Frequently Asked Questions (FAQs)

FAQs:
Expand All

Global Common FAQs

How do I identify what a reference number relates to? Reference numbers on the 9i...

How are the numbers in a reference number allocated after the prefix? Platform-Wide

All numbers following the prefix are unique within the 9ine Platform. They are automatically generated and cannot be modified.

 
 

If a user's account is deleted and they later re-joins the 9ine Platform, do they receive the same user reference number? Platform-Wide

Yes, each email address is allocated a unique identifier that is retained if the email address is reinvited to the 9ine Platform. If a user re-joins with a new email address, they will receive a new user reference number.

 
 

How can I change my password? Platform-Wide

If you have enabled Single Sign-On (SSO) with Google or Microsoft, your account credentials will be managed by their authentication services, and your previous password will not be used for logging into the Platform. To change your password, there are three available options:

  • On the Login page (app.9ine.com), click the Forgotten Password link.
  • Navigate to My Profile and select Change Password.
  • Ask an administrator to reset your password via the User Management area. Administrators also have the ability to log your account out of any active sessions.
 
 

Why do I see an extend session warning? Platform-Wide

  • For security purposes, the 9ine Platform logs users out after 45 minutes of inactivity, with a reminder at 30 minutes. 
  • In full-screen mode when using the Rich Text Editor, the inactivity reminder may not appear unless browser notifications are enabled. Typing is not considered activity; you must click Cancel or Save to reset the inactivity timer.
 
 

Why am I being logged out? Platform-Wide

  • Session Timeout: For security purposes, the 9ine Platform automatically logs users out after 45 minutes of inactivity. A reminder is triggered at 30 minutes of inactivity. User activity includes actions like navigating between pages and saving data. Merely having the platform open or typing into the Platform without saving (or discarding changes via the Cancel button) is considered inactivity.
  • SSO Session Expiration: If you have logged in using Single Sign-On (SSO) and your SSO session expires (e.g., through Google or Microsoft), you will be automatically logged out of the Platform.
  • System Updates: You may also be logged out during routine maintenance or Platform updates.

If the issue persists or you believe it's unrelated to these reasons, please contact [email protected] for further assistance.

 
 

How do I recover data I've deleted? Platform-Wide

To recover deleted data, please email the details of the data you need restored to [email protected]. A member of our support team will assist you with your recovery request.

 
 

How do I download data? Platform-Wide

The 9ine Platform supports five types of downloads: log, form, advanced, Gantt Chart and Dashboards. 

To download data from a log, click the Download button located in the top right-hand corner and choose either Log or Advanced as your option. You can customise your download report to include or exclude specific data by using the search bar, filters, view options, or the My Actions function. Regardless of your sequence order and View selections, all columns are downloaded when exporting a log. After clicking Download, the export will be saved to your local file explorer in .xls format. If the export is large, an email notification will be sent once the download is ready.

For forms, downloads are available for incident management, records of processing activity, processing operation assessment, or DPIA. To download a form, click the three dots on the form page and select the Download option. These form downloads are exported in .docx format.

 
 

Why can't I see the other modules in the left navigation menu when I could see them previously? Platform-Wide

If you can no longer see certain modules in the left navigation menu, it may be due to your organisation's subscription status. When a subscription to specific modules expires, those modules are no longer accessible. To resolve this, please check with your primary account administrator or contact [email protected] for assistance with your subscription.

 
 

How will I know if any new changes or enhancements have been added? Platform-Wide

You can stay informed about new changes or enhancements added to the Platform through the following methods:

  • Help Centre: The Help Centre contains Release Notes, where detailed information about recent changes and enhancements is available.
  • Home Screen: Important updates and new enhancements may be highlighted on your home screen for a quick overview of key changes.
  • Email Updates: If you have opted in, you will receive email notifications outlining the latest changes or enhancements made to the Platform.
 
 

What happens if I close or delete a form (data protection impact assessment (DPIA), record of processing activity, incident, or processing operation assessment)? Platform-Wide

When a form is closed or deleted, all associated risks, issues, lessons, and tasks are also marked as closed or deleted. Closed items are removed from the respective logs, and deleted items are fully removed from the Platform.

 
 

How can I create associated risks, issues, lessons, or tasks within a form (data protection impact assessment (DPIA), record of processing activity, incident, or processing operation assessment)? Platform-Wide

In the form, click the +New button in the top right-hand corner and choose to create a risk, issue, lesson, or task. These items will then appear in the Summary of Activities table.

 
 

What is the purpose of the summary of activities table in the forms? Platform-Wide

The summary of activities table provides an overview of any associated risks, issues, lessons, and tasks that were created through the form using the +New button, ensuring comprehensive governance.

 
 

How do I add a notified user to a form (data protection impact assessment (DPIA), record of processing activity, incident, or processing operation assessment)? Platform-Wide

You can add a notified user by mentioning them in the Additional Notes feature using the @mention function. This notifies the user through an in-Platform and email notification.

 
 

When closing a form (record of processing activity, incident, data protection impact assessment, or processing operation assessment) or grandparent or parent item (project group or project) is it possible to keep a risk, issue, lesson or task open? Platform-Wide

No, it is not possible to keep a risk, issue, lesson, or task open when closing a form (such as a Record of Processing Activity, Incident, Data Protection Impact Assessment, or Processing Operation Assessment) or a grandparent/parent item (like a Project Group or Project). When these higher-level items are marked as closed, all associated risks, issues, lessons, and tasks are also automatically closed to maintain consistency and compliance within the 9ine Platform’s structured workflow.

 
 

Can the screening outcome decision (for an incident or DPIA) be changed after the initial selection? Platform-Wide

Yes, users can return to the screening outcome step to update the decision or review fields if new information becomes available or if reassessment is necessary.

 
 

What are the roles of approvers and reviewers in data protection impact assessments, records of processing activity and processing operation assessment forms? Platform-Wide

  • Reviewer: Available in ROPA, DPIA, and POA forms to examine and validate form content.
  • Approver: Available in DPIA and POA forms for final approval, and confirmation that the assessment aligns with expectations. 
 
 

Global Dashboard FAQs

How do I remove access to data being displayed on a colleague's dashboard? To rem...

How do I remove access to data being displayed on a colleague's dashboard? Dashboard Common

To remove access to data on a colleague's dashboard, you need to adjust their permissions within the Platform. You can do this in two ways:

  • Remove Feature Access Entirely: Navigate to the User Management section: This area is accessible to administrators via the header. Locate your colleague in the list of users. Remove their access to the specific feature entirely. This action will prevent them from accessing any data associated with that feature across the platform.
  • Identify relevant items and remove limited access: Determine which specific items (such a specific incident form, a task, a record of processing area) you want to restrict access to. Remove your colleague from roles that grant access to these items. This includes roles like owner, member, notified user, reviewer, approver, or attachment reviewer.

Remember permissions can be inherited through grandparent and parent items. For example, if a user is a member of a project group (the grandparent), they may have access to all associated projects, risks, issues, lessons, and tasks (the children and grandchildren). You may need to adjust permissions at the parent level to fully remove access.

For detailed information on a user's access level, navigate to User Management and locate their name, then click Manage User Permissions. Individual access is listed under each of the permission accordion bars.

 
 

How do I rearrange or remove dashboard cards?Dashboard Common

You can assign sequence numbers to dashboard cards to rearrange them. Simply enter a number (e.g., 1, 2, 3) in the left-hand corner of each card, and they will automatically reorder based on the sequence. To remove individual cards, click View and deselect the cards you don't want displayed. Click Apply to save your changes.

 
 

Why am I seeing limited or no data available on my dashboards?  Dashboard Common

You may be seeing limited or no data available on your dashboards because the feature associated with the dashboard may not have been populated with data yet. Initially, users might encounter No records available messages on dashboard cards until relevant data is entered across these features. Additionally, the items displayed are limited to those to which you are assigned or have permission to access based on your roles, such as owner, member, notified user, or attachment reviewer.

 
 

Why are my Top 10 dashboard cards not displaying correctly, and how can I fix this? Dashboard Common

The Top 10 dashboard cards rely on specific data inputs, particularly dates and priorities, to sort and display data on these cards. If these items do not have dates assigned, they may not appear in the Top 10 cards, causing the dashboard to function improperly. There is a No Date Selection option available in the Date Range Picker. When selecting No Date Selection, the Top 10 cards will appear blank.

By ensuring that dates and priorities are assigned to items within features such as risks, tasks, records of processing activities, you enable the dashboard to function correctly, providing you with accurate and timely insights into your most critical items. Without dates, the system cannot accurately display items in the Top 10 cards.

 
 

What are the date range options available on the dashboards? Dashboard Common

The date range picker offers several predefined options: Today, Yesterday, Last 7 Days, This Month, Last Month, Custom Date Range, and No Date Selection. For monthly selections, the system automatically sets the start and end dates based on the calendar month. To review data from a specific period within a month, use the Custom Date Range option

 
 

How does No Date Selection work in the date range picker on the dashboards? Dashboard Common

When No Date Selection is applied in the date range picker on a dashboard, only data entries without a specific date are displayed. This is useful for identifying or reviewing items that do not have deadlines or assigned dates, helping you focus on undated entries.

 
 

How does the Clear Date Range function work on the dashboards? Dashboard Common

The Clear Date Range option removes any applied date filters, allowing you to view data from all available time periods without any date limitations. This is useful if you want to reset the filter and see a comprehensive overview of all available dashboard data, rather than restricting the view to a specific time range.

 
 

How does the Reset Filters & Date Range function work on the dashboards? Dashboard Common

The Reset Filters & Date Range option clears all applied filters and date selections. This feature is helpful when you want to reset the dashboard to its full dataset, free of any restrictions or previously applied filters. When used, it:

  • Removes all applied filters (e.g., status, priority, or category filters), returning the dashboard to its default, unfiltered view.
  • Clears any selected date range, allowing the dashboard to display all data, regardless of time frame.
 
 

Can I download both graphs and tables in a single export? Dashboard Common

No, it is not possible to download both graphs and tables in one export. Graphs are exported as PDFs, while tables are exported as XLS files. You must deselect graph charts if you wish to download tables and vice versa.

 

Global Log FAQs

How do I change my pagination from alphabetical to numeric? The pagination style ...

How do I change my pagination from alphabetical to numeric? Platform Logs Table

The pagination style for each log on the 9ine Platform is predefined and cannot be changed by users.

 
 

How do I sort the data displayed in my log? Platform Logs Table

To sort the data in your log, click on a column header once to sort the log by that column in ascending order. Click the same column header again to reverse the order and sort by descending order.

 
 

How can I apply sorting to multiple columns? Platform Logs Table

Currently, it is not possible to apply multi-column sorting on the 9ine Platform logs. Each column can only be sorted individually.

 
 

How do I resize the columns in my log? Platform Logs Table

When you remove columns from a log, additional space becomes available, allowing you to resize the remaining columns.

 
 

How do I reorder the columns in my log? Platform Logs Table

You can change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login. These changes are user and log specific and are only applied to your profile. 

 
 

I’ve reordered the sequence of a log but the view popup remained the same? Platform Logs Table

The sequence order in the View popup does not automatically update to reflect the order created through your dragging and dropping actions. This order is predefined by the 9ine Platform and is not editable.

 
 

How do I limit the number of columns I can see in my log? Platform Logs Table

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Save View in the top right-hand corner of the View popup to apply the changes.

 
 

How do I edit something I have closed? Platform Logs Table

Once an item is closed in the 9ine Platform, it becomes uneditable. To make any edits, you will need to reopen the item first.

 
 

How do I know if a filter has been applied? Platform Logs Table

When a filter is active, an orange dot appears next to the filter icon for easy recognition. To quickly clear any filters, click the Clear Filters button in the popup. You can also apply a temporary filter without clicking Save Filter. To revert back to your saved filter, click Reset. Similarly, you can select data points and click Apply without saving your filter options.

 
 

How does the My Toggle button work? Platform Logs Table

The My Toggle button is located in the top right corner of every log. When activated, the log filters to display only the items where you are a member, owner, or notified user. This feature allows you to quickly view and manage items directly related to you.

 
 

How do I delete something allocated to me if I can't see an option? Platform Logs Table

You can only delete items for which you are the owner. It is not possible to delete an item if you are a member, notified user, attachment reviewer, approver, or reviewer.

 
 

How do I make a copy of an item? Platform Logs Table

A duplicate function is available throughout the 9ine Platform, with the exception of incident management. When you duplicate an item, it is prefixed with Copy of followed by the original title. The permissions from the original item are retained, although they can be modified as needed. If the item has associated child items, these are automatically included in the duplication. However, attachments and notes from the original item are not duplicated.

 
 

What happens when I duplicate an item? Platform Logs Table

  • It is possible to duplicate a:
    • Project Group
    • Project
    • Risk
    • Issue
    • Lesson
    • Task
    • Record of Processing Activity 
    • Data Protection Impact Assessment (DPIA)
    • Vendor
    • Processing Operation Assessment (POA)
  • It is not possible to duplicate a:
    • incident
    • Record of Processing Area
  • When duplicating a grandparent or parent item, all associated children are duplicated as part of the process. 
  • Each duplicated item is labeled with the prefix Copy of.
  • When duplicating a project group, project, risk, issue, lesson, or task (either from Governance or via a form duplication) notes, attachments, logged time, and logged costs are not copied to the duplicated items.
 
 

Why can I see fewer (or more) records on my log than my colleague? Platform Logs Table

The number of records displayed on your log depends on the permissions assigned to you. You will only be able to see records where you have been given access, such as being an owner, member, notified user, reviewer, approver, or attachment reviewer. If your colleague has been assigned different permissions or roles, they may see more or fewer records based on their access.

 
 

Notified User (@ Mention) FAQs

How do I add a notified user? To add a notified user: Use the mention function in...

How do I add a notified user? Notifications

The Notify User (Mention) functionality is available throughout the Governance Platform (Project Groups, Projects, Risks, Issues, Lessons, and Tasks) via the Description or Notes tab. Additionally, it is accessible on all forms (Records of Processing Activity, Data Protection Impact Assessment, Processing Operation Assessment, and Incident Management) through the Additional Note section. This feature allows you to mention users, ensuring they receive both in-Platform notifications and, if enabled, email alerts. To add a notified user:

  • Type the @ symbol followed by the first name of the user you wish to mention.
  • The user can be mentioned anywhere in the text.

Mentioning a user sends them an in-Platform notification and an email (unless they have disabled email notifications).

 
 

How do I remove a notified user? Notifications

To remove a notified user, simply delete their name from the relevant description or note where they were mentioned.

 
 

Attachment FAQs

Can I see all attachments that have been uploaded in one view? No, attachments ar...

Can I see all attachments that have been uploaded in one view? Attachments

No, attachments are only visible within the specific item where they have been uploaded. You cannot view all attachments across different items in a single view. 

 
 

What file types and sizes are supported when uploading attachments? Attachments

The supported file types include jpg, jpeg, tif, tiff, png, doc, docx, pdf, xls, xlsx, and many more. The maximum file size is 10MB, and you can upload up to five files at a time.

 
 

Notifications FAQs

How do I manage my notification preferences? You can manage your notification pre...

How do I manage my notification preferences? Notifications

You can manage your notification preferences by clicking the settings icon in the notification popup. This opens a settings window where you can toggle different types of notifications on or off.

 
 

What types of notifications can I receive? Notifications

You can receive five types of notifications:

  • Assignments: When you are assigned or reassigned as owner, member, reviewer, or other roles.
  • Comments: When you are mentioned in a comment.
  • Due Dates: Reminders about overdue or upcoming due dates.
  • General Updates – For Me: Updates on items you are directly involved in.
  • General Updates – For Others: Updates on items you are indirectly involved with.
 
 

Can I receive notifications via email as well? Notifications

Yes, notifications can be sent both in-Platform and via email. You can customise which types of notifications you want to receive through your notification settings.

 
 

How do I change my cookie preferences? To adjust your cookie settings, click the ...

  • To adjust your cookie settings, click the header menu and select Cookie Preferences from the dropdown menu. This will open a Preferences popup where you can manage your cookie options. 
  • When the popup first opens, you will see two main options:
    • Allow All: Enables all cookies.
    • Decline All: Disables all non-essential cookies.
  • For more granular control, select or deselect specific cookie categories by clicking the checkboxes next to each category.

Please note that essential cookies cannot be deselected, as they are necessary for the Platform’s functionality. 

 
 

My Profile FAQs

How do I change my preferred initials? To change your preferred initials, click o...

How do I change my preferred initials? My Profile

Open My Profile, update Preferred Initials and select Save.

Your preferred initials must be two or three letters and must be unique within your organisation. If another user already uses the initials you enter, the message The selected initials are already in use. is displayed and the change is not saved.

 
 

How do I update my first name or last name? My Profile

Open My Profile, update First name or Last name and select Save.

Both fields are mandatory and each accepts up to 35 characters.

 
 

Why can’t I access My Profile in my secondary organisation? My Profile

My Profile is only available in your primary organisation. When you are working in a secondary organisation, the My Profile option is not displayed.

The same applies to a consultant working in a client organisation. Use Switch Organisation to return to your primary organisation if you need to view or update your details.

Your personal details are shared across the organisations you belong to, so there is only one profile to maintain.

 
 

Can I change my email address? My Profile

No. You cannot change the email address associated with your 9ine Platform account in My Profile. Email address and Organisation name are read-only.

If you need help with your account email address, use Request Support in the 9ine Platform to contact 9ine Support, or email [email protected].

 
 

Why can’t I see the Change Password option? My Profile

Change Password is available only if you have completed your profile and you do not sign in using Google or Microsoft single sign-on.

If you use single sign-on, your password is managed by your identity provider rather than the 9ine Platform, so there is no Platform password to change here.

 
 

What are the requirements for my profile picture? My Profile

Your profile picture must be a JPEG or PNG file, no larger than 10 MB, with a filename that does not contain special characters.

Uploaded images are scanned for viruses before they are stored, and embedded location or device information is removed. To return to the standard profile image, select Set Default.

 
 

What is my user reference number, and why does it start with TEMP? My Profile

Your user reference number is the unique identifier for your account.

A reference number beginning with TEMP is temporary and means your account is waiting to be approved by an administrator in your organisation. Once you are approved, it is replaced by a permanent reference number automatically. You do not need to do anything.

 
 

Organisation Profile FAQs

How do I update the primary account administrator (PAA) for my organisation? To u...

How do I update the primary account administrator (PAA) for my organisation? Organisation Profile

To update the primary account administrator for your organisation, you must have administrator permissions.

  • Click on the header menu and select Organisation Profile from the dropdown.
  • In the Primary Account Admin dropdown field, select the new user from the list and click Save at the bottom of the page to confirm the update.
  • This action will trigger an email and an in-Platform notification to all administrators.
 
 

How do I enable (or disable) Single Sign-On (SSO) for my organisation? Organisation Profile

To enable Single Sign-On (SSO) for your organisation, you must have administrator permissions and assistance from your IT department. Your IT department must approve 9ine as an authorised third-party application using either Google Workspace Admin Console or Microsoft Entra Admin Center. For more details, refer to our user guides:

Once approved, click on the header menu and select Organisation Profile from the dropdown.

  • In the bottom-right corner of the page, locate the Manage Single Sign-On section.
  • You can enable SSO by using the Google or Microsoft toggles and clicking Save SSO Settings.
  • Once SSO is enabled by a Platform administrator via Organisation Profile, the SSO buttons will appear on the login page (app.9ine.com).

To disable SSO, please contact us at [email protected].

 
 

Handshake FAQs

...

User Management FAQs

Can there be multiple owners for an item? No, there can only be a single owner of...

Can there be multiple owners for an item? User Management

No. Each item can have only one Owner.

 
 

Can a user be both the Owner and a Member of the same item? User Management

No. A user cannot be both the Owner and a Member of the same item.

An Owner or Member can also be a Notified User for the same item.

 
 

What is the difference between Owner and Member permissions? User Management

Owner: Can edit and delete the items they own.

Member: Can edit items where they are a Member, but cannot delete them.

Reviewer, Approver, Attachment Reviewer and Notified User: Have the same access level as a Member.

 
 

What happens if an Owner’s account is disabled or deleted? User Management

Disabled: The next time the item is edited and saved, you are prompted to reassign the Owner.

Deleted: 9ine Platform Administrators are prompted to reassign any items that are not Closed, including items with statuses such as Open, Not Started, In Progress, On Hold or Quality Assurance.

 
 

How many users can I invite to an organisation? User Management

There is no limit to the number of users you can invite to the 9ine Platform.

 
 

Why has a module disappeared from my left navigation? User Management

A module is displayed only while your organisation has access to it and you have been granted the module individually. If either is removed, the module is no longer displayed in your navigation.

If your organisation still has access to the module, ask your organisation’s 9ine Platform Administrator to review your permission. If your organisation’s access to the module has ended, use Request Support in the 9ine Platform to contact 9ine Support, or email [email protected].

 
 

Why can’t I see a module I have been given access to? User Management

If you have recently been given access to a module, the change appears the next time you load a page or move around the Platform. You do not need to sign out and back in.

If the module is still not displayed, ask your organisation’s 9ine Platform Administrator to review your permissions.

 
 

You are taken to Home and shown a message explaining that you no longer have access, rather than being left on a page you cannot use.

This applies whether you use a saved link, a link in an in-Platform notification or email, or a link to a specific item.

 
 

Why can I see some items in a navigation group but not others? User Management

Each item within a navigation group is granted separately. A group heading, such as Governance or Vendor Assessment, appears when you have access to at least one item within it and disappears when you have access to none.

Being granted one item in a group does not give you access to the other items in that group.

 
 

Why can I see Contract Log but not Finance Log? User Management

Finance Log is a separate permission from Contract Log, so it must be granted to you separately.

Ask your organisation’s 9ine Platform Administrator to grant access to Finance Log. Vendor Log and POA Log are also granted separately from each other.

 
 

Can Home be removed from my navigation? User Management

No. Home is always available to every user, regardless of their other permissions.

 
 

Provide Feedback FAQs

How do I provide feedback? To provide feedback, click the ...

How do I provide feedback? Provide Feedback

To provide feedback, click the Provide Feedback button in the header menu. This will open a Provide Feedback popup with three sections:

  • Rating: Send a standalone rating for the 9ine Platform.
  • Write a Review: The Feedback Type, Module and Message fields are mandatory if you choose to write a review. You can also add up to five attachments.
    Client Feedback Session: 
  • You can select the checkbox to participate in a client feedback session.

You can complete any or all sections. Once your rating, review, and/or checkbox selection is ready, click Send.

 
 

Request Support FAQs

How do I request support? To request support, click the ...

How do I request support? Request Support

To request support, click the Request Support button in the header menu. This will open a Request Support popup, where you can compose a message to the 9ine Support team. Both the Subject and Message fields are mandatory, and you can also upload up to five attachments.

 
 

How long will it take to receive a reply from 9ine Support? Request Support

The 9ine Support team strives to provide an initial response to queries within 4 hours (during 08:30 - 5:30 GMT). However, response times may vary based on the complexity and urgency of the issue. If your request is urgent, include Urgent in the subject line of your support request to ensure prioritisation.

 
 

Switch Organisation FAQs

How do I add users with a different email domain?  By default, only users with th...

How do I add users with a different email domain? Switch Organisation

By default, only users with the same email domain can be added, and only administrators have permission to add new users. To add users with a different email domain, please contact [email protected] and provide the domain you wish to add. The 9ine Support team will process your request, add the additional email domain, and notify you once the process is complete.

 
 

Why do I see an option to Switch Organisation? Switch Organisation

The Switch Organisation option, located in the header menu, is available to all users and allows those associated with multiple organisations to access their different environments. When you click on Switch Organisation, you will either see a list of organisations to switch between (if linked to multiple organisations) or a message prompting you to contact [email protected] to add an additional domain.

 
 

Home FAQs

What is the Home Screen? Home

The Home Screen is your personalised dashboard in the 9ine Platform, displayed when you sign in.

It brings together the work that needs your attention, together with the content and tools most relevant to your role. You can personalise your Home Screen by choosing which dashboard cards are displayed and how they are organised.

 
 

How do I personalise my Home Screen? Home

Select the Edit Home icon to personalise your Home Screen.

From Edit Home, you can add or remove dashboard cards, organise them into accordions, rearrange their order and save your layout. Dashboard cards can be combined across Governance, Incident, Privacy, Contract and Vendor areas.

You can return to Edit Home at any time to update your Home Screen.

 
 

How many accordions and cards can I add to my Home Screen? Home

You can add up to nine accordions to your Home Screen, with up to twelve cards in each accordion.

Once an accordion contains twelve cards, create another accordion to continue adding cards. If you exceed either limit, the Platform will prompt you to remove items or create a new accordion.

 
 

What is the difference between No Accordion and an accordion? Home

No Accordion displays your selected dashboard cards directly on the Home Screen, making it suitable for a small number of high-priority cards.

Grouping cards within an accordion places them under a collapsible heading, helping you organise larger dashboards or related information.

You can use either approach, or combine both, to personalise your Home Screen.

 
 

What is the Progress & Quick Add card? Home

The Progress & Quick Add card provides an overview of your outstanding work across the Platform.

It shows completed and overdue items, with overdue items highlighted in red to help you identify where action is needed. You can also create new records directly from the card using the Add option, without opening the relevant module.

Incident Management displays separate totals for Open and Closed incidents.

 
 

Which items are counted in Progress & Quick Add? Home

Progress & Quick Add includes items where you are the Owner, Member, Reviewer or Approver.

Items with a Closed status are not included, helping you focus on the work that still requires your attention.

 
 

Why can't I create a new item from Progress & Quick Add? Home

If you cannot create a new item, the Add option is replaced by an information icon.

This happens when:

  • you do not have access to the module;
  • the module licence has expired; or
  • your organisation has reached its licence allowance.

Hover over the information icon to view the reason. If you believe you should have access, contact your organisation's 9ine Platform administrator.

 
 

Why can't I see some modules in Progress & Quick Add? Home

Progress & Quick Add only displays modules you have permission to access.

If you expect to see a module that is not displayed, contact your organisation's 9ine Platform administrator to review your permissions.

 
 

How do I refresh my Home Screen? Home

Select the Refresh icon to update your Home Screen with the latest information.

Hover over the icon to view the date and time your Home Screen was last refreshed.

 
 

Governance Common FAQs

Why are the buttons at the top of the Governance features (project groups, projec...

Why are the buttons at the top of the Governance features (project groups, projects, risks, issues, lessons, and tasks) greyed out and disabled? Governance Platform

The buttons and functions available in the three dots of the log, are greyed out and disabled if your organisation has not purchased the Governance subscription. Although risks, issues, lessons, and tasks associated with the forms you have access to will be displayed in the respective logs, they cannot be ma,naged from this view. Instead, you must manage them using the functionality available in the Summary of Activities table on each specific form.

 
 

I have duplicated a task (or a project) and the logged time and costs have not been copied. Why is that? Governance Platform

This is by design. Logged time and costs are not copied during the duplication process to ensure that new duplicates start with a clean state for accurate tracking and management. 

 
 

How do default Project Groups and Projects work in the 9ine Platform? Governance Platform

Default Project Groups and Projects are created based on your organisation’s subscription to help manage risks, issues, lessons, and tasks. These default groups cannot be deleted, but they can be hidden using filters. Your organisation is granted access to default Project Groups based on the subscription purchased, such as Data Privacy & Protection, Incident Management, and Vendor Assessment.

 
 

Governance Dashboard FAQs

...

Gantt Chart FAQs

What is displayed in the Gantt Chart when a project has no start date and due dat...

What is displayed in the Gantt Chart when a project has no start date and due date? Gantt Chart

  • When a project has no start and due dates, it is still displayed on the left-hand panel if its associated tasks have specified start or due dates. However, no corresponding bar graph appears on the right.
  • If neither the project nor its tasks have start and due dates, the project will not appear in the left panel or on the Gantt Chart graph, but tasks with no dates appear in the left-hand grid with no bar graph on the timeline.
  • For projects without set dates where tasks have either a start or due date, a milestone icon is displayed on the Gantt chart at the dates provided for the tasks. This helps in visually tracking task deadlines even when the overall project timeline is not defined.
 
 

What is displayed in the Gantt Chart when a project has a start date but no due date? Gantt Chart

  • When a project has a start date but no due date, and its associated tasks have specified start and/or due dates, the project information is shown on the left side, with milestones displayed on the right for these dates.
  • If the project has only a start date and its tasks has neither a start and due date, a milestone will represent the project on the right-hand panel, and the tasks will not appear in the left panel.
  • When the project has a start date but no due date, and its tasks have either a start or due date, milestones will be displayed on the Gantt chart at these dates for both the project and its associated tasks, providing a clear view of individual task timelines relative to the project start.
 
 

What is displayed in the Gantt Chart when a project has no start date but has a due date? Gantt Chart

  • When a project only has a due date and its associated tasks have both start and due dates, the project's details will appear on the left side, with a milestone displayed in the right panel, while bar graphs show the tasks' timelines.
  • If the project has only a due date and its tasks do not have a start and due date, a milestone will represent the project on the right panel, and the tasks will appear on the left side with no bar graph.
  • When a project has only a due date, and its tasks have either a start or due date, milestones will be displayed for both the project and its tasks at their respective dates on the Gantt chart.
  • In scenarios where the project has either a start date, due date, or both, and its associated tasks has no specific dates assigned, the project will be represented by either a bar graph or a milestone, while its tasks will be listed in the left grid without graphical representation.
 
 

What is displayed in the Gantt Chart when a task has either a start date or due date? Gantt Chart

  • When tasks are scheduled with both start and due dates, a bar graph visually represents these tasks on the Gantt Chart, extending from the start to the due date.
  • If a task has neither a start or due date, it will not be represented by a bar graph on the Gantt chart. Instead, these tasks are listed in the left grid on the left panel, without a bar graph.
  • For tasks with only a start date and no due date, a milestone marker is placed on the start date on the graph to indicate the beginning of the task.
  • Conversely, if a task has a due date but no start date, a milestone marker is shown at the due date on the graph, highlighting the deadline for task completion.
 
 

Project Group FAQs

What is a Project Group? Project Group

A Project Group is the top level of the Governance hierarchy. It groups related Projects together so that ownership, membership, access and status are managed once at the group level and inherited by everything beneath it. Each Project in a group holds its own Tasks, Risks, Issues and Lessons, so managing the group affects that whole branch of work. Grouping is optional, a Project can also stand alone.

 
 

Who can access Project Groups? Project Group

Access depends on your organisation’s licence and on your role on each group. Your organisation needs the Governance licence, and you then see a Project Group when you are added to it as an Owner, Member, Notified User or Attachment Reviewer. Everything is scoped to your organisation, and anyone added to a group is given access to the module automatically.

 
 

What are the roles in a Project Group and what can each do? Project Group

There are four roles:

  • Owner is accountable for the group and is the only role that can delete it; an Owner can also create, view, edit and duplicate.
  • Member can create, view, edit and duplicate, but cannot delete.
  • Notified User has the same working rights as a Member and is also kept informed about the group; cannot delete.
  • Attachment Reviewer reviews the attachment assigned to them.

Only the Owner can delete a Project Group.

 
 

How do I add someone as a Notified User? Project Group

You add a Notified User while creating or editing the group, in the same place you assign the Owner and Members. A Notified User is kept informed about the group and holds the same working rights as a Member, they can view, create, edit and duplicate it, but cannot delete it. Anyone you add is given access to the module automatically.

 
 

What are the Project Group statuses? Project Group

Project Groups use a fixed set of five statuses: Not Started, In Progress, On Hold, Quality Assurance and Closed. A new group always starts as Not Started, and you can then move it to any other status in any order. Closed is not final and can be reopened. The set is the same for every organisation and cannot be changed, and you update one group’s status at a time.

 
 

What happens when I close or delete a Project Group? Project Group

Closing a group sets its status to Closed and notifies the relevant people. It is not final, so a closed group can be moved back to another status at any time. Deleting a group removes it entirely, and you can choose to delete its child Projects, Risks, Issues, Lessons and Tasks along with it. Deleting also removes the related access and notifies the relevant people. Only the Owner can delete a group.

 
 

Can I duplicate a Project Group? Project Group

Yes. Owners and Members can duplicate a group, subject to your organisation’s contract. You can add a prefix to the copy’s title, and the copy keeps the same access as the original.

 
 

What are default Project Groups? Project Group

A default Project Group is created for you automatically when a contract is purchased, so a usable group is ready from the start. You can work in it straight away or create your own groups as normal.

 
 

How do I get reminded about a Project Group’s due date? Project Group

You are reminded through a due-date reminder on the group. You choose the timing, the reminder fires according to the reminder you set against the due date rather than on a fixed schedule. It reaches you as an in-Platform notification and, where you have email notifications enabled, by email.

 
 

Why does the log look different for me, and where did a closed group go? Project Group

Your log reflects your own saved filter and the My Project Groups toggle, so two people can see different lists. When you have not set a filter, a personal or organisation default is applied, and the toggle narrows the log to the groups you are on. Everything is also limited to your organisation and to the groups you can access. A closed group has not been removed, it has moved to the Closed status, so clearing your filter or including Closed brings it back.

 
 

Projects FAQs

Can I create a project without a project group? Projects

Yes, it is possible to create a project that does not belong to a project group. This is referred to as a standalone project. You can select or remove a project group when editing a project by selecting your preferred project group title.

 
 

How are project group permissions linked to individual projects? Projects

If a project is part of a project group, the project group’s Owner, Members, Notified Users, and Attachment Reviewers are automatically granted edit and delete privileges for the project. These users are not shown in the project log or popup but still have inherited permissions. To view a project group's permission, navigate to the project group log.

 
 

How are permissions inherited from a project to associated risks, issues, lessons, and tasks? Projects

A project’s permissions, such as Owner, Member, Notified User, and Attachment Reviewer, are automatically inherited by any associated risks, issues, lessons, and tasks. The project is considered a parent in the permission hierarchy, granting edit and delete permissions to the child items.

 
 

How can I schedule and manage time in a project? Projects

The scheduling tab allows you to set start dates, due dates, and the project timeline. Time can be estimated and logged against tasks, but it is not possible to log time directly against a project. Time entries are displayed in a visual bar that changes colours (on the Projects log) based on the logged and estimated time.

 
 

What is the relationship between tasks and projects in terms of cost and time? Projects

Time and cost behave differently. Time is estimated and logged against a project's tasks, and the project's total estimated and logged time is rolled up from those tasks for display; you cannot log time directly against the project. 

Cost works separately: you can estimate and log cost against the project and against individual tasks, but task costs are not aggregated into the project cost total, and the project's own cost is not added to its tasks. 

The projects log shows the project cost and the task cost as separate figures, and all tasks and the project must use the same currency.

 
 

Can I estimate and log costs for a project? Projects

Yes, costs can be estimated and logged both for a project and individual tasks. However, project cost and task cost are kept separate: task costs are not rolled into the project cost total, and a Total logged task cost is shown on the tab for convenience only. The platform allows you to view cost logs, track changes, and ensure all tasks within a project use the same currency.

 
 

Risk & Issues FAQs

How do I convert a risk to an issue or an issue to a risk? To convert a risk to a

How do I convert a risk to an issue or an issue to a risk? Risk & Issues

To convert a risk to an issue or vice versa, you can either click the three dots in the risk and issue log and select the Convert option, or change the Type in the top right corner of the risk or issue popup. Additionally, conversions can be made via the Summary of Activities table in any of the forms available on the 9ine Platform, including incident management, records of processing activity, processing operation assessment, or DPIA. Once a risk or issue is converted, all references to it will automatically be updated across the platform, such as in logs and association fields.

 
 

When converting a risk to an issue or an issue to a risk, what happens to the reference number? Risk & Issues

The prefix for a risk (RIS) is changed to the format used for issues (ISS), while the numerical part of the reference number remains unchanged.

 
 

Why can users of a form see the details of my associated risk or issue? Risk & Issues

When a risk (or issue) is associated with a form such as incident management, records of processing activity, processing operation assessment, or DPIA, it becomes a linked or child item. Consequently, anyone with permissions to access the form also gains permissions to view the details of the associated risk (or issue) and any linked tasks. This integration ensures that all relevant information is accessible to users managing related forms.

 
 

How do I upload my existing risk register? Risk & Issues

To upload your existing risk register, please email a copy to [email protected]. A member of our team will handle the data upload for you.

 
 

How are risks and issues scored? Risk & Issues

Risks and issues are scored by multiplying the impact and likelihood values. This score is displayed on the log, and the overall rating is used to determine the level of risk or issue.

 
 

Who can see and edit a risk or issue? Risk & Issues

Only people assigned to a risk or issue can see it: its Owner, Members, Notified Users and Attachment Reviewers, along with anyone who has access to a project or project group it belongs to. Members and Notified Users can edit the record, but only the owner can delete it. If you cannot see a record you expect to, ask your organisation's 9ine Platform administrator to check your access.

 
 

What happens when I close a risk or issue? Risk & Issues

Closing a risk or issue removes it from the default log and closes any tasks linked to it at the same time. It is not deleted: you can Reopen it whenever you need to, which restores the record and returns its associated tasks to Not Started. Use Close when something is resolved, and Delete only when you want to remove the record and its tasks from the Platform entirely.

 
 

Can a risk or issue exist without a project? Risk & Issues

Yes. Choosing a project group and project is optional, so a risk or issue can stand on its own. When it does, the log simply shows a dash in the project and project group columns. You can link it to a project later by editing the record.

 
 

Lessons FAQs

...

What are Lessons used for? Lessons

Lessons helps your organisation capture and share learning from completed projects, resolved issues and other activities from across the Platform such as Incidents.

Each lesson records the key learning, together with the people responsible, checklists, notes, attachments and any custom data. Lessons can also be linked to related projects and tasks, helping you retain knowledge and apply it to future work.

Lessons also contribute to the Governance Dashboard, where recent lessons and summaries are displayed alongside other governance information.

 
 

Who can access Lessons? Lessons

Access to Lessons is included with your organisation's Governance Platform licence, and available to customers who have access to Governance Lite.

Users must also be granted permission to access the module through User Management. Access to the Lessons module does not automatically give access to every lesson. Each lesson has its own permissions, so users can only access lessons they have been assigned to.

If you cannot access Lessons or a particular lesson, contact your organisation's 9ine Platform administrator.

 
 

What happens when I close a lesson? Lessons

Closing a lesson changes both the lesson and its associated tasks to a Closed status.

The lesson remains in the Lesson Log and can be viewed using the Status filter. Nothing is deleted, and the lesson can be reopened at any time.

 
 

Can I reopen a closed lesson? Lessons

Yes. Reopening a lesson changes its status back to Open and restores any associated tasks that were automatically closed when the lesson was closed. These tasks are returned to a Not Started status so work can continue.

Tasks that were already Closed before the lesson was closed remain closed.

 
 

What are the roles on a lesson, and who can delete one? Lessons

Each lesson includes the following roles:

  • Owner: Can view, edit, delete and manage the lesson and its members.
  • Member: Can view and edit the lesson but cannot delete it.
  • Notified User: Can view and edit the lesson but cannot delete it.
  • Attachment Reviewer:  Reviews attachments assigned to them.

Each lesson can have only one Owner, and the Owner cannot also be assigned as a Member.

If a lesson is linked to a Project Group, Project or another supported record (such as an Incident or Data Protection Impact Assessment (DPIA)), users with access to the linked record are automatically granted access to the lesson, including permission to view, edit and delete it.

 
 

How do I add a notified user to a lesson? Lessons

Add a Notified User by mentioning them in the Description field or in a Note.

Type @ followed by the person's name, then select them from the list.

The user receives an in-Platform notification and, if enabled, an email notification. They are also automatically granted access to the lesson.

Removing the mention removes them as a Notified User.

 
 

What does duplicating a lesson copy? Lessons

Duplicating a lesson creates a new lesson with the prefix Copy of.

The following information is copied:

  • Lesson details
  • Checklist;
  • Custom data
  • Associated tasks.

Notes and attachments are not copied.

 
 

What happens to associated tasks when I close or delete a lesson? Lessons

Closing a lesson changes all associated tasks to Closed.

Deleting a lesson permanently deletes both the lesson and its associated tasks.

If you want to keep an associated task, move it to another lesson before closing or deleting the original lesson.

 
 

Can a lesson be linked to a project, or can it stand alone? Lessons

Yes. Linking a lesson to a Project or Project Group is optional.

Lessons can be created without being linked to a Project or Project Group.

When you link a lesson to a Project, the associated Project Group is populated automatically.

 
 

Why does a lesson show an association I cannot edit? Lessons

Associations are created automatically by the records that raise the lesson and cannot be edited from within Lessons.

The Association column displays the related record's title and reference number for information only.

 
 

How do I see only the lessons I am responsible for? Lessons

Enable the My Lessons toggle to display only lessons where you are the Owner, a Member or a Notified User.

Turn the toggle off to return to the full Lesson Log.

 
 

Can I export the Lesson Log? Lessons

Yes. Select Download from the Lesson Log to export the current view to Excel.

The exported file reflects the filters currently applied to the log, so apply any required filters before requesting the export.

 
 

Tasks FAQs

What is the role of checkboxes on the Task Log, and how do I duplicate, delete, o...

What is the role of checkboxes on the Task Log, and how do I duplicate, delete, or close multiple tasks? Tasks

The checkboxes on the Task Log allow you to perform bulk actions on multiple tasks simultaneously. The available options function the same way as they would for individual tasks but allow you to apply the action to multiple tasks simultaneously.

After selecting multiple tasks using the checkboxes, click on the Manage Tasks button. From there, you can choose any of the following options:

  • Manage: Change the owner, member(s), status, priority, or due date for all selected tasks. You can also move the tasks to a different project group or project. Be sure to click the Save or Cancel buttons.
  • Duplicate: Create copies of the selected tasks.
  • Close: Mark the selected tasks as completed.
  • Delete: Permanently remove the selected tasks.
 
 

Tasks can be linked to create dependencies by using the Link tab in the task popup. You can search for and select tasks based on their reference number or title and link them by different relationships, such as Blocked by, Blocks, Related to, Completed with, Completed before, or Completed after.

When tasks are linked, permissions are shared across the linked tasks. This means that task owners, members, notified users, and attachment reviewers gain access to any task linked to the one they have permissions for.

 
 

How do I manage and track task time? Tasks

Time can be estimated and logged against individual tasks. The total logged or estimated time is aggregated into the project. A Total Logged Time bar displays the time status using different colours (grey, blue, red, green) based on how much time has been estimated and logged.

 
 

How do I manage and track task costs? Tasks

Costs can be estimated and logged for individual tasks, but task costs are not aggregated into the project total. Costs associated with tasks are displayed in the cost log, and the bar displays colours (grey, blue, red, green) to represent the cost status.

 
 

How do I schedule a task? Tasks

In the Scheduling tab, you can assign dates such as start date, due date, and term or semester. The clear button allows you to remove entered dates. If a scheduled date lapses, it will appear in red in the task log. This data is used to help structure tasks in the Gantt Chart.

 
 

How do I use the Gantt Chart for task management? Tasks

The Gantt Chart provides a visual representation of task progress and scheduling. You can access it by clicking the Gantt Chart button in the tasks log. The chart displays tasks in priority colours and provides details on task status, start and end dates, estimated and logged time, and remaining time. Unscheduled tasks are shown under the Unscheduled Tasks header.

 
 

Who can view or edit a task, and how is access granted? Tasks

A task has four roles: owner, member, notified user and attachment reviewer. Only the owner can delete a task; the other roles can edit it but not delete it, and every task has exactly one owner. You see only the tasks you have access to.

Access is granted automatically in a few ways: when you are added as an owner or member; when you are mentioned with an @ in the task description or a note, which also adds you as a notified user with edit access; and when a task is linked to another task you can already access. If you cannot open a task you expect to see, ask the task owner or your administrator to add you.

 
 

How do I focus on just my tasks? Tasks

Turn on the My Tasks toggle on the task log. It filters the log to your open tasks, showing only those where you are the owner, member or notified user, so you can concentrate on the work that is yours. Turn it off again to see every task you have access to.

 
 

How do I associate a task with a risk, incident or other record? Tasks

Associations are created from the other record, not from the task log. Open the risk, incident, record of processing, assessment or other record and add the task from there. The task then shows that record's title and reference number in its Association field and appears on that module's log, and everyone with access to the record is given access to the task.

 
 

How are due-date reminders sent, and how do I control them? Tasks

Due-date reminders are sent in-Platform to everyone associated with a task: the owner, members, notified users and attachment reviewers. Each person controls their own reminders in their User Settings, choosing how many days before the due date to be reminded, from 1 to 31 days, and whether to be reminded Daily or Weekly. If you are not receiving reminders, check these settings.

 
 

How do I import or export tasks? Tasks

You can export the task log to Excel at any time using the download option; the export reflects the filters you have applied. You can also import many tasks at once from the Excel template using the upload option, which is available only if you have upload permission for tasks. Imported rows are validated, and if any rows fail you receive an email summarising the successes and failures with a spreadsheet of the failed rows to correct and re-upload.

 
 

Incident Dashboard FAQs

...

Incident FAQs

How are incident reference numbers generated?  Incident reference numbers begin w...

How are incident reference numbers generated? Incident

Incident reference numbers are generated automatically. They begin with INC, followed by the calendar year, month, date and a unique reference number.

 
 

How is ownership assigned for a new incident, and can it be changed? Incident

When you create an incident, you are automatically assigned as its Owner. The Owner cannot be changed.

 
 

What is the purpose of the screening outcome in the background step of incident management? Incident

The Screening Outcome determines whether the incident needs a full assessment.

Use the information recorded during screening to decide whether further investigation or action is required.

 
 

What options are available for the screening outcome question in the background step of incident management, and what do they mean? Incident

The Screening Outcome has three options:

  • Yes : A full incident assessment is required. The remaining assessment steps become available.
  • No: A full incident assessment is not required. Additional fields are provided to record the reason and, where needed, a follow-up review.
  • Don’t Know: Is not yet enough information to decide. Additional fields are provided so the incident can be reviewed again.
 
 

Does the screening outcome affect which parts of the incident form are accessible? Incident

Yes. If you select No or Don’t Know, later assessment steps remain unavailable. Selecting Yes makes the remaining assessment steps available.

 
 

Who can delete an incident? Incident

Only the incident Owner and your organisation’s 9ine Platform Administrators can delete an incident.

Other incident roles can view and edit the incident where they have access, but they cannot delete it. Deleting an incident also deletes its associated risks, issues, lessons and tasks.

 
 

What happens to associated risks, issues, lessons and tasks when I close or delete an incident? Incident

Closing an incident also closes its associated risks, issues, lessons and tasks. Deleting the incident deletes them.

If you reopen a closed incident, its associated items are restored: tasks return to Not Started, while risks, issues and lessons return to Open.

 
 

How do I see only the incidents I am responsible for? Incident

Turn on My Incidents in the Incident Log. It filters the log to incidents where you are the Owner, Member, Notified User, Data Protection Lead or IT Lead.

 
 

When does the Security & Systems investigation step appear? Incident

The Security & Systems investigation step (step 2a) appears only when Incident Classification is set to Security & Systems or Both. It is intended to be completed by the IT Lead.

 
 

How is an incident’s risk score calculated? Incident

The 9ine Platform calculates the risk score automatically by multiplying the Impact value by the Likelihood value selected in Risk & Impact. You do not enter the score manually.

 
 

Who can access an incident, and how is access granted? Incident

Being granted access to Incident lets you create new incidents, but it does not give you access to every existing incident.

You can access an individual incident when you are assigned to it as its Owner, Member, Data Protection Lead, IT Lead, Screening Reviewer, Notified User or Attachment Reviewer, or when you own or are a member of an associated risk, issue, lesson or task.

If you need access to an incident you cannot find in the Incident Log, ask your organisation’s 9ine Platform Administrator to review your access.

 
 

Data Privacy & Protection Common FAQs

...

Privacy Dashboard FAQs

...

Records of Processing FAQs

What is the difference between Records of Processing (RoP) and Records of Process...

What is the difference between Records of Processing (RoP) and Records of Processing Activity (RoPA)? RoP (Area & Activity)

Records of Processing (RoP) refers to the broader departments or areas within your organisation where data processing activities occur. It provides a high-level view of the different processing areas and the overall purposes and nature of the processing within them, such as HR, admissions, alumni or IT.

A Record of Processing Activity (RoPA) records the detail of a specific processing activity within that area, including what personal data is used, whose data it is, why it is processed and whether it is transferred.

In summary, RoP is the different areas where processing occurs, while RoPA is the individual processing activity within it.

 
 

Who can see and edit a Record of Processing area or activity? RoP (Area & Activity)

Being granted access to Records of Processing lets you create new processing areas, but it does not give you access to every existing area or activity.

For a processing area, you can be the Owner or a Member. For a processing activity, you can be the Owner, Member, Reviewer, Attachment Reviewer or Notified User. Owners and members of a processing area can also access the activities within that area.

The Owner can edit and delete the area or activity they own. Other assigned roles can edit it but cannot delete it.

If you need access to an area or activity you cannot find in the relevant log, ask your organisation’s 9ine Platform Administrator to review your access

 
 

How do I move a record of processing activity to a different area? RoP (Area & Activity)

If you have permission to move the activity, you can move it directly to another processing area.

If you do not have permission to move it directly, a request is sent to the Owner of the destination area to approve or reject. The Platform shows you who will receive the request before you send it.

While a move request is outstanding, the activity cannot be edited and its quick actions are unavailable. The request can be withdrawn before it is approved. Moving the activity keeps all of its existing content.

 
 

What is the Quickstart for Records of Processing? RoP (Area & Activity)

Quickstart provides pre-configured processing areas and activities designed for schools, which you can add to your organisation and then customise.

Quickstart is available when you create a processing area and can also be used within an existing area. Activities added through Quickstart are identified until they have been edited and saved, helping you see which records still contain template wording that needs to be reviewed by your organisation.

 
 

What happens if I close or delete a record of processing area? RoP (Area & Activity)

Closing a processing area also closes its activities and their associated risks, issues, lessons and tasks. Deleting the area deletes them.

If you reopen a closed area, its associated items are restored: activities, risks, issues and lessons return to Open, while tasks return to Not Started.

 
 

What does duplicating a Record of Processing Activity copy? RoP (Area & Activity)

Duplicate creates a copy of the processing activity with Copy Of added to the title.

It does not copy associated risks, issues, lessons or tasks, and it does not duplicate a linked DPIA. These can be added separately to the new activity where needed.

 
 

The link is created from the vendor record.

Open the vendor from the Processing Operation Assessment Log and use Link RoP(s) and Link RoPA(s) to select the processing areas and activities the vendor processes data for.

Once linked, the vendor is shown against the relevant processing area and activity records.

 
 

What happens when a Record of Processing Activity is linked to a DPIA? RoP (Area & Activity)

Information shared by the Record of Processing Activity (RoPA) and Data Protection Impact Assessment (DPIA) is kept in sync, so the same information does not need to be entered twice. Changes to shared information are reflected in both records.

A DPIA can be started from the activity’s review step, or an activity can be linked from the DPIA screening step.

Linking also shares access to that activity: users who can access the DPIA can view and edit the linked activity, but this does not give them access to other activities in the same processing area.

 
 

How do I see only the Records of Processing I am responsible for? RoP (Area & Activity)

Use My Areas on the processing area log or My Activities on the processing activity log.

Each filters the relevant log to items that are not closed and where you are the Owner, Member or Notified User. For more specific criteria, use Filter.

 
 

What can I download from Records of Processing? RoP (Area & Activity)

You can download:

  • Log from the area log: Exports the processing areas currently displayed.
  • Advanced from the area log: Exports processing areas together with their activities.
  • Log from the activity log: Exports the processing activities currently displayed.
  • Advanced from the activity log: Provides the detailed activity export.
  • Download from an individual activity: Creates the completed form as a Word document.

Your search, filter, view and toggle selections affect what is included in a log export, so set them before downloading.

Exports are generated in the background. You receive an email and an in-Platform notification with the download link when the export is ready.

 
 

Retention Management FAQs

 What do I need to use Retention Management? Retention Management

Access to Retention Management is included with the Privacy Platform licence.

Your organisation’s 9ine Platform Administrator grants access in User Management. Being granted access lets you create retention items, but it does not give you access to every existing item.

You can access an existing retention item if you are its Owner, Member or Notified User, or if you have access to a Record of Processing Activity (RoPA) or Data Protection Impact Assessment (DPIA) linked to it.

If you cannot see Retention Management, ask your organisation’s 9ine Platform Administrator to review your access.

 
 

Can I keep data indefinitely? Retention Management

Yes. Select Infinite Retention on the retention item when the data is kept indefinitely rather than for a fixed period.

Selecting Infinite Retention clears and disables the Retention Period field.

 
 

 How do I record how long data is kept? Retention Management

Enter the duration in Retention Period using years, months and days, for example 1y 2m 6d.

If the data is kept indefinitely rather than for a fixed period, use Infinite Retention.

 
 

Yes. A retention item can be linked to one or more Records of Processing Activity (RoPA) and Data Protection Impact Assessments (DPIA).

Once you select an Association type, you must select the RoPA or DPIA to link. Users who can access a linked RoPA or DPIA also gain access to the retention item.

Access is shared with the retention item only. Linking a RoPA and DPIA to the same retention item does not give users of one linked record access to the other.

 
 

What is the difference between archiving and deleting a retention item? Retention Management

Archive closes the retention item and its associated risks, issues, lessons and tasks. The item can be reactivated later.

Delete deletes the retention item and its associated risks, issues, lessons and tasks. Deletion cannot be undone.

 
 

Who can delete a retention item? Retention Management

The Owner can delete a retention item.

If the item is linked to a Record of Processing Activity (RoPA) or Data Protection Impact Assessment (DPIA), the relevant RoPA or DPIA Owners can also delete it.

Members and Notified Users can edit the retention item but cannot delete it.

 
 

What does My Retention do? Retention Management

My Retention filters the log to retention items that are not archived and where you are the Owner, Member or Notified User.

 
 

How am I reminded to review a retention policy? Retention Management

Set a Next review date on the retention item. When the review is due, the Platform sends you a notification.

You can also create an associated Task for the review and add it to your Google Calendar using the Platform’s Google Calendar integration.

To plan and monitor upcoming reviews, you can sort the Retention Management log by review date or filter it by due dates.

 
 

What does duplicating a retention item copy? Retention Management

Duplicate creates a new retention item with the title prefixed Copy of. It also duplicates the associated Tasks, Risks, Issues and Lessons.

It does not copy notes from the retention item. Attachments and Notified Users are not copied from the retention item or from any associated Tasks, Risks, Issues or Lessons. For duplicated Tasks, logged time and logged cost are also not copied.

 
 

Can I create a Task, Risk, Issue or Lesson from a retention item? Retention Management

Yes. You can create a Task, Risk, Issue or Lesson from a retention item using its quick actions in the log.

The new item is linked to the retention item. If you archive or delete the retention item, the associated governance items are closed or deleted with it.

 
 

DPIA FAQs

...

Can DPIAs be linked to a record of processing activity (RoPA)? DPIA

Yes, DPIAs can be linked to RoPAs. If a DPIA and a RoPA are linked, shared information (such as the processing description) will automatically populate in both forms to avoid duplicate data entry.

 
 

How does linking a DPIA with a record of processing activity (RoPA) affect the screening? DPIA

If a DPIA is linked to a RoPA, shared questions in the screening step (such as processing activity details) will automatically populate to ensure consistency across forms. Updates made in one form will reflect in the linked form, saving time and reducing data entry errors.

 
 

What is the purpose of the DPIA screening step? DPIA

The DPIA screening step helps determine if a full DPIA is required based on the initial assessment of risks. This preliminary evaluation allows organisations to decide if further detailed steps are necessary, focusing resources on high-risk processing activities.

 
 

What options are available for the DPIA screening question, and what do they indicate? DPIA

The options include:

  • Yes: Indicates that a full DPIA assessment will be conducted, unlocking additional steps in the DPIA form.
  • No: Indicates that a DPIA is not needed, allowing users to provide a rationale and schedule follow-up reviews if needed.
  • Don’t Know: Indicates uncertainty and prompts additional fields for a scheduled review.
 
 

Does the DPIA screening decision affect the progression of the DPIA form? DPIA

Yes, selecting No or Don’t Know will keep subsequent steps of the DPIA form locked. The remaining sections will only be accessible if the screening decision is changed to Yes or if a review leads to further assessment requirements.

 
 

Who can access a DPIA, and how is access granted? DPIA

You can open and edit a DPIA once you are added to it in a role. Being given access to the DPIA module lets you log a new DPIA, but it does not, on its own, open every existing DPIA. To work on a specific DPIA you must be added to it as an owner, member, screening reviewer, reviewer, approver, attachment reviewer or notified user. Owners and members of a risk, issue, lesson or task also gain edit access when that item is linked to the DPIA, and linking a DPIA to a record of processing activity grants the activity’s people edit access. If you cannot see a DPIA you expect to, ask your Primary Account Administrator (PAA) to add you.

 
 

What does the My DPIAs toggle show? DPIA

The My DPIAs toggle filters the log to the DPIAs you are involved in. It shows the DPIAs where you are the owner, member, screening reviewer, reviewer, approver or notified user, and hides the rest. Turn it off to return to the full list of DPIAs you can access.

 
 

Can I change a DPIA reference number? DPIA

No. Each DPIA is given a unique reference number when it is created, starting with DPIA, and it cannot be edited. The reference stays with the assessment so you can track it and link it to other records.

 
 

What happens when I duplicate a DPIA? DPIA

Duplicating a DPIA creates a copy of the assessment together with its associated risks, issues, lessons and tasks, each labelled with the prefix Copy of. The copy does not carry over notes, attachments, or logged time and cost. Use it to start a new assessment from a similar one without re-entering everything.

 
 

What is the difference between closing and deleting a DPIA? DPIA

Closing a DPIA marks it and its associated risks, issues, lessons and tasks as closed and removes them from the active logs; you can reverse this with Reopen, which restores the associated items (tasks return to Not Started, and risks, issues and lessons return to Open). Deleting a DPIA marks it and its associated items as deleted and removes them from the log. In short, close is a reversible tidy-up, whereas delete is for assessments you no longer need.

 
 

Do the Completion Required By and Next Review Date fields send reminders? DPIA

No. The Completion Required By and Next Review Date fields record your intended dates, but they do not trigger a reminder or an escalation when the date arrives. DPIA notifications are sent for other events, such as a screening reviewer being assigned, a screening answer or status change, a review or approval change, a close or reopen, and being mentioned in a note. Diarise these dates separately if you need a prompt.

 
 

Can I add a data subject type that is not in the list? DPIA

Yes. If the data subject type you need is not in the default list, add it with the +Other function. Any data subject type you add this way becomes available to everyone in your organisation for future assessments, so it only needs adding once.

 
 

Who reviews an attachment on a DPIA? DPIA

Each attachment on a DPIA can be given a single reviewer, along with a review date and any further information. This keeps supporting evidence accountable and helps ensure attachments stay current rather than becoming out of date. You can upload up to five attachments at a time.

 
 

Application Library

Can I link applications in the library with vendors and processing operation asse...

Yes. If your organisation has access to the 9ine Vendor Platform or 9ine Privacy Platform, the Vendor and POA fields are available within the Application Library, allowing you to link applications to the relevant Vendors and Processing Operation Assessments (POAs).

When you select a POA, its title is automatically populated in the Application Library. You can edit the title if required without affecting the original POA.

 
 

What permissions are available in the Application Library? Application Library

There are two permission levels available for the Application Library:

  • Application Library administrator: Can publish, Quickstart, bulk upload, create, edit and delete applications within the Application Library.
  • Authorised User: Can search, preview, review and request access to applications within the Application Library, but cannot create, publish, Quickstart, bulk upload, edit or delete applications.

Permissions are assigned by a 9ine Platform Administrator in User Management.

 
 

How do I create a new application in the Application Library? Application Library

You must be a 9ine Platform Administrator or have Application Library administrator permissions.

Open the Application Library, select New Application in the top-right corner, and complete the application form. Title and Approval Status are mandatory fields.

For detailed guidance, see the Application Library article.

 
 

What technical details should our IT team review when publishing an application? Application Library

Before publishing an application, your IT team should review its technical requirements to ensure it is suitable for your organisation's IT environment. This includes the supported platforms (mobile, desktop and browser), recommended browser, login method and any other technical requirements that may affect deployment, security or user access.

 
 

Can I add applications with age restrictions or specific subject or departmental relevance? Application Library

Yes. You can configure age restrictions, subjects, departments, languages and school sites for an application to help ensure it is available to the appropriate users.

Age restrictions are selected from your organisation's configured age ranges (for example, 4+ to 18+, Staff or Faculty).

 
 

What does the Request button do in the Application Library? Application Library

The Request button allows you to request access to an application that is already available in your organisation's Application Library. Your request is sent to the appropriate administrator for review.

To request a new application that is not yet available in your Application Library, use Application Requests instead.

 
 

How do we enable the Request button for an application?Application Library

Enabling the Request button requires two steps:

  1. A 9ine Platform Administrator must configure one or more email recipients under Application Library in Organisation Profile.
  2. An Application Library administrator must enable the Request button for the application and select one of the configured email recipients.

Once enabled, requests submitted for that application will be emailed to the selected recipient.

 
 

How can I submit a rating or review for an application in the Application Library? Application Library

You can submit a rating and review for an application directly from the application tile or from the application's preview page.

Once submitted, your rating and review will be displayed alongside the application to help other users make informed decisions.

 
 

Are reviews visible to all users within the organisation? Application Library

Yes. Reviews are visible to all users with access to the Application Library within your organisation. Reviews are organisation-specific and are not shared with or visible to users outside your organisation.

 
 

Can I filter or sort reviews by star rating? Application Library

Yes. You can filter reviews by star rating (for example, to display only 5-star or 1-star reviews) and sort them by newest or oldest first.

 
 

What information is displayed with each application's reviews? Application Library

Each application displays the average star rating, total number of reviews and a breakdown of reviews by star rating, giving you a quick overview of user feedback.

 
 

Yes. Each application displays its average star rating and total number of reviews, helping you identify applications that have received positive feedback from users within your organisation.

 
 

For users, 9ine's Application Platform provides access to? Application Library

  • Application Library: Browse a curated repository of approved EdTech applications available in your organisation.
  • Application Requests: Submit requests for new applications to be reviewed and approved by your Application Library Administrators.
 
 

For Application Library Administrators, 9ine's Application Platform provides access to? Application Library

  • Application Library: Maintain an organised, accessible repository of all educational platforms and apps. This feature helps administrators track available resources, evaluate their impact, and access support materials efficiently.
  • Application Requests: Streamline the process of requesting new applications, ensuring that all requests are logged, tracked, and reviewed in a structured manner.
  • Application Directory : A pre-built directory of application templates maintained by 9ine, designed to help Application Library Administrators save time and effort when adding new applications to your organisation's library.
 
 

Can I share our Application Library with people who don't have a 9ine Platform account? Application Library

Yes. A 9ine Platform administrator, Primary Account Administrator (PAA) or Application Library administrator can create a shareable link, which publishes a curated, public version of your Application Library. This allows people such as staff, students, and parents to view selected applications without requiring a 9ine Platform account. 

When creating a shareable link, you choose which applications are included and which information sections visitors can view.

For detailed guidance, see the Application Library article article.

 
 

Only Application Library administrators, Organisation administrators and Primary Account Administrators (PAAs) can create and manage shareable links.

If you don't have the required permissions, contact your 9ine Platform administrator.

 
 

When creating a shareable link, you choose which applications to include and which information sections visitors can view for each application.

Visitors can browse and search the selected applications. The Vendor and POA filters are not available within a shareable link.

For detailed guidance, see the Application Library article article.

 
 

Yes. When creating or editing a shareable link, set the Access Type to Password Protected, then enter your own password or select Generate Password. Passwords must be at least 8 characters long and include at least one number and one special character.

Visitors must enter the password before they can access the shareable link. If Access Type is set to Unrestricted, anyone with the link can access it.

 
 

Yes. From Manage Public View, you can:

  • Edit a shareable link without changing its web address.
  • Archive a shareable link to remove public access immediately.
  • Reopen an archived shareable link so you can make changes and publish it again.
  • Duplicate a shareable link to create a new draft.
  • Delete a shareable link permanently.

For detailed guidance, see the Application Library article article.

 
 

Shareable links do not expire and there is no limit to the number of applications they can include.

A shareable link remains accessible only while:

  • Your organisation is active
  • The shareable link has an Active status

Every visit is recorded for audit purposes, including the date and time of access, together with the visitor's device and browser information. Visitors remain anonymous, so you can see that a shareable link has been accessed, but not who accessed it.

The 9ine Platform does not send notifications when a shareable link is viewed.

 
 

 

Application Directory FAQs

What is the Application Directory, and how is it different from my Application Library? Application Directory 

The Application Directory is 9ine's catalogue of pre-built application templates. It is not a separate module; it is an alternative layout within your Application Library. Your Application Library contains the applications used by your organisation, while the Application Directory contains the templates available to add to your library.

Use the Application Directory to browse applications maintained by 9ine. When you find an application you want to use, you can Quickstart it into your Application Library, where you can review, customise and publish it for your organisation.

For more information, see the Application Directory article.

 
 

Who can access the Application Directory? Application Directory 

Only administrators can access the Application Directory. This includes both 9ine Platform Administrators and users with Application Library administrator permissions. Access is granted by a 9ine Platform Administrator in User Management by enabling the permission to publish, Quickstart, bulk upload, edit and delete items within the Application Library.

Users without this permission can access your organisation's published Application Library but cannot access the Application Directory.

 
 

How do I open the Application Directory? Application Directory 

Open your Application Library, then select the Switch Layout icon to change to the Application Directory view. The Application Directory is an alternative layout within the Application Library, allowing you to browse 9ine's catalogue of pre-built application templates.

 
 

What does Certified mean? Application Directory 

A Certified application has been reviewed by 9ine and meets our certification criteria. Certified applications display a Certified badge on the application tile and can be viewed together using the Certified tab within the Application Directory.

 
 

What happens when I Quickstart an application? Application Directory 

When you Quickstart an application, a copy of the application is added to your Application Library and opened in edit mode. You can then review and customise it to meet your organisation's requirements.

The application is not visible to Authorised Users until it has been Published. If you save your changes without publishing, the application will remain available only to administrators until you publish it.

For step-by-step instructions, see the Application Directory article.

 
 

Why do I see a Request button instead of Quickstart? Application Directory 

Quickstart is only available to organisations with an Application Platform contract. If your organisation does not have an Application Platform contract, or the application is not included within your contract, the tile will display a Request button instead.

Select Request to contact 9ine and request access to the application.

 
 

Why is the Application Directory empty? Application Directory 

If your organisation does not have access to any applications within the Application Directory, the directory will appear empty. This is usually because your organisation does not have an Application Platform contract.

To discuss access to the Application Directory, please contact [email protected].

 
 

Can I edit or delete entries in the directory? Application Directory 

No. Applications within the Application Directory are managed and maintained by 9ine and cannot be edited or deleted by your organisation.

To customise an application, Quickstart it into your Application Library. Once added, you can edit and manage your own copy without affecting the original application in the Application Directory.

 
 

Application Requests (FAQs)

Is Application Requests included in the Application Platform licence? Application...

Is Application Requests included in the Application Platform licence? Application Requests

Yes, Application Requests is included in the Application Platform licence. Organisations can choose to enable or disable this feature alongside the Application Library, or use it as a standalone feature for managing application requests.

 
 

What is the difference between the Request button in the Application Library and Application Requests? Application Requests

The Request button in the Application Library is used to request access to an application that is already available in your organisation's Application Library. Application Requests are used to request a new application that is not yet available in your organisation's Application Library.

In short, use the Request button to request access to an existing application, and use Application Requests to request a new application for your organisation.

 
 

What are the levels of access for Application Requests, and who can approve or reject requests? Application Requests

There are two levels of access for Application Requests:

  • Application Request administrators can view all requests submitted within the organisation and approve, reject, edit and delete them. Access is granted by a 9ine Platform Administrator in User Management by enabling the permission to approve, reject and delete Application Requests.
  • Authorised Users can submit new Application Requests and track the status of their own requests, but they cannot view or manage requests submitted by other users.
 
 

How are administrators notified of new application requests? Application Requests

When a new Application Request is submitted or an existing request is updated, email notifications are sent to the email addresses configured under Request New Application in Organisation Profile.

Application Request administrators can also view and manage all requests within the Application Requests log.

 
 

How do I submit a new application request? Application Requests

Select New Request from either the Application Library or the Application Requests log, then enter the application title and complete the required information across the following steps:

  • Application Request
  • Safety & Privacy
  • Custom Questions

When you have completed all required information, select Save & Request to submit your request.

For detailed guidance, see the Application Requests article.

 
 

How does an administrator approve or reject an application request? Application Requests

Open the Application Requests log, select the three-dot menu for the relevant request, and then choose Approve or Reject. Enter a reason for your decision and confirm your selection.

The requester will be notified of the decision by email and an in-platform notification.

For detailed guidance, see the Application Requests article.

 
 

Do I need to set anything up before staff can use Application Requests? Application Requests

Yes. Before staff can use Application Requests, a 9ine Platform Administrator must configure at least one email recipient under Request New Application in Organisation Profile. These recipients will receive email notifications when new requests are submitted or existing requests are updated.

Until at least one email recipient has been configured, the Application Request administrator permission cannot be enabled.

 
 

What happens after a request is approved? Application Requests

When an Application Request is approved, the requester is notified by email and an in-Platform notification.

The administrator can then either:

  • Create a new Application in the Application Library, or
  • Quickstart the application from the Application Directory if a matching application is available.

The application is not published automatically. It must be reviewed and published in accordance with your organisation's normal application management process.

 
 

 

Vendor Common FAQs

How do I change between the Vendor Assessment and Processing Operation Assessment...

How do I change between the Vendor Assessment and Processing Operation Assessment view? Vendor Platform

Vendor Assessment offers two distinct views: Vendor Assessment and Processing Operation Assessment. In the top-right corner, there is a layout icon that allows you to switch between these views. The platform conveniently remembers the last view you accessed, so if you last viewed the Vendor Assessment, it will be displayed the next time you visit. Likewise, if you switched to the Processing Operation Assessment view, that will be the view shown when you return. You can seamlessly switch between these views based on your preference, and the Platform will retain your selection for future visits. This feature is user-specific, so it only applies to your individual profile.

 
 

What is the difference between vendor and processing operation assessment? Vendor Platform

The Vendor Assessment in the 9ine Platform is designed to centralise key details about each vendor, including trading information, contact details, country of operation, and the ability to attach important contractual documents. This area serves as a comprehensive record of the vendor's profile.

The Processing Operation Assessment (POA), on the other hand, provides a structured form that guides users through specific data processing activities performed by the vendor. It includes steps and questions focused on capturing detailed information about the vendor's data processing practices, risks, and compliance with privacy and safeguarding requirements. Together, they equip schools with insights to make informed, risk-aware decisions regarding their vendors.

 
 

Why is conducting a Vendor Assessment and POA important? Vendor Platform

Vendor assessments are essential to ensure third-party vendors meet your school’s data protection standards and comply with privacy regulations. These assessments help identify risks, confirm adherence to privacy policies, and ensure that data-sharing agreements are appropriate and compliant.

 
 

How do I add a logo to a vendor or processing operation assessment? Vendor Platform

During the new or edit process, you can upload a custom logo for each vendor or POA. You have the option to reset it to the default 9ine Platform logo or replace the logo with a new image at any time.

 
 

Vendor Dashboard FAQs

...

Vendor Assessment FAQs

...

What is a Processing Operation Assessment (POA)? Vendor Assessment

A Processing Operation Assessment (POA) records and assesses how a Vendor processes personal data.

Each Vendor can have multiple Processing Operation Assessments (POAs), with each POA relating to a specific processing activity. A POA always belongs to a single Vendor.

 
 

Who can access a Vendor or Processing Operation Assessment? Vendor Assessment

Access to Vendors and Processing Operation Assessments (POAs) is permission-based.

Having access to the Vendor Platform allows you to create Vendors and POAs, but you can only access records you have been assigned to.

The available roles are:

  • Vendor: Owner, Members, Notified Users and Attachment Reviewer.
  • Processing Operation Assessment (POA): Owner, Members, Notified Users, Attachment Reviewer, Reviewers and Approver.

The Owner can edit and delete the record. All other assigned users can edit the record but cannot delete it.

If a Vendor is linked to a Data Protection Impact Assessment (DPIA), Record of Processing (RoP) or Record of Processing Activity (RoPA), users with permission to access the linked record can also access the Vendor and its associated POAs.

If you require access to a record, contact your organisation's 9ine Platform administrator.

 
 

Do I need a licence to use Vendor Assessment? Vendor Assessment

Yes. Vendor Assessment and Processing Operation Assessments (POAs) are available as part of the 9ine Privacy Platform and 9ine Vendor Platform.

If you cannot access these features, your organisation may not have the required licence or you may not have permission to use them. Contact your organisation's 9ine Platform administrator for assistance.

 
 

Which fields are required to create a vendor? Vendor Assessment

Only two fields are mandatory:

  • Legal Name
  • Owner

All other information, such as trading name, address, contacts, review date and linked records, is optional and can be added later.

 
 

What are the six steps of a Processing Operation Assessment (POA)? Vendor Assessment

A Processing Operation Assessment (POA) is completed across six steps:

  • Processing Operation Description
  • Processing Compliance
  • Safeguarding
  • Security and Systems
  • Assessment Summary
  • Review & Approval

You must save your answers as you progress between steps, and you can return to any step at any time.

 
 

How is a Processing Operation Assessment (POA) reviewed and approved? Vendor Assessment

The Review & Approval step is used to assign one or more Reviewers and an Approver. Each assignment records a status of Open or Closed.

A Processing Operation Assessment (POA) does not have a Submit action. The review and approval process is complete when all required review and approval statuses have been set to Closed.

Each change is recorded as a revision, providing a complete history of the review and approval process.

 
 

What happens when I close a Vendor or Processing Operation Assessment? Vendor Assessment

Closing a Vendor or Processing Operation Assessment (POA) makes the inactive and removes it from your logs. Associated Risks, Issues, Lessons and Tasks are also closed, but nothing is deleted.

You can reopen the Vendor or POA at any time. Once reopened, users with edit permission can continue making changes.

Vendors and POAs use two statuses only: Open and Closed.

 
 

Will I receive reminders when a review date is due? Vendor Assessment

No. Vendors and Processing Operation Assessments (POAs) do not send scheduled review reminders. This feature will be developed in the near future.

Instead, you receive an in-Platform notification when a review date is first added and again whenever it is changed.

Keeping the Next Review Date up to date helps you manage when assessments should be reviewed.

 
 

Yes.

A Vendor can be linked to:

  • Data Protection Impact Assessments (DPIAs)
  • Records of Processing (RoPs)
  • Records of Processing Activities (RoPAs)
  • An Application

A Processing Operation Assessment (POA) can be linked to:

  • Risks
  • Issues
  • Tasks
  • Lessons
  • An Application

Some linking options require the relevant platform licence and appropriate user permissions. If an option is unavailable, contact your organisation's 9ine Platform Administrator.

 
 

How do I export Vendors or Processing Operation Assessments (POAs)? Vendor Assessment

To export your data, select Download from the Vendor or Processing Operation Assessment (POA) log.

You can export:

  • A basic Excel report
  • An advanced Excel report
  • a Word document for an individual Processing Operation Assessment (POA)

The export is generated in the background, allowing you to continue working. You will receive both an in-Platform notification and an email when it is ready.

The exported file reflects the filters currently applied to the log, so apply any required filters before requesting the export.

 
 

Can two Vendors or Processing Operation Assessments (POAs) have the same name? Vendor Assessment

Yes. Vendor and Processing Operation Assessment (POA) names do not have to be unique, so duplicate names are permitted.

This allows you to duplicate existing records and create similar assessments without first changing the original name.

 
 

Why can't I submit a Vendor for an assessment from 9ine? Vendor Assessment

The Submit action is available only if your organisation has the required Vendor Platform licence.

When you submit a Vendor, a request is sent to the 9ine Privacy and Support team for review. The Vendor remains editable while the assessment is in progress.

If you do not see the Submit option, contact your Primary Account Administrator (PAA) to confirm your organisation's licence.

 
 

Creating a new Vendor, duplicating a record and creating a Processing Operation Assessment (POA) are available only while your organisation's licence is active and within its allocated limits.

Linking a Vendor to a Data Protection Impact Assessment (DPIA), Record of Processing (RoP), Record of Processing Activity (RoPA) or publishing to the Application Library also requires the relevant platform licence and the appropriate user permissions.

If an option is unavailable, contact your organisation's 9ine Platform administrator.

 
 

What is a Transfer Impact Assessment (TIA)? Vendor Assessment

A Transfer Impact Assessment (TIA) is completed when personal data is transferred to another country.
A separate assessment is completed for each destination country, recording:

  • The transfer mechanism
  • The safeguards in place
  • Whether the destination country provides an adequate level of legal protection
  • Any human rights considerations

This information helps you assess and manage the risks associated with transferring personal data internationally.

 
 

What is the Assessment Summary step used for? Vendor Assessment

The Assessment Summary step is used to summarise the processing activities and record the overall risk assessment for the Processing Operation Assessment (POA).
From this step, you can also create associated:

  • Risks
  • Issues
  • Lessons
  • Tasks

This helps ensure any actions arising from the assessment are managed alongside the assessment itself.

 
 

How do review and approval work for a Processing Operation Assessment (POA)? Vendor Assessment

The Review & Approval step is used to complete the review and approval process for a Processing Operation Assessment (POA).

Assign one or more reviewers and an approver. Each person records their review or approval status.

Review and approval use two statuses only:

  • Open
  • Closed

A Processing Operation Assessment (POA) does not have a Submit action. The review and approval process is complete when all required review and approval statuses have been set to Closed.

Whenever a reviewer, approver, status or review date is changed, the affected users receive an email and in-Platform notification, and a new revision is recorded.

You can view the history of every review and approval cycle from the POA's Revisions.

 
 

What statuses are available for Vendors and Processing Operation Assessments (POAs)? Vendor Assessment

Vendors and Processing Operation Assessments (POAs) use two statuses:

  • Open
  • Closed

A Closed record is inaccessible. To make changes, the record must first be reopened to Open. Only users with permission to edit the record can then make changes.

 
 

Processing Operation Assessment FAQs

How do I use my toggle for the processing operation assessment log? The “My POAs”...

How do I use my toggle for the processing operation assessment log? Processing Operation Assessment

The My POAs feature is available when you switch to the Processing Operation Assessment log view. This view is not available on the Vendor Details processing operation assessment log.

 
 

Vendor Library FAQ

What is the purpose of the vendor library? The Vendor Library is a resource for s...

Contract Management FAQs

Who can access Contract Management? Contract Management

Access to Contract Management is included with your organisation's Contract Platform licence. Within a licensed organisation, a 9ine Platform administrator grants access through User Management. Access to Contract Management does not automatically give users access to every contract. Users can only access contracts they have been given permission to view.

For detailed guidance, see the Contract Management user guide.

 
 

Why can I only see some of my organisation's contracts? Contract Management

You can only access contracts that you created, have been assigned to, or have been granted permission to view. Access to Contract Management does not automatically give you access to every contract within your organisation. Each contract has its own permissions, so different users may have access to different contracts.

For more information about contract permissions, see the Contract Management user guide.

 
 

What are the contract roles, and what can each do? Contract Management

Each contract has one Owner and can have multiple Members, Notified Users and Attachment Reviewers. Requester and Approver are informational fields that record who requested and approved the contract.

The available roles are:

  • Owner: The person responsible for the contract. Every contract must have one Owner, who can edit and delete the contract.
  • Member: Can edit the contract but cannot delete it. There is no limit to the number of Members.
  • Notified User: Receives notifications about the contract and can edit the record. There is no limit to the number of Notified Users.
  • Requester: Records who requested the contract. This can be a 9ine Platform user or someone who does not have a 9ine Platform account.
  • Approver: Records who approved the contract. This can be a 9ine Platform user or someone who does not have a 9ine Platform account.
  • Attachment Reviewer: Reviews attachments assigned to them.

A user cannot be both the Owner and a Member of the same contract.

 
 

What is the difference between Contract Cost and Calculated Cost? Contract Management

Contract Cost is the overall value you enter for the contract. Calculated Cost is automatically calculated from the financial entries associated with the contract. Calculated Cost includes the total value of all financial entries that are not marked as Reference Only, providing a running total of your committed spend.

Use Contract Cost to record the expected value of the contract, and Calculated Cost to compare it with the value that has actually been recorded through the contract's financial entries.

 
 

What does Reference Only mean on a financial entry? Contract Management

Reference Only marks a financial entry as informational and excludes it from the Calculated Cost. Use Reference Only for amounts you want to record without including them in your committed spend, such as projected future costs or entries awaiting approval.

If you remove the Reference Only setting, the financial entry is automatically included in the Calculated Cost.

 
 

How do I record a contract in a foreign currency? Contract Management

Select the contract's currency during the Finance step. If it differs from your organisation's default currency, you can review and, if required, update the Currency Exchange Rate. The exchange rate is populated using live market data, but you can override it by entering a fixed exchange rate if required. This allows contracts in different currencies to be reported consistently using your organisation's default currency.

 
 

What are the contract statuses? Contract Management

A contract can have one of the following statuses:

  • Active
  • Pending
  • Archived
  • Pending Termination
  • Cancelled

Contracts with an Archived or Cancelled status are removed from the active contract logs but are retained for audit and record-keeping purposes.

Licence Status (Active, Inactive or Expired) relates to your organisation's Contract Platform licence and determines whether the platform is available. It is separate from an individual contract's status.

 
 

How do I edit an archived or cancelled contract? Contract Management

You cannot edit a contract while it has an Archived or Cancelled status.

To make changes:

  • Reopen an Archived or Cancelled contract.

Once the contract has been returned to an editable status, you can make changes as normal.

 
 

Does duplicating a contract copy everything? Contract Management

No. When you duplicate a contract, a new contract is created with the prefix Copy of.

The following information is copied:

  • Financial records
  • Risks
  • Issues
  • Lessons
  • Tasks

The following information is not copied:

  • Notes
  • Attachments
  • Logged Time
  • Logged Cost

Duplicating a financial entry works differently. It does not copy:

  • Linked items
  • Purchase Order Number
  • Invoice Number
  • Start Date
  • End Date
  • Attachments
  • Payment Due Date
 
 

What do the My Contract and My Finance toggles do? Contract Management

The My Contracts toggle filters the Contract Log to display only contracts where you are the Owner, a Member or a Notified User. Contracts with an Archived or Cancelled status are not included.

The My Finance toggle provides the same functionality within the Financial Information layout, displaying only the financial entries associated with your contracts.

Use these toggles to quickly focus on the contracts and financial information relevant to you.

 
 

How do I export the Contract Log or Financial Information log? Contract Management

To export the data, click Download from the Contract Log or Financial Information log. The export is generated in the background, and you will receive both an in-Platform notification and an email when it is ready.

The exported file reflects the filters currently applied to the log, so apply any required filters before requesting the export.

 
 

How do I compare contracts side by side? Contract Management

To compare contracts, open Contract Analysis from the Contract Log. You can compare up to five contracts side by side.

Contract Analysis displays key information for each selected contract, including status, contract term, key dates, Contract Cost, Calculated Cost and payment status, helping you compare contracts and support procurement or renewal decisions.

 
 

9ine Academy FAQs

 Who can access 9ine Academy? 9ine Academy

Access to 9ine Academy depends on your organisation’s subscription. Everyone in an organisation with a subscription can browse the catalogue, take learning content and download their own certificates.

If 9ine Academy is not available to you and you believe it should be, ask your organisation’s 9ine Platform Administrator to review your access.

 
 

What types of learning content are available? 9ine Academy

9ine Academy includes six types of learning content: Video, Quiz, Assessment, Course, Training and Webinar.

A learning content may contain a single piece of content or a sequence of steps combining videos, quizzes and downloadable resources.

Review rationale: Kept the content types as a simple enumeration and retained the explanation that content can combine different content, because this helps users understand what the categories represent.

 
 

How do I find a specific learning content? 9ine Academy

Use Search, Filter or Sort to narrow the 9ine Academy catalogue.

Search looks across information about the learning content, including its title, type, level, description, learning objectives, prerequisites, audience, topics, modules, country, data protection law, release date and status. Filter lets you narrow the catalogue using the same kinds of criteria, including whether content is CPD Certified. Sort lets you order content by release date or title.

Your filter selection is saved, so the catalogue opens with the same filters the next time you visit.

 
 

What do the New, Updated, Coming Soon and CPD Certified labels mean? 9ine Academy

New: The learning content was added recently.

Updated: The learning content has been revised since it was first released.

Coming Soon: The item has been announced but cannot be started yet. You can preview it, but Start is not available until it is released.

CPD Certified: The item counts towards Continuing Professional Development (CPD).

 
 

Can I save a learning content to come back to later? 9ine Academy

Yes. Mark the learning content as a favourite and it is saved to the Favourites tab in My Academy.

Adding content to Favourites does not start it or affect your progress.

 
 

Where can I see the learning content I have started or completed? 9ine Academy

My Academy shows your own learning and becomes available once you have started at least one learning content.

The In Progress, Completed, Favourites and Certificates tabs are displayed only while the My Academy toggle is turned on.

It contains four tabs:

In Progress: Content you have started but not completed.

Completed: Content you have finished.

Favourites: Content you have saved for later.

Certificates: Completed content and the certificates you have earned.

 
 

Do I have to watch a video all the way through? 9ine Academy

Only if the video step is mandatory.

You must watch a mandatory video in full before you can move on. Optional video steps can be skipped without preventing you from completing the learning content.

Your position in a video is saved, so you can leave part way through and continue from the same point later.

 
 

What happens if I do not pass a quiz? 9ine Academy

You can take the quiz again.

Retake Quiz lets you make another attempt. There is no limit on the number of attempts and no waiting period between them. Retake Quiz is unavailable once you have scored 100%.

If the quiz is a mandatory step, you must reach the pass mark before you can continue to the next step.

 
 

Can I review my quiz answers? 9ine Academy

Yes. Review Answers shows each question as correct or incorrect, together with your grade and the pass mark.

The Platform does not keep a history of individual quiz attempts, so the review shows your most recent attempt.

 
 

What happens if I leave a quiz before submitting an answer? 9ine Academy

You are warned before leaving, and only an answer you have not submitted is lost.

Answers you have already submitted are saved, so leaving part way through does not make you lose the whole quiz.

 
 

What happens to my progress if a learning content is updated? 9ine Academy

Your existing progress is kept, and the updated version is offered separately.

Start Over begins the updated version from the beginning. Until you choose it, your progress on the version you originally started remains unchanged.

 
 

How do I download my certificate? 9ine Academy

You can download certificates from the Certificates tab in My Academy or from the learning content once you have completed it.

A learning content can award a certificate for an individual step and a main certificate for completing the content as a whole. You can download them individually or use Download All where more than one is available. Certificates are PDF files, and content marked CPD Certified produces a CPD certificate.

 
 

Why is the main certificate not available to download? 9ine Academy

The main certificate is unavailable if you have not yet completed the learning content or if the content is not configured to award one.

Certificates for individual steps may become available before the main certificate, so it is possible to download a step certificate while the content is still in progress.

If you have completed the content and expect a main certificate to be available, ask your organisation’s 9ine Platform Administrator to review it.

 
 

 Do my certificates expire? 9ine Academy

No. A certificate is not removed and your learning content does not stop being Completed because a validity date has passed.

Where a validity date is set, it is recorded against your completion and appears in the Academy report as evidence of how current your learning is. The Platform does not use the date to expire the certificate or send an expiry reminder.

 
 

Who creates the learning content in 9ine Academy? 9ine Academy

9ine creates and maintains the learning content in 9ine Academy across data privacy, cyber security, IT and Artificial Intelligence (AI).

Your organisation does not need to create or maintain the content. The learning content available to you depend on your organisation’s 9ine Academy subscription.

 
 

What happens to my learning if content is removed from the catalogue? 9ine Academy

You keep your learning record. If content you have started or completed is removed from the catalogue, your copy is retained with your progress, results and any certificate you have earned.

The removed item is no longer available for other users to start.

 
 

Does 9ine Academy learning count towards CPD? 9ine Academy

Yes, where the learning content is marked CPD Certified.

Continuing Professional Development (CPD) certified content is labelled in the catalogue and can be found using the CPD filter. Completing one produces a CPD certificate rather than a standard certificate.

 
 

Can I see how users in my organisation are progressing? 9ine Academy

Yes, if you are an Administrator in your organisation.

The Academy Report shows each user’s learning, including the content type and title, the user, video and quiz progress, start, completion, last accessed and validity dates, overall status and whether a certificate is available. You can search, filter, sort and set a date range, and download an individual user’s certificate.

When you select Download for the report, it is generated in the background. You receive an email and an in-Platform notification with a download link when it is ready.

If the Academy Report is not available to you and you believe it should be, ask your organisation’s 9ine Platform Administrator to review your access.