TS-RDC-06
Trust & Stewardship
Risk, Data & Compliance
CORE
Compliance
v2.9.7
GDPR accountability & DPIA log
Assesses a systematic approach to GDPR compliance, ensuring all new or changed data processing activities are screened for risk, full Data Protection Impact Assessments (DPIAs) are conducted where required, and a formal log is maintained to demonstrate accountability. This rigorous oversight embodies the Islamic principle of muhasabah (accountability) and the imperative of sadd al-dhara'i (blocking the means to harm) by proactively identifying and mitigating risks to safeguard privacy.
Compliance 6
-
Documented Data Protection PolicyDocumentation Essential
-
Appointed DPO (where Art. 37 applies) or independent Data Protection LeadGovernance Essential
-
Regular staff training on data handling and DPIA scenariosTraining Essential
-
DPIA screening checklist for all new/changed processingProcess Essential
-
Documented DPIA process (consultation, risk scoring, Art. 36 triggers)Process Essential
-
Comprehensive log of screenings/DPIAs with ROPA linkagesMonitoring Essential
Good 2
-
Privacy Impact Assessments (PIAs) for all significant projectsExcellence High
-
Annual board review of DPIA logLeadership High
Better 3
-
DPIA outcomes drive 'privacy by design' controlsOperations High
-
Alignment with ICO Children's Code where applicableCompliance High
-
Quarterly lessons-learned reviewsContinuous Improvement Medium
Related Criteria
Version
2.9.7
2025-11-05
Discussion (1)
Administrator
2026-03-07 11:07:51.693135
📋 **Version updated: 1.0.0 → 2.9.7** **Changes:** Updated islamic_references from mizan-297.json
Sign in to post a comment.