29 April, 2024
We are pleased to announce two new updates as part of this release:
- Users now have the ability to link vendors directly with DPIAs, RoP, and RoPA records through the Vendor Assessment. This enhancement streamlines vendor relationship management by connecting vendors with critical processing and privacy assessments, ensuring a more cohesive approach to data protection and compliance.
- Additionally, several new incident cards have been introduced to the Incident Dashboard, improving visibility into how incidents are identified and managed across different data types, systems, and organisational roles. These cards offer deeper insights into incident trends, highlighting their connections to processing activities, data subjects, and impacted systems.
Linking a vendor assessment to a data protection impact assessment (DPIA), record of processing area (RoP), or record of processing activity (RoPA)
- It is now possible to link a vendor to a DPIA, RoP, or RoPA through Vendor Assessment. To create this link, users must use the options available via the vendor log.
- Clicking any of these buttons opens a popup where users can select the relevant RoP, RoPA, or DPIA from a dropdown.
- Please note processing areas, activities, or DPIAs marked as Closed will not appear in the dropdown.
- Once a relevant item is selected and the user clicks Save, users are presented with a toaster notification:
-
The DPIA has been linked.
-
The RoP has been linked.
-
The RoPA has been linked.
-
The DPIA has been linked.
- Three new columns have been added to the Vendor Assessment log, labelled Linked RoPs, Linked RoPAs, and Linked DPIAs. The linked data will be displayed in these columns on the vendor log page.
- Users can click on the counts to view the reference number and title of each linked item.
- Users can also link a Vendor Assessment to a Record of Processing Area (RoP), Record of Processing Activity (RoPA), or DPIA via Vendor Details, as three new fields have been added.
Note: If a user does not hold a contract for DPIA, RoP, or RoPA, the option to link these items will appear greyed out.
DeleteAdditional cards added to the incident dashboard
Incidents by Identification
- Data pulled from the Background tab in the Incident form.
- Question: How was the incident identified?
Incidents by Data Subjects
- Data pulled from the Investigation tab in the Incident form.
- Question: Who are the data subjects?
Incidents by Personal Data
- Data pulled from the Investigation tab in the Incident form.
- Question: Personal Data
Incidents by Special Category Data
- Data pulled from the Investigation tab in the Incident form.
- Question: Special Category Data
Open Incidents by Processing Activities
- Data pulled from the Investigation tab in the Incident form.
- Question: Does the organisation’s record of processing include a processing activity related to this incident?
Open Incidents by Affected System Type
- Data pulled from the S&S Investigation tab in the Incident form.
- Question: Detail the type of system that has been affected
Open Incidents by Impacted System Type
- Data pulled from the S&S Investigation tab in the Incident form.
- Question: How was the system affected?
Open Incidents by Organisation Role
- Data pulled from the Investigation tab in the Incident form.
- Question: In reference to this incident, is your organisation a controller or processor?