Data Protection & Article 32

CareVerity ECM & Care Compliance System with CareVerity Training Academy.

Data Protection & Article 32 Compliance

Operational security controls, registers, audit trails and evidence records for confidentiality, integrity, availability, resilience and traceability. Demo records only; do not enter real personal data.

UK GDPR Article 32 evidence
Overall status
86%
Controls visible
12
Open actions
7
Overdue reviews
1
Personal, health, staff, service user, NHS, key safe, DBS, payroll and safeguarding data must not be exported without authorised permission and lawful reason.

Operational Article 32 Control Centre

This area demonstrates how CareVerity enforces Article 32 controls through permission gates, system settings, locked records, evidence registers and audit events.

Operational controls, not policy text
Controls
Not policy-only

The module shows enforceable gates for access, exports, journals, transfers, training and backups.

Permissions
Role restricted

Care coordinators, general admins, HR, finance, care workers, family users and auditors see different access levels.

Traceability
Always audited

Restricted data views, downloads, exports, tag actions, emergency access and permission changes create audit records.

Evidence
Register based

Backup tests, supplier reviews, risk actions, breach records, secure transfers and training are held as evidence records.

Live control and evidence map
System controlApplies toEnforcement behaviourEvidence producedAudit event
Restricted field gateKey safe, NHS number, DBS, NI, payroll, safeguarding and medication fieldsChecks role, visit allocation, time window and manager authorisation before displayRestricted field access recordrestricted field viewed / denied
Role permission guardAll modules and action buttonsControls view, create, edit, approve, archive, print, download and export actionsRole matrix and permission reviewpermission changed / failed access attempt
Working-hours lockoutOffice/admin usersBlocks access outside approved schedule unless emergency access is approvedAccess schedule and emergency request recordoutside-hours login blocked / emergency access used
Export approval gateReports, client/staff files, invoices and audit logsRequires role permission, lawful reason, manager approval where sensitiveExport register and approval statusreport exported / export denied
Secure transfer workflowExternal sharing to LA, NHS/ICB, professionals and familiesRequires recipient, organisation, lawful basis, data category and secure methodSecure transfer logsecure transfer created / sent
Journal lock and addendumClient Journal / Communication LogLocks original entry after saving and allows correction only by addendumImmutable journal record and response threadjournal entry created / addendum added
Backup and restore evidenceDatabase, files and audit logsRecords encrypted backup, restore test, result, corrective action and sign-offBackup and restore registerbackup tested / restore tested
Supplier due diligence gateHosting and data processor servicesRequires DPA, contract, sub-processors, security measures and review dateSupplier register and approval decisionsupplier approved / review overdue
Training access blockStaff and office usersBlocks restricted access until data protection/cyber training is complete where requiredTraining tracker and certificate evidencetraining completed / access blocked
Incident response workflowData breach, cyber and confidentiality incidentsCaptures risk assessment, ICO/NHS/LA decisions, lessons and corrective actionsBreach/incident registerincident recorded / manager sign-off

Article 32 compliance dashboard

Status badges show whether each Article 32 control is complete, in progress, due soon, overdue, missing or requiring manager review.

Encryption controls

Complete

Application, documents, backups and secure transfer placeholders visible

Role-based access

Complete

20 role profiles with view/create/edit/approve/export/download controls

Restricted fields

Complete

Service user, staff, payroll, DBS, key safe and safeguarding restrictions flagged

Audit logs

Complete

Restricted access, exports, journals, permissions, backups and incidents logged

Backup testing

Due soon

Monthly restore evidence required by 15 Jun 2026

Restore testing

Complete

Latest demo restore test passed with evidence placeholder

Business continuity testing

In progress

Manual rota and visit log exercise has one open action

Staff training

In progress

28/31 demo staff completed data protection and cyber refresher

Supplier due diligence

Manager review required

One hosting review action awaits System Owner sign-off

Risk register

Complete

Cyber, data loss, key safe and mobile device risks are owned and reviewed

Incident response

Complete

Breach register includes ICO/NHS/LA decision prompts and lessons learned

Access reviews

Overdue

Quarterly permission review needs Registered Manager sign-off

Article 32 control sections

Visible operational surfaces required by the uploaded Article 32 annex.

Encryption, anonymisation and pseudonymisation

Encryption flags, report anonymisation, pseudonymised exports, demo data warnings

Confidentiality, integrity, availability and resilience

RBAC, restricted fields, continuity controls, backups and system status evidence

Backup and restore

Backup test log, restore evidence, corrective actions and manager sign-off

Testing and evaluation

Cyber review, access review, supplier review, vulnerability scan placeholders

Secure transfer and access controls

Lawful basis, recipient, secure transfer method, approval and audit log

Role-based permissions

View, create, edit, approve, delete, archive, export, print, download, mobile and emergency access

Audit trail and traceability

Who accessed or changed data, old/new values, reason, device and audit reference

Risk register

Unauthorised access, breach, ransomware, outage, wrong recipient and mobile loss risks

Supplier / data processor controls

DPA, contract, hosting location, subprocessors, MFA, backup and incident response checks

Staff training and confidentiality

Training, certificate, refresher due, sign-off and access block until completion

Breach / incident response

Incident details, risk assessment, ICO/NHS/LA decisions, lessons and corrective action

Evidence register

Article 32, DSPT, audit, transfer, training, supplier and backup evidence pack

Encryption / anonymisation controls

Security, anonymisation and demo-data safeguards for reports, files, backups and exports.

Encryption, pseudonymisation and demo mode controls
ControlStatusEvidence / behaviour
Encryption enabled placeholderEnabledSystem-wide security control flag
Database encryption placeholderEnabledManaged database encryption at rest placeholder
Document/file encryption placeholderEnabledCare plans, staff files and evidence documents flagged
Secure HTTPS/TLS placeholderEnabledAll web traffic must use secure TLS in production
VPN/secure access placeholderConfiguredOffice/admin access restricted by role and location/IP placeholder
Encrypted backups placeholderEnabledBackups marked encrypted with restore testing evidence
Pseudonymisation option for reportsAvailableSenior reports can hide direct identifiers
Anonymised reports optionAvailableGovernance exports can use anonymised aggregate data
Demo/test data flagEnabledPrototype surfaces clearly use fake demo records
No real personal data in demo modeRequiredReal service user, NHS, DBS, bank and key safe data must not be entered

Data protection principles

Checklist demonstrating UK GDPR data protection principles in the app workflow.

Principle evidence checklist
PrincipleCareVerity controlStatus
Data obtained fairly and lawfullyConsent/lawful basis placeholders on client, staff, finance and transfer recordsComplete
Data used for specified purposesModule permissions and secure transfer reason fieldsComplete
Data minimisedPseudonymised/anonymised report options and limited task sharingIn progress
Data accurate and up to dateReview dates, addendum process and audit historyComplete
Data not kept longer than necessaryRetention/archive settings placeholder and review actionsIn progress
Data protected against unauthorised access, loss or damageRBAC, restricted fields, backups, BCP, access hours and audit trailComplete
Processing only under authorised instructionsSupplier due diligence, DPA status, role controls and manager approvalsManager review required

Role-based access matrix

Action-level controls are visible for every office, care, family and auditor role. Admin staff are not granted full access by default.

