| