
Data Protection & Article 32
CareVerity ECM & Care Compliance System with CareVerity Training Academy.
Data Protection & Article 32 Compliance
Operational security controls, registers, audit trails and evidence records for confidentiality, integrity, availability, resilience and traceability. Demo records only; do not enter real personal data.
Operational Article 32 Control Centre
This area demonstrates how CareVerity enforces Article 32 controls through permission gates, system settings, locked records, evidence registers and audit events.
The module shows enforceable gates for access, exports, journals, transfers, training and backups.
Care coordinators, general admins, HR, finance, care workers, family users and auditors see different access levels.
Restricted data views, downloads, exports, tag actions, emergency access and permission changes create audit records.
Backup tests, supplier reviews, risk actions, breach records, secure transfers and training are held as evidence records.
| System control | Applies to | Enforcement behaviour | Evidence produced | Audit event |
|---|---|---|---|---|
| Restricted field gate | Key safe, NHS number, DBS, NI, payroll, safeguarding and medication fields | Checks role, visit allocation, time window and manager authorisation before display | Restricted field access record | restricted field viewed / denied |
| Role permission guard | All modules and action buttons | Controls view, create, edit, approve, archive, print, download and export actions | Role matrix and permission review | permission changed / failed access attempt |
| Working-hours lockout | Office/admin users | Blocks access outside approved schedule unless emergency access is approved | Access schedule and emergency request record | outside-hours login blocked / emergency access used |
| Export approval gate | Reports, client/staff files, invoices and audit logs | Requires role permission, lawful reason, manager approval where sensitive | Export register and approval status | report exported / export denied |
| Secure transfer workflow | External sharing to LA, NHS/ICB, professionals and families | Requires recipient, organisation, lawful basis, data category and secure method | Secure transfer log | secure transfer created / sent |
| Journal lock and addendum | Client Journal / Communication Log | Locks original entry after saving and allows correction only by addendum | Immutable journal record and response thread | journal entry created / addendum added |
| Backup and restore evidence | Database, files and audit logs | Records encrypted backup, restore test, result, corrective action and sign-off | Backup and restore register | backup tested / restore tested |
| Supplier due diligence gate | Hosting and data processor services | Requires DPA, contract, sub-processors, security measures and review date | Supplier register and approval decision | supplier approved / review overdue |
| Training access block | Staff and office users | Blocks restricted access until data protection/cyber training is complete where required | Training tracker and certificate evidence | training completed / access blocked |
| Incident response workflow | Data breach, cyber and confidentiality incidents | Captures risk assessment, ICO/NHS/LA decisions, lessons and corrective actions | Breach/incident register | incident recorded / manager sign-off |
Article 32 compliance dashboard
Status badges show whether each Article 32 control is complete, in progress, due soon, overdue, missing or requiring manager review.
Encryption controls
CompleteApplication, documents, backups and secure transfer placeholders visible
Role-based access
Complete20 role profiles with view/create/edit/approve/export/download controls
Restricted fields
CompleteService user, staff, payroll, DBS, key safe and safeguarding restrictions flagged
Audit logs
CompleteRestricted access, exports, journals, permissions, backups and incidents logged
Backup testing
Due soonMonthly restore evidence required by 15 Jun 2026
Restore testing
CompleteLatest demo restore test passed with evidence placeholder
Business continuity testing
In progressManual rota and visit log exercise has one open action
Staff training
In progress28/31 demo staff completed data protection and cyber refresher
Supplier due diligence
Manager review requiredOne hosting review action awaits System Owner sign-off
Risk register
CompleteCyber, data loss, key safe and mobile device risks are owned and reviewed
Incident response
CompleteBreach register includes ICO/NHS/LA decision prompts and lessons learned
Access reviews
OverdueQuarterly permission review needs Registered Manager sign-off
Article 32 control sections
Visible operational surfaces required by the uploaded Article 32 annex.
Encryption flags, report anonymisation, pseudonymised exports, demo data warnings
RBAC, restricted fields, continuity controls, backups and system status evidence
Backup test log, restore evidence, corrective actions and manager sign-off
Cyber review, access review, supplier review, vulnerability scan placeholders
Lawful basis, recipient, secure transfer method, approval and audit log
View, create, edit, approve, delete, archive, export, print, download, mobile and emergency access
Who accessed or changed data, old/new values, reason, device and audit reference
Unauthorised access, breach, ransomware, outage, wrong recipient and mobile loss risks
DPA, contract, hosting location, subprocessors, MFA, backup and incident response checks
Training, certificate, refresher due, sign-off and access block until completion
Incident details, risk assessment, ICO/NHS/LA decisions, lessons and corrective action
Article 32, DSPT, audit, transfer, training, supplier and backup evidence pack
Encryption / anonymisation controls
Security, anonymisation and demo-data safeguards for reports, files, backups and exports.
| Control | Status | Evidence / behaviour |
|---|---|---|
| Encryption enabled placeholder | Enabled | System-wide security control flag |
| Database encryption placeholder | Enabled | Managed database encryption at rest placeholder |
| Document/file encryption placeholder | Enabled | Care plans, staff files and evidence documents flagged |
| Secure HTTPS/TLS placeholder | Enabled | All web traffic must use secure TLS in production |
| VPN/secure access placeholder | Configured | Office/admin access restricted by role and location/IP placeholder |
| Encrypted backups placeholder | Enabled | Backups marked encrypted with restore testing evidence |
| Pseudonymisation option for reports | Available | Senior reports can hide direct identifiers |
| Anonymised reports option | Available | Governance exports can use anonymised aggregate data |
| Demo/test data flag | Enabled | Prototype surfaces clearly use fake demo records |
| No real personal data in demo mode | Required | Real service user, NHS, DBS, bank and key safe data must not be entered |
Data protection principles
Checklist demonstrating UK GDPR data protection principles in the app workflow.
| Principle | CareVerity control | Status |
|---|---|---|
| Data obtained fairly and lawfully | Consent/lawful basis placeholders on client, staff, finance and transfer records | Complete |
| Data used for specified purposes | Module permissions and secure transfer reason fields | Complete |
| Data minimised | Pseudonymised/anonymised report options and limited task sharing | In progress |
| Data accurate and up to date | Review dates, addendum process and audit history | Complete |
| Data not kept longer than necessary | Retention/archive settings placeholder and review actions | In progress |
| Data protected against unauthorised access, loss or damage | RBAC, restricted fields, backups, BCP, access hours and audit trail | Complete |
| Processing only under authorised instructions | Supplier due diligence, DPA status, role controls and manager approvals | Manager review required |
Role-based access matrix
Action-level controls are visible for every office, care, family and auditor role. Admin staff are not granted full access by default.
| Role | Client files | Staff files | Finance/payroll | Restricted fields | Access mode |
|---|---|---|---|---|---|
| System Owner | Full access | Full access | Full access | Restricted by role | Office schedule controlled |
| Registered Manager | Full access | Full access | Full access | Restricted by role | Office schedule controlled |
| Deputy Manager | Add and edit all records | Add and edit all records | Manager approval required | Restricted by role | Office schedule controlled |
| Operations Manager | Full access | Full access | Full access | Limited / no restricted access | Office schedule controlled |
| Service Manager | Full access | Full access | Full access | Limited / no restricted access | Office schedule controlled |
| Branch Manager | Full access | Full access | Full access | Limited / no restricted access | Office schedule controlled |
| Care Coordinator | Add and edit all records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Senior Care Coordinator | Add and edit all records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Rota Coordinator | Add and edit all records | No access | No access | Limited / no restricted access | Office schedule controlled |
| On-call Coordinator | Add and edit all records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Field Care Supervisor | Add and edit all records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Senior Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Permanent Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| One-off / Emergency Cover Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Admin Manager | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| Senior Administrator | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| General Administrator | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| Office Administrator | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| Reception / Front Desk | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| Records Administrator | Add only | View only | No access | Limited / no restricted access | Office schedule controlled |
| HR Manager | No access | Restricted sensitive access | No access | Restricted by role | Office schedule controlled |
| HR Administrator | No access | Restricted sensitive access | No access | Restricted by role | Office schedule controlled |
| Recruitment Manager | No access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Recruitment Administrator | No access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Training Manager | No access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Training Administrator | No access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Training Coordinator | No access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Quality Assurance Manager | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Quality / Compliance Officer | Restricted sensitive access | View only | No access | Restricted by role | Office schedule controlled |
| CQC Evidence Lead | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Audit Officer | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Governance Officer | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Data Protection Lead | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Information Governance Lead | Restricted sensitive access | View only | No access | Limited / no restricted access | Office schedule controlled |
| Finance Manager | View only | No access | Add and edit all records | Restricted by role | Office schedule controlled |
| Finance Administrator | View only | No access | Add and edit all records | Restricted by role | Office schedule controlled |
| Payroll Manager | No access | No access | Restricted sensitive access | Restricted by role | Office schedule controlled |
| Payroll Officer | No access | No access | Restricted sensitive access | Restricted by role | Office schedule controlled |
| Invoicing Officer | View only | No access | Add and edit all records | Limited / no restricted access | Office schedule controlled |
| Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Care Worker / Mobile User | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Outreach Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Additional Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Additional Outreach Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Float Pool Care Worker | Add and edit own records | No access | No access | Limited / no restricted access | Mobile/portal only |
| Medication-Authorised Care Worker | Add and edit own records | No access | No access | Restricted by role | Mobile/portal only |
| Medication Lead | View only | No access | No access | Restricted by role | Office schedule controlled |
| Safeguarding Lead | Restricted sensitive access | View only | No access | Restricted by role | Office schedule controlled |
| Moving and Handling Lead | Add and edit own records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Infection Control Lead | Add and edit own records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Health and Safety Lead | Add and edit own records | No access | No access | Limited / no restricted access | Office schedule controlled |
| Auditor / Inspector Read-Only | View only | View only | No access | Limited / no restricted access | Read-only/time-limited |
| Read-Only Auditor / Inspector View | View only | View only | No access | Limited / no restricted access | Read-only/time-limited |
| Family Portal User | No access | No access | No access | Limited / no restricted access | Mobile/portal only |
| NHS / ICB Read-Only | View only | View only | No access | Limited / no restricted access | Office schedule controlled |
| Local Authority Read-Only | View only | View only | No access | Limited / no restricted access | Office schedule controlled |
Service user restricted fields
Only authorised roles should see these fields, and each view is audited.
| Restricted field | Authorised visibility |
|---|---|
| NHS number | Registered Manager, authorised coordinator, finance where invoice evidence is needed |
| Key safe code | Allocated care worker during visit window, coordinator, manager |
| Medical history | Care team and manager where role-permitted |
| Medication risk | Medication Lead, manager, authorised care team |
| Allergies | Care team where required for safe care |
| Mental capacity | Manager, care coordinator and authorised professionals |
| Safeguarding records | Registered Manager, Safeguarding Lead, authorised quality staff |
| Mental health notes | Restricted care and safeguarding roles |
| Family dispute notes | Manager-only unless specifically authorised |
| Care plan documents | Care team visible by permission and mobile approval |
| Risk assessments | Care team visible by permission and mobile approval |
| Hospital discharge records | Manager, care coordinator, authorised clinical/care roles |
| GP/NHS correspondence | Manager, care coordinator, authorised professional communication roles |
| Funding/source of payment | Manager, finance, authorised administrator |
Staff restricted fields
Staff personal, HR, DBS and payroll fields are separated from general admin access.
| Restricted field | Authorised visibility |
|---|---|
| National Insurance number | Payroll Officer, Finance Administrator, Registered Manager, authorised HR |
| DBS certificate number | Registered Manager, HR Administrator, authorised recruitment staff |
| Right-to-work documents | Registered Manager, HR Administrator, Recruitment Administrator |
| Passport/ID | Registered Manager, HR Administrator, Recruitment Administrator |
| Bank details | Payroll Officer, Finance Administrator, Registered Manager |
| Payroll details | Payroll Officer, Finance Administrator, Registered Manager |
| Disciplinary records | Registered Manager, authorised HR only |
| HR warnings | Registered Manager, authorised HR only |
| Sickness/absence records | Registered Manager, HR Administrator, line manager where authorised |
| References | Registered Manager, HR Administrator, Recruitment Administrator |
| Employment history | Registered Manager, HR Administrator, Recruitment Administrator |
| Interview records | Registered Manager, Recruitment Administrator, authorised HR |
Working hours / access time control
Office/admin access can be limited to working hours. Emergency access requires reason, manager approval, duration and audit log.