ViewCreateEditApproveDeleteArchiveExportPrintDownloadMobile accessRestricted accessEmergency access
Default Article 32 role controls
RoleClient filesStaff filesFinance/payrollRestricted fieldsAccess mode
System OwnerFull accessFull accessFull accessRestricted by roleOffice schedule controlled
Registered ManagerFull accessFull accessFull accessRestricted by roleOffice schedule controlled
Deputy ManagerAdd and edit all recordsAdd and edit all recordsManager approval requiredRestricted by roleOffice schedule controlled
Operations ManagerFull accessFull accessFull accessLimited / no restricted accessOffice schedule controlled
Service ManagerFull accessFull accessFull accessLimited / no restricted accessOffice schedule controlled
Branch ManagerFull accessFull accessFull accessLimited / no restricted accessOffice schedule controlled
Care CoordinatorAdd and edit all recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Senior Care CoordinatorAdd and edit all recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Rota CoordinatorAdd and edit all recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
On-call CoordinatorAdd and edit all recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Field Care SupervisorAdd and edit all recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Senior Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Permanent Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
One-off / Emergency Cover Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Admin ManagerAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
Senior AdministratorAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
General AdministratorAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
Office AdministratorAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
Reception / Front DeskAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
Records AdministratorAdd onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
HR ManagerNo accessRestricted sensitive accessNo accessRestricted by roleOffice schedule controlled
HR AdministratorNo accessRestricted sensitive accessNo accessRestricted by roleOffice schedule controlled
Recruitment ManagerNo accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Recruitment AdministratorNo accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Training ManagerNo accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Training AdministratorNo accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Training CoordinatorNo accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Quality Assurance ManagerRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Quality / Compliance OfficerRestricted sensitive accessView onlyNo accessRestricted by roleOffice schedule controlled
CQC Evidence LeadRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Audit OfficerRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Governance OfficerRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Data Protection LeadRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Information Governance LeadRestricted sensitive accessView onlyNo accessLimited / no restricted accessOffice schedule controlled
Finance ManagerView onlyNo accessAdd and edit all recordsRestricted by roleOffice schedule controlled
Finance AdministratorView onlyNo accessAdd and edit all recordsRestricted by roleOffice schedule controlled
Payroll ManagerNo accessNo accessRestricted sensitive accessRestricted by roleOffice schedule controlled
Payroll OfficerNo accessNo accessRestricted sensitive accessRestricted by roleOffice schedule controlled
Invoicing OfficerView onlyNo accessAdd and edit all recordsLimited / no restricted accessOffice schedule controlled
Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Care Worker / Mobile UserAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Outreach Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Additional Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Additional Outreach Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Float Pool Care WorkerAdd and edit own recordsNo accessNo accessLimited / no restricted accessMobile/portal only
Medication-Authorised Care WorkerAdd and edit own recordsNo accessNo accessRestricted by roleMobile/portal only
Medication LeadView onlyNo accessNo accessRestricted by roleOffice schedule controlled
Safeguarding LeadRestricted sensitive accessView onlyNo accessRestricted by roleOffice schedule controlled
Moving and Handling LeadAdd and edit own recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Infection Control LeadAdd and edit own recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Health and Safety LeadAdd and edit own recordsNo accessNo accessLimited / no restricted accessOffice schedule controlled
Auditor / Inspector Read-OnlyView onlyView onlyNo accessLimited / no restricted accessRead-only/time-limited
Read-Only Auditor / Inspector ViewView onlyView onlyNo accessLimited / no restricted accessRead-only/time-limited
Family Portal UserNo accessNo accessNo accessLimited / no restricted accessMobile/portal only
NHS / ICB Read-OnlyView onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled
Local Authority Read-OnlyView onlyView onlyNo accessLimited / no restricted accessOffice schedule controlled

Service user restricted fields

Only authorised roles should see these fields, and each view is audited.

Service user sensitive field rules
Restricted fieldAuthorised visibility
NHS numberRegistered Manager, authorised coordinator, finance where invoice evidence is needed
Key safe codeAllocated care worker during visit window, coordinator, manager
Medical historyCare team and manager where role-permitted
Medication riskMedication Lead, manager, authorised care team
AllergiesCare team where required for safe care
Mental capacityManager, care coordinator and authorised professionals
Safeguarding recordsRegistered Manager, Safeguarding Lead, authorised quality staff
Mental health notesRestricted care and safeguarding roles
Family dispute notesManager-only unless specifically authorised
Care plan documentsCare team visible by permission and mobile approval
Risk assessmentsCare team visible by permission and mobile approval
Hospital discharge recordsManager, care coordinator, authorised clinical/care roles
GP/NHS correspondenceManager, care coordinator, authorised professional communication roles
Funding/source of paymentManager, finance, authorised administrator

Staff restricted fields

Staff personal, HR, DBS and payroll fields are separated from general admin access.

Staff sensitive field rules
Restricted fieldAuthorised visibility
National Insurance numberPayroll Officer, Finance Administrator, Registered Manager, authorised HR
DBS certificate numberRegistered Manager, HR Administrator, authorised recruitment staff
Right-to-work documentsRegistered Manager, HR Administrator, Recruitment Administrator
Passport/IDRegistered Manager, HR Administrator, Recruitment Administrator
Bank detailsPayroll Officer, Finance Administrator, Registered Manager
Payroll detailsPayroll Officer, Finance Administrator, Registered Manager
Disciplinary recordsRegistered Manager, authorised HR only
HR warningsRegistered Manager, authorised HR only
Sickness/absence recordsRegistered Manager, HR Administrator, line manager where authorised
ReferencesRegistered Manager, HR Administrator, Recruitment Administrator
Employment historyRegistered Manager, HR Administrator, Recruitment Administrator
Interview recordsRegistered Manager, Recruitment Administrator, authorised HR

Working hours / access time control

Office/admin access can be limited to working hours. Emergency access requires reason, manager approval, duration and audit log.

Access restricted outside authorised working hours. Please contact the Registered Manager if urgent access is required.
Admin staff access schedules
RoleAllowed daysStartEndAccess location ruleEmergency access
Care CoordinatorMonday to Friday09:0017:00Office access only unless remote access is authorisedManager approval required
Senior AdministratorMonday to Friday08:0017:00Office access only unless remote access is authorisedManager approval required
General AdministratorMonday to Friday08:0017:00Office access only unless remote access is authorisedManager approval required
HR AdministratorMonday to Friday08:0017:00Office access only unless remote access is authorisedManager approval required
Recruitment AdministratorMonday to Friday08:0017:00Office access only unless remote access is authorisedManager approval required
Training AdministratorMonday to Friday08:0017:00Office access only unless remote access is authorisedManager approval required
Finance AdministratorMonday to Friday09:0017:00Finance office only unless approvedManager approval required
Payroll OfficerMonday to Friday payroll weeks09:0017:00Finance office onlyPayroll manager approval required
Emergency reason
Required before access
Manager approval
Required
Duration
Time-limited
Audit log
Always recorded

Audit trail / traceability

Traceability of who accessed or changed data, old/new values, affected records, reasons and device/IP placeholders.

Article 32 audit log
Audit refDate/timeUserRoleActionOld valueNew valueAffected recordReason/commentIP/device
LOGIN-DEMO-00116 May 2026 08:58Demo Care CoordinatorCare CoordinatorLoginN/ASuccessful loginOffice accountNormal accessOffice laptop/IP placeholder
FAIL-DEMO-00216 May 2026 07:40Demo General AdministratorGeneral AdministratorFailed loginN/ABlocked outside authorised hoursUser accountOut-of-hours accessOffice laptop/IP placeholder
REST-DEMO-00316 May 2026 09:10Demo Registered ManagerRegistered ManagerRestricted field viewedHiddenNHS number viewedDemo Service User 101Commissioner evidence reviewManaged browser
KEY-DEMO-00416 May 2026 09:14Demo Care Worker ACare Worker / Mobile UserKey safe viewedHiddenVisible during allocated visit windowDemo Service User 101Check-in supportMobile app
DBS-DEMO-00516 May 2026 09:30Demo HR AdministratorHR AdministratorDBS record viewedHiddenCertificate number displayedDemo Care Worker ARecruitment file auditOffice laptop/IP placeholder
PAY-DEMO-00616 May 2026 09:45Demo Payroll OfficerPayroll OfficerPayroll field viewedHiddenPayroll number displayedDemo Care Worker APayroll run evidenceFinance workstation
JRN-DEMO-00716 May 2026 10:15Demo Care CoordinatorCare CoordinatorJournal entry taggedNo tagsManager and Quality / Compliance Officer taggedJRN-DEMO-0005Social services response requiredOffice laptop/IP placeholder
PERM-DEMO-00816 May 2026 10:45Demo System OwnerSystem OwnerPermissions changedView onlyRestricted sensitive accessMedication LeadMedication review role updateOffice laptop/IP placeholder
EXP-DEMO-00916 May 2026 11:00Demo Compliance OfficerCompliance / Quality OfficerReport exportedNo exportArticle 32 report PDF placeholderDP-ART32-REPORTManager review packOffice laptop/IP placeholder
BACK-DEMO-01016 May 2026 11:30Demo System OwnerSystem OwnerBackup testedUntestedRestore successfulBACKUP-DEMO-002Monthly resilience evidenceAdmin console

Journal immutability controls

Client Journal / Communication Log entries are immutable after saving.

Original entry
Cannot be edited
Deletion
Not permitted
Corrections
Addendum only
Attachments
Upload/view audited
Tagged actions
Completion audited

Backup & Restore register

Backup and restore evidence for availability and resilience.

Backup and restore evidence
Backup typeSystem/data coveredFrequencyBackup date/timeEncryptedLocationRestore test dateResultIssuesCorrective actionNext testSigned off by
Daily encrypted backupCareVerity databaseDaily16 May 2026 23:00YesUK cloud region placeholder15 May 2026PassNoneN/A15 Jun 2026Demo System Owner
Document repository backupCare plans, HR files, evidence uploadsDaily16 May 2026 23:20YesEncrypted object storage placeholder15 May 2026PassMetadata review noteDocument screenshot evidence15 Jun 2026Demo Registered Manager
Audit log backupSystem audit trailHourly16 May 2026 23:45YesImmutable log storage placeholder15 May 2026PassNoneN/A15 Jun 2026Demo System Owner

Business continuity controls

Availability and resilience evidence for system outage, manual rota, manual visit logging and high-risk service users.

Continuity and resilience controls
ControlStatusEvidenceOwnerRAG
Emergency rota availableCompleteManual rota export held for high-risk callsDemo Care CoordinatorGreen
Offline visit log templateCompletePrintable manual visit log placeholderDemo Senior AdministratorGreen
Manual MAR/medication contingencyManager reviewMedication policy link and paper MAR contingency placeholderMedication LeadAmber
High-risk service user priority listCompleteHigh-risk calls and welfare-sensitive visits identifiedRegistered ManagerGreen
Emergency contact listCompleteOffice, on-call, LA/NHS and family escalation contacts placeholderDeputy ManagerGreen
System outage processIn progressPhone tree and manual check-in process testedQuality OfficerAmber
Cloud system status placeholderConfiguredSupplier status link placeholderSystem OwnerBlue
Data restore processCompleteRestore runbook and sign-off fields visibleSystem OwnerGreen

Continuity dashboard alerts

Alerts for controls that require manager attention.

Backup overdueNo
Restore test overdueNo
Business continuity test overdueNo, action due soon
Supplier review overdueOne manager review required
High-risk continuity warningMedication contingency review

Testing & Evaluation register

Regular testing and evaluation register for technical and organisational measures.

Testing and evaluation evidence
Test typeDateCompleted byResultIssue foundRisk ratingCorrective actionOwnerDue dateCompletion dateManager sign-off
Cyber security review15 May 2026Demo Compliance OfficerPass with actionsPatch evidence dueMediumUpload supplier security summarySystem Owner31 May 2026OpenPending
Access review01 May 2026Demo System OwnerAction requiredDormant account flaggedLowDisable account and record approvalRegistered Manager20 May 2026OpenPending
Permission review01 May 2026Demo Registered ManagerPassNoneLowNext quarterly reviewSystem Owner01 Aug 2026ScheduledSigned
Backup test15 May 2026Demo System OwnerPassNoneLowNext monthly restoreSystem Owner15 Jun 2026CompleteSigned
Business continuity test13 May 2026Demo Registered ManagerAction requiredMessage owner unclearMediumUpdate communication checklistCare Coordinator13 Jun 2026OpenPending
Supplier review15 May 2026Demo Senior AdministratorManager reviewPen test summary awaitedMediumRequest annual evidenceSystem Owner30 Jun 2026OpenPending
Vulnerability scan placeholder12 May 2026Demo IT LeadNo critical issuesTwo medium itemsMediumSupplier remediation planSystem Owner31 May 2026In progressPending
Antivirus/endpoint review placeholder10 May 2026Demo IT LeadPassNoneLowContinue monthly reviewSystem Owner10 Jun 2026CompleteSigned

Secure Transfer controls

Any external sharing/export records recipient, lawful basis, data categories, transfer method, encryption and approval.

