks labelling them with the prefix Copy of. The duplicated items do not include notes, attachments, logged time and logged cost data.
  • Download - Downloads the record of processing activity form in a DOCX format.
  • Close - Marks a record of processing activity and all its associated risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen
    Marks a closed processing activity, Open and restores all associated items. Related tasks are returned to Not Started, while associated risks, issues and lessons are returned to Open status.
  • Delete - Marks a record of processing activity and all its associated risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.