| Role | Allowed days | Start | End | Access location rule | Emergency access |
|---|---|---|---|---|---|
| Care Coordinator | Monday to Friday | 09:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| Senior Administrator | Monday to Friday | 08:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| General Administrator | Monday to Friday | 08:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| HR Administrator | Monday to Friday | 08:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| Recruitment Administrator | Monday to Friday | 08:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| Training Administrator | Monday to Friday | 08:00 | 17:00 | Office access only unless remote access is authorised | Manager approval required |
| Finance Administrator | Monday to Friday | 09:00 | 17:00 | Finance office only unless approved | Manager approval required |
| Payroll Officer | Monday to Friday payroll weeks | 09:00 | 17:00 | Finance office only | Payroll manager approval required |
Audit trail / traceability
Traceability of who accessed or changed data, old/new values, affected records, reasons and device/IP placeholders.
| Audit ref | Date/time | User | Role | Action | Old value | New value | Affected record | Reason/comment | IP/device |
|---|---|---|---|---|---|---|---|---|---|
| LOGIN-DEMO-001 | 16 May 2026 08:58 | Demo Care Coordinator | Care Coordinator | Login | N/A | Successful login | Office account | Normal access | Office laptop/IP placeholder |
| FAIL-DEMO-002 | 16 May 2026 07:40 | Demo General Administrator | General Administrator | Failed login | N/A | Blocked outside authorised hours | User account | Out-of-hours access | Office laptop/IP placeholder |
| REST-DEMO-003 | 16 May 2026 09:10 | Demo Registered Manager | Registered Manager | Restricted field viewed | Hidden | NHS number viewed | Demo Service User 101 | Commissioner evidence review | Managed browser |
| KEY-DEMO-004 | 16 May 2026 09:14 | Demo Care Worker A | Care Worker / Mobile User | Key safe viewed | Hidden | Visible during allocated visit window | Demo Service User 101 | Check-in support | Mobile app |
| DBS-DEMO-005 | 16 May 2026 09:30 | Demo HR Administrator | HR Administrator | DBS record viewed | Hidden | Certificate number displayed | Demo Care Worker A | Recruitment file audit | Office laptop/IP placeholder |
| PAY-DEMO-006 | 16 May 2026 09:45 | Demo Payroll Officer | Payroll Officer | Payroll field viewed | Hidden | Payroll number displayed | Demo Care Worker A | Payroll run evidence | Finance workstation |
| JRN-DEMO-007 | 16 May 2026 10:15 | Demo Care Coordinator | Care Coordinator | Journal entry tagged | No tags | Manager and Quality / Compliance Officer tagged | JRN-DEMO-0005 | Social services response required | Office laptop/IP placeholder |
| PERM-DEMO-008 | 16 May 2026 10:45 | Demo System Owner | System Owner | Permissions changed | View only | Restricted sensitive access | Medication Lead | Medication review role update | Office laptop/IP placeholder |
| EXP-DEMO-009 | 16 May 2026 11:00 | Demo Compliance Officer | Compliance / Quality Officer | Report exported | No export | Article 32 report PDF placeholder | DP-ART32-REPORT | Manager review pack | Office laptop/IP placeholder |
| BACK-DEMO-010 | 16 May 2026 11:30 | Demo System Owner | System Owner | Backup tested | Untested | Restore successful | BACKUP-DEMO-002 | Monthly resilience evidence | Admin console |
Journal immutability controls
Client Journal / Communication Log entries are immutable after saving.
Backup & Restore register
Backup and restore evidence for availability and resilience.
| Backup type | System/data covered | Frequency | Backup date/time | Encrypted | Location | Restore test date | Result | Issues | Corrective action | Next test | Signed off by |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Daily encrypted backup | CareVerity database | Daily | 16 May 2026 23:00 | Yes | UK cloud region placeholder | 15 May 2026 | Pass | None | N/A | 15 Jun 2026 | Demo System Owner |
| Document repository backup | Care plans, HR files, evidence uploads | Daily | 16 May 2026 23:20 | Yes | Encrypted object storage placeholder | 15 May 2026 | Pass | Metadata review note | Document screenshot evidence | 15 Jun 2026 | Demo Registered Manager |
| Audit log backup | System audit trail | Hourly | 16 May 2026 23:45 | Yes | Immutable log storage placeholder | 15 May 2026 | Pass | None | N/A | 15 Jun 2026 | Demo System Owner |
Business continuity controls
Availability and resilience evidence for system outage, manual rota, manual visit logging and high-risk service users.
| Control | Status | Evidence | Owner | RAG |
|---|---|---|---|---|
| Emergency rota available | Complete | Manual rota export held for high-risk calls | Demo Care Coordinator | Green |
| Offline visit log template | Complete | Printable manual visit log placeholder | Demo Senior Administrator | Green |
| Manual MAR/medication contingency | Manager review | Medication policy link and paper MAR contingency placeholder | Medication Lead | Amber |
| High-risk service user priority list | Complete | High-risk calls and welfare-sensitive visits identified | Registered Manager | Green |
| Emergency contact list | Complete | Office, on-call, LA/NHS and family escalation contacts placeholder | Deputy Manager | Green |
| System outage process | In progress | Phone tree and manual check-in process tested | Quality Officer | Amber |
| Cloud system status placeholder | Configured | Supplier status link placeholder | System Owner | Blue |
| Data restore process | Complete | Restore runbook and sign-off fields visible | System Owner | Green |
Continuity dashboard alerts
Alerts for controls that require manager attention.
Testing & Evaluation register
Regular testing and evaluation register for technical and organisational measures.
| Test type | Date | Completed by | Result | Issue found | Risk rating | Corrective action | Owner | Due date | Completion date | Manager sign-off |
|---|---|---|---|---|---|---|---|---|---|---|
| Cyber security review | 15 May 2026 | Demo Compliance Officer | Pass with actions | Patch evidence due | Medium | Upload supplier security summary | System Owner | 31 May 2026 | Open | Pending |
| Access review | 01 May 2026 | Demo System Owner | Action required | Dormant account flagged | Low | Disable account and record approval | Registered Manager | 20 May 2026 | Open | Pending |
| Permission review | 01 May 2026 | Demo Registered Manager | Pass | None | Low | Next quarterly review | System Owner | 01 Aug 2026 | Scheduled | Signed |
| Backup test | 15 May 2026 | Demo System Owner | Pass | None | Low | Next monthly restore | System Owner | 15 Jun 2026 | Complete | Signed |
| Business continuity test | 13 May 2026 | Demo Registered Manager | Action required | Message owner unclear | Medium | Update communication checklist | Care Coordinator | 13 Jun 2026 | Open | Pending |
| Supplier review | 15 May 2026 | Demo Senior Administrator | Manager review | Pen test summary awaited | Medium | Request annual evidence | System Owner | 30 Jun 2026 | Open | Pending |
| Vulnerability scan placeholder | 12 May 2026 | Demo IT Lead | No critical issues | Two medium items | Medium | Supplier remediation plan | System Owner | 31 May 2026 | In progress | Pending |
| Antivirus/endpoint review placeholder | 10 May 2026 | Demo IT Lead | Pass | None | Low | Continue monthly review | System Owner | 10 Jun 2026 | Complete | Signed |
Secure Transfer controls
Any external sharing/export records recipient, lawful basis, data categories, transfer method, encryption and approval.
| Transfer ref | Recipient | Reason | Lawful basis | Data categories | Secure method | Encryption | Manager approval | Date/time sent | Sent by | Audit log |
|---|---|---|---|---|---|---|---|---|---|---|
| TRN-DEMO-001 | Demo Local Authority | Package review | Public task / legitimate interest placeholder | Care notes and package summary | Secure email / portal placeholder | Yes | Yes | 16 May 2026 10:20 | Demo Care Coordinator | Logged |
| TRN-DEMO-002 | Demo NHS ICB | Invoice evidence | Contract / care provision placeholder | Visit times and invoice evidence | Approved secure transfer placeholder | Yes | Yes | 16 May 2026 11:05 | Demo Finance Administrator | Manager review |
| TRN-DEMO-003 | Demo Family Representative | Approved family update | Consent / family portal permission placeholder | Selected visit update only | Family portal message | N/A | No | 16 May 2026 12:15 | Demo Care Coordinator | Logged |
Supplier / Hosting Due Diligence register
Data processor and hosting checks for DPA, contracts, hosting location, encryption, backups, MFA, subprocessors and incident timescales.
| Supplier | Service | Data processed | Special category data | Hosting location | Encryption | Backups | Access controls | MFA | Breach timescale | Sub-processors | DPA/contract | Review date | Status | Approved by |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Demo Cloud Hosting Ltd | Secure application hosting | Care, staff, rota and audit records | Yes | UK region placeholder | At rest and in transit | Daily encrypted | RBAC and MFA | Yes | 24 hours | Demo subprocessors listed | Yes | 15 Nov 2026 | Approved | Demo System Owner |
| Demo Email Gateway Ltd | Secure email routing | Professional communications metadata | Potentially | UK/EU placeholder | TLS | Provider managed | Admin only | Yes | 24 hours | Demo anti-spam processor | Yes | 01 Sep 2026 | Approved with action | Demo Compliance Officer |
| Demo PDF Export Service | Report and invoice document generation | Exported report content | Yes | UK region placeholder | Encrypted temporary files | No persistent storage | Token-based | Yes | 12 hours | None declared | DPA pending review | 30 Jun 2026 | Manager review required | Demo System Owner |
Data Protection / Cyber Risk Register
Data protection and cyber risk register with likelihood, impact, controls, owner and review date.
| Risk title | Description | Likelihood | Impact | Rating | Control measures | Owner | Review date | Action required | Status |
|---|---|---|---|---|---|---|---|---|---|
| Unauthorised access to key safe code | Key safe visible outside allocated visit window | Medium | High | High | Visit-window restriction, audit log, manager review | Registered Manager | 15 Jun 2026 | Review mobile visibility rules | Open |
| Wrong recipient email | Professional update sent to wrong address | Medium | Medium | Medium | Recipient confirmation, secure transfer log, training | Care Coordinator | 30 Jun 2026 | Add double-check prompt | In progress |
| Ransomware / malware | Endpoint compromise affecting office access | Low | High | Medium | MFA, endpoint protection, backups, restore tests | System Owner | 15 Jun 2026 | Upload endpoint review evidence | Open |
| Backup failure | Backups unavailable during restore | Low | High | Medium | Encrypted backup monitoring and monthly restore test | System Owner | 15 Jun 2026 | Next test scheduled | Controlled |
| Staff access misuse | Admin views records outside role need | Medium | High | High | RBAC, access schedules, restricted field audit, manager review | Registered Manager | 01 Jun 2026 | Quarterly permissions review | Open |
| Mobile phone loss | Care worker loses device with app session | Medium | Medium | Medium | No personal storage, app timeout, report lost device process | Field Supervisor | 30 Jun 2026 | BYOD review | In progress |
| Supplier failure | Hosting supplier outage affects ECM | Low | High | Medium | BCP, status page, manual rota, data restore process | System Owner | 15 Nov 2026 | Supplier annual review | Controlled |
Staff Data Protection / Cyber Security training tracker
Restricted system access can be blocked until staff complete required data protection and cyber training.
| Staff | Role | Training completed | Completion date | Certificate uploaded | Refresher due | Score/pass | Manager sign-off | Access blocked |
|---|---|---|---|---|---|---|---|---|
| Demo Care Worker A | Care Worker / Mobile User | Data Protection / Confidentiality / Cyber Security | 12 May 2026 | Yes | 12 May 2027 | Passed 92% | Demo Registered Manager | No |
| Demo Care Coordinator | Care Coordinator | Confidentiality, secure email, RBAC, journal/audit rules | 10 May 2026 | Yes | 10 May 2027 | Passed 96% | Demo Registered Manager | No |
| Demo General Administrator | General Administrator | Safe email, phishing, restricted data handling | 02 May 2026 | Yes | 02 May 2027 | Passed 88% | Demo Senior Administrator | No |
| Demo Finance Administrator | Finance Administrator | Secure invoice evidence and transfer controls | 15 Apr 2026 | Yes | 15 Apr 2027 | Passed 91% | Demo Registered Manager | No |
| Demo New Starter | Care Worker / Mobile User | Awaiting refresher | Not completed | No | Before system access | Pending | Demo Training Admin | Yes |
Incident Response / Data Breach register
Breach and security incidents include ICO, NHS/LA, safeguarding and individual notification decisions.
| Reference | Discovered | Occurred | Reported by | Affected person | Data involved | Breach type | Immediate action | Risk assessment | ICO required | NHS/LA notified | Safeguarding | Individuals notified | Outcome | Lessons | Corrective action | Sign-off |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IG-DEMO-INC-001 | 14 May 2026 10:20 | 14 May 2026 09:55 | Demo Care Coordinator | Demo service user record | Limited visit scheduling data | Misdirected internal message | Message recalled and manager notified | Low likelihood of harm | No | No | No | No | Closed | Recipient checking refresher | Office prompt added | Demo Registered Manager |
| IG-DEMO-INC-002 | 12 May 2026 16:40 | 12 May 2026 16:30 | Demo Field Supervisor | Demo staff member | Mobile device access token | Lost device report | Session disabled and device marked lost | Low after immediate lock | No | No | No | No | Manager review | Lost device process worked | BYOD checklist refresh | Demo System Owner |
| IG-DEMO-INC-003 | 09 May 2026 08:15 | 09 May 2026 08:00 | Demo HR Administrator | Demo staff file | Recruitment document attachment | Attachment upload error | Restricted document moved to correct staff file | Medium | Manager decision pending | No | No | No | Open | Upload verification needed | Audit and add sign-off step | Demo Registered Manager |
Article 32 Evidence Register
Evidence pack index for Article 32, DSPT, audit exports, secure transfer logs and cyber security reviews.
| Evidence category | Evidence source | Demo status | Owner | Review date | Status |
|---|---|---|---|---|---|
| Encryption policy | Access Control Policy and Cyber Security Arrangements | Uploaded placeholder | Demo System Owner | 01 May 2027 | Active |
| Staff training evidence | Training tracker and certificates | 28 completed; 3 due | Training Administrator | 12 May 2027 | In progress |
| Backup test records | BACKUP-DEMO-001 / BACKUP-DEMO-002 | Latest passed | System Owner | 15 Jun 2026 | Complete |
| Restore test records | RESTORE-DEMO-001 | Evidence placeholder retained | System Owner | 15 Jun 2026 | Complete |
| Business continuity test records | BCP-DEMO-001 | Action plan open | Registered Manager | 13 Jun 2026 | Manager review |
| Supplier due diligence | Supplier register | DPA/contract status tracked | Senior Administrator | 15 Nov 2026 | In progress |
| Risk register | DP-RISK-REGISTER | Reviewed monthly | Compliance Officer | 15 Jun 2026 | Active |
| Incident log | Breach / incident register | ICO/NHS/LA decision prompts | Registered Manager | Ongoing | Active |
| Audit log export | AUDIT-ART32-DEMO | Export placeholder | System Owner | 31 May 2026 | Available |
| Secure transfer log | TRN-DEMO register | Recipient and lawful basis recorded | Care Coordinator | Ongoing | Active |
| DSPT evidence | DSPT certificate / publication reference | 2025-26 version 8 placeholder | Registered Manager | 30 Jun 2027 | Complete |
| Cyber security review | Cyber action plan | MFA, device security and review evidence | Compliance Officer | 30 Jun 2026 | In progress |
Compliance report exports
Export placeholders are role restricted and every export is audited.
| Report | Permitted roles | Format | Restriction | Audit requirement |
|---|---|---|---|---|
| Article 32 Compliance Report | System Owner / Registered Manager / Compliance Officer | PDF placeholder | Manager approval required | Export audited |
| Access Control Report | System Owner / Registered Manager | Excel/PDF placeholder | Restricted | Export audited |
| Backup & Restore Report | System Owner / Registered Manager / Compliance Officer | PDF placeholder | Manager sign-off | Export audited |
| Supplier Due Diligence Report | System Owner / Registered Manager / Senior Administrator | Excel/PDF placeholder | Manager approval required | Export audited |
| Incident / Breach Report | Registered Manager / Compliance Officer | PDF placeholder | Restricted sensitive | Export audited |
| Staff Training Report | HR / Training / Registered Manager | Excel/PDF placeholder | Staff file restricted | Export audited |
| Audit Log Report | System Owner / Registered Manager / Auditor where authorised | CSV/PDF placeholder | Time-limited access | Export audited |
| Risk Register Report | Registered Manager / Compliance Officer | PDF placeholder | Manager review | Export audited |
| Secure Transfer Report | System Owner / Registered Manager / Compliance Officer | CSV/PDF placeholder | Restricted | Export audited |