Searching documents. These results are alphaZ document templates. If you are looking for guidance on a subject rather than a template, search the knowledge base.
Search alphaZ documents
Products meeting the search criteria
Data protection is simpler than it sounds once you know what personal data you hold. Start with the guidance, fill in one register, write the privacy notice from it, and use the rest of the toolkit as..
The personal data register is the record of processing, and it is the first thing looked at when data protection is reviewed. This one keeps a row per category of data and has room to say where AI too..
Some organisations think about personal data by activity rather than by category, and need to show who is responsible for each one. This register records processing that way, with the impact assessmen..
When I audit personnel files I am checking the data is held in line with data protection. This form is marked confidential and has a data-retention prompt built in, so each record is compliant from th..
When I audit personnel records, I want one place that tells me where each employee's data is held and what has been checked. This register is that overview, and it doubles as a data-protection retenti..
A short health questionnaire at the right moment tells you whether someone needs support or an adjustment to do a job safely. This form asks the questions plainly and keeps the answers as the confiden..
In an emergency you need someone's next-of-kin details to hand and correct. This form captures up to three emergency contacts per employee and carries a retention note, so the data is there when it ma..
Pre-employment screening is where a lot of risk is caught or missed, this form can help you keep a consistent record of what was checked. This form collects information on employees - identity, histor..
A useful form template to help you complete screening checks before hiring new employees. The form assesses areas such as; right-to-work, background checks, references, driver checks, medical and addi..
For data protection you have to know what personal data you hold, where it sits, who can see it and how it is protected. This matrix maps that out, and it is the first thing worth having when someone ..
Any supplier that handles personal data for you needs a written agreement, and that includes the AI services it uses. This form records what is processed, where, by whom and under what safeguards, wit..
A request about personal data can be for a copy, a correction, erasure or any of the other rights, and the clock starts once identity is confirmed. This form logs the type of request, the due date and..
When personal data is lost, sent to the wrong person or accessed without authority, the facts needed to decide whether to report it have to be gathered quickly. This form asks for them in the order yo..
Some processing needs thinking through before it starts, and AI tools and software that score, rank or filter people are high on that list. This assessment works through the need, the processing, cons..
A register row is fine for most processing, but a complex or higher risk activity deserves a full description. This form gives one activity the space it needs, including any AI use and automated decis..
When data protection is looked at during an audit, the questions follow a familiar list: the record of processing, retention, notices, training, impact assessments, rights, security and breaches. This..
A data protection policy is the statement you hand to a customer, a tender panel or a new starter when they ask whether you are safe with personal data. This one is written to be shared openly and sta..
A privacy notice has to tell people what you collect, why, who sees it and what they can do about it, in words they understand. This one explains each of the rights in plain English and gives you the ..
A website privacy notice only has to cover what happens on the website, but it has to be right about it. This one prompts you to check the cookie wording against your own site before you publish, so t..
Retention is where good intentions go wrong, because copies turn up in backups, inboxes and AI tools long after the live record has gone. This policy states how retention periods are decided and that ..
When a breach happens people need to know straight away that it has to be reported internally, and what the organisation will do next. This policy says that plainly, and tells anyone affected what to ..
People have more rights over their data than just asking for a copy, and every one of them comes with the same deadline. This policy tells them how to ask and what will happen, for access and for the ..
Where special category or criminal offence data is processed there is more to record, and a spreadsheet makes it easier to keep track. This workbook holds the register and the transfers, requests, bre..
This is the procedure that holds the data protection arrangements together. It covers retention, breaches and access requests in full, so the separate policies on those subjects become optional, and i..
Auditing personal data starts with plain questions: what do you hold, why, who sees it, where is it, how long do you keep it. This checklist asks those, and asks whether any of it goes into an AI tool..
A data protection audit covers the whole arrangement, not only the register: policies, training, impact assessments, rights, transfers, security and breaches. This checklist sets those out as audit qu..