This is the procedure that holds the data protection arrangements together. It covers retention, breaches and access requests in full, so the separate policies on those subjects become optional, and it sets out how AI tools are approved before personal data goes near them.
This policy-procedure template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Procedure number and title
- Information-classification
- Version
- Page number / total pages
An amendment record is included so changes between issues can be tracked.
alphaZ documents - beautifully designed, tried and tested policy-procedure templates. No junk, jargon or unnecessary content. Simple and usable policy-procedure templates
developed over 25 years through practical use in the real world.
Further guidance on data protection and AI:
Download this policy-procedure template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This procedure is also included in the GDPR / Data Protection Toolkit, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like hands-on help putting your data protection procedure, registers and privacy notices in place, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Data Protection Policy Procedure Template
The PP-1-16 Data Protection Policy Procedure is the internal procedure for managing and protecting personal data. It sets out responsibilities, how personal data is recorded, reviewed and retained, the lawful basis and special category conditions, processing and transfers, the use of AI and automated decisions, security, requests from individuals, data breaches and complaints.
It contains the policy content itself, so it is complete on its own. The standalone retention, breach and subject access request policies are optional add-ons for organisations that want a separate publicly shareable document on one of those subjects.
What the Procedure Covers
- Documents referred to in this procedure - a key that maps each term used (personal data register, privacy notices, access request record, data breach record, impact assessment, processing agreement) to the document you use, so the procedure works whichever register or form you choose
- Statement of Intent and Responsibilities for Data Protection
- Management of Personal Data - the personal data register as the record of processing activities (RoPA)
- Personal Data Review and Retention (Data Retention Policy) - retention decisions, every copy including provider and AI copies, and deletion
- Lawful Basis / Consent and Special Category Data / Sensitive Personal Data - including the conditions and the policy document for special category and criminal offence data
- Personal Data Processing / Transfer and Where we act as a Processor
- Use of AI and Automated Decisions - approving AI tools before personal data is used with them, and what meaningful human review of a decision involves
- Data and Information Security
- Transparency and Data Subject Access (Subject Access Request Policy) - handling all the rights, not only access
- Data Breach Procedure (Data Breach Policy) and Data Protection Complaints
Sections that replace a standalone policy carry the policy name in brackets, so questionnaire wording can be found straight from the contents page.
Policy and Procedure in One
With the F-IMS24 Personal Data Register or another personal data register, the procedure also serves as the policy document an organisation holds for processing special category and criminal offence data. If you want standalone public versions, the P-91 Data Retention Policy, P-92 Data Breach Policy and P-93 Personal Data Subject Access Request Policy are available separately and must say the same as the procedure.
Who Needs a Data Protection Procedure?
Any organisation that wants its data protection arrangements written down as a controlled document - for staff to follow, for management review and to show at audit. It suits smaller organisations that need one procedure covering the whole subject rather than a stack of separate policies.
Included in the GDPR / Data Protection Toolkit
This procedure is part of the GDPR / Data Protection Toolkit - the registers, forms, policies, procedure and guidance for documenting how you collect and process personal data, in one download.
Works with the Data Protection Policy and Privacy Policy
The procedure is the internal document. The P-25 Data Protection Policy is the public assurance statement, and the P-26 Privacy Policy is the privacy notice given to the people whose data you hold.
Would you rather we prepared it for you?
Our Personal Data Register and Privacy Notice Preparation service works through the personal data your organisation holds with you, including the AI tools in use, and prepares the register and privacy notice so they describe what actually happens to that data.
Personal Data Register and Privacy Notice Preparation