Only authorised users may export personal data. Exports must be necessary, proportionate, recorded and sent using approved secure methods.
Secure transfer log
Transfer refRecipientReasonLawful basisData categoriesSecure methodEncryptionManager approvalDate/time sentSent byAudit log
TRN-DEMO-001Demo Local AuthorityPackage reviewPublic task / legitimate interest placeholderCare notes and package summarySecure email / portal placeholderYesYes16 May 2026 10:20Demo Care CoordinatorLogged
TRN-DEMO-002Demo NHS ICBInvoice evidenceContract / care provision placeholderVisit times and invoice evidenceApproved secure transfer placeholderYesYes16 May 2026 11:05Demo Finance AdministratorManager review
TRN-DEMO-003Demo Family RepresentativeApproved family updateConsent / family portal permission placeholderSelected visit update onlyFamily portal messageN/ANo16 May 2026 12:15Demo Care CoordinatorLogged

Supplier / Hosting Due Diligence register

Data processor and hosting checks for DPA, contracts, hosting location, encryption, backups, MFA, subprocessors and incident timescales.

Supplier and processor controls
SupplierServiceData processedSpecial category dataHosting locationEncryptionBackupsAccess controlsMFABreach timescaleSub-processorsDPA/contractReview dateStatusApproved by
Demo Cloud Hosting LtdSecure application hostingCare, staff, rota and audit recordsYesUK region placeholderAt rest and in transitDaily encryptedRBAC and MFAYes24 hoursDemo subprocessors listedYes15 Nov 2026ApprovedDemo System Owner
Demo Email Gateway LtdSecure email routingProfessional communications metadataPotentiallyUK/EU placeholderTLSProvider managedAdmin onlyYes24 hoursDemo anti-spam processorYes01 Sep 2026Approved with actionDemo Compliance Officer
Demo PDF Export ServiceReport and invoice document generationExported report contentYesUK region placeholderEncrypted temporary filesNo persistent storageToken-basedYes12 hoursNone declaredDPA pending review30 Jun 2026Manager review requiredDemo System Owner

Data Protection / Cyber Risk Register

Data protection and cyber risk register with likelihood, impact, controls, owner and review date.

Risk register
Risk titleDescriptionLikelihoodImpactRatingControl measuresOwnerReview dateAction requiredStatus
Unauthorised access to key safe codeKey safe visible outside allocated visit windowMediumHighHighVisit-window restriction, audit log, manager reviewRegistered Manager15 Jun 2026Review mobile visibility rulesOpen
Wrong recipient emailProfessional update sent to wrong addressMediumMediumMediumRecipient confirmation, secure transfer log, trainingCare Coordinator30 Jun 2026Add double-check promptIn progress
Ransomware / malwareEndpoint compromise affecting office accessLowHighMediumMFA, endpoint protection, backups, restore testsSystem Owner15 Jun 2026Upload endpoint review evidenceOpen
Backup failureBackups unavailable during restoreLowHighMediumEncrypted backup monitoring and monthly restore testSystem Owner15 Jun 2026Next test scheduledControlled
Staff access misuseAdmin views records outside role needMediumHighHighRBAC, access schedules, restricted field audit, manager reviewRegistered Manager01 Jun 2026Quarterly permissions reviewOpen
Mobile phone lossCare worker loses device with app sessionMediumMediumMediumNo personal storage, app timeout, report lost device processField Supervisor30 Jun 2026BYOD reviewIn progress
Supplier failureHosting supplier outage affects ECMLowHighMediumBCP, status page, manual rota, data restore processSystem Owner15 Nov 2026Supplier annual reviewControlled

Staff Data Protection / Cyber Security training tracker

Restricted system access can be blocked until staff complete required data protection and cyber training.

Training tracker
StaffRoleTraining completedCompletion dateCertificate uploadedRefresher dueScore/passManager sign-offAccess blocked
Demo Care Worker ACare Worker / Mobile UserData Protection / Confidentiality / Cyber Security12 May 2026Yes12 May 2027Passed 92%Demo Registered ManagerNo
Demo Care CoordinatorCare CoordinatorConfidentiality, secure email, RBAC, journal/audit rules10 May 2026Yes10 May 2027Passed 96%Demo Registered ManagerNo
Demo General AdministratorGeneral AdministratorSafe email, phishing, restricted data handling02 May 2026Yes02 May 2027Passed 88%Demo Senior AdministratorNo
Demo Finance AdministratorFinance AdministratorSecure invoice evidence and transfer controls15 Apr 2026Yes15 Apr 2027Passed 91%Demo Registered ManagerNo
Demo New StarterCare Worker / Mobile UserAwaiting refresherNot completedNoBefore system accessPendingDemo Training AdminYes

Incident Response / Data Breach register

Breach and security incidents include ICO, NHS/LA, safeguarding and individual notification decisions.

Breach and incident records
ReferenceDiscoveredOccurredReported byAffected personData involvedBreach typeImmediate actionRisk assessmentICO requiredNHS/LA notifiedSafeguardingIndividuals notifiedOutcomeLessonsCorrective actionSign-off
IG-DEMO-INC-00114 May 2026 10:2014 May 2026 09:55Demo Care CoordinatorDemo service user recordLimited visit scheduling dataMisdirected internal messageMessage recalled and manager notifiedLow likelihood of harmNoNoNoNoClosedRecipient checking refresherOffice prompt addedDemo Registered Manager
IG-DEMO-INC-00212 May 2026 16:4012 May 2026 16:30Demo Field SupervisorDemo staff memberMobile device access tokenLost device reportSession disabled and device marked lostLow after immediate lockNoNoNoNoManager reviewLost device process workedBYOD checklist refreshDemo System Owner
IG-DEMO-INC-00309 May 2026 08:1509 May 2026 08:00Demo HR AdministratorDemo staff fileRecruitment document attachmentAttachment upload errorRestricted document moved to correct staff fileMediumManager decision pendingNoNoNoOpenUpload verification neededAudit and add sign-off stepDemo Registered Manager

Article 32 Evidence Register

Evidence pack index for Article 32, DSPT, audit exports, secure transfer logs and cyber security reviews.

Evidence register
Evidence categoryEvidence sourceDemo statusOwnerReview dateStatus
Encryption policyAccess Control Policy and Cyber Security ArrangementsUploaded placeholderDemo System Owner01 May 2027Active
Staff training evidenceTraining tracker and certificates28 completed; 3 dueTraining Administrator12 May 2027In progress
Backup test recordsBACKUP-DEMO-001 / BACKUP-DEMO-002Latest passedSystem Owner15 Jun 2026Complete
Restore test recordsRESTORE-DEMO-001Evidence placeholder retainedSystem Owner15 Jun 2026Complete
Business continuity test recordsBCP-DEMO-001Action plan openRegistered Manager13 Jun 2026Manager review
Supplier due diligenceSupplier registerDPA/contract status trackedSenior Administrator15 Nov 2026In progress
Risk registerDP-RISK-REGISTERReviewed monthlyCompliance Officer15 Jun 2026Active
Incident logBreach / incident registerICO/NHS/LA decision promptsRegistered ManagerOngoingActive
Audit log exportAUDIT-ART32-DEMOExport placeholderSystem Owner31 May 2026Available
Secure transfer logTRN-DEMO registerRecipient and lawful basis recordedCare CoordinatorOngoingActive
DSPT evidenceDSPT certificate / publication reference2025-26 version 8 placeholderRegistered Manager30 Jun 2027Complete
Cyber security reviewCyber action planMFA, device security and review evidenceCompliance Officer30 Jun 2026In progress

Compliance report exports

Export placeholders are role restricted and every export is audited.

Article 32 report export centre
ReportPermitted rolesFormatRestrictionAudit requirement
Article 32 Compliance ReportSystem Owner / Registered Manager / Compliance OfficerPDF placeholderManager approval requiredExport audited
Access Control ReportSystem Owner / Registered ManagerExcel/PDF placeholderRestrictedExport audited
Backup & Restore ReportSystem Owner / Registered Manager / Compliance OfficerPDF placeholderManager sign-offExport audited
Supplier Due Diligence ReportSystem Owner / Registered Manager / Senior AdministratorExcel/PDF placeholderManager approval requiredExport audited
Incident / Breach ReportRegistered Manager / Compliance OfficerPDF placeholderRestricted sensitiveExport audited
Staff Training ReportHR / Training / Registered ManagerExcel/PDF placeholderStaff file restrictedExport audited
Audit Log ReportSystem Owner / Registered Manager / Auditor where authorisedCSV/PDF placeholderTime-limited accessExport audited
Risk Register ReportRegistered Manager / Compliance OfficerPDF placeholderManager reviewExport audited
Secure Transfer ReportSystem Owner / Registered Manager / Compliance OfficerCSV/PDF placeholderRestrictedExport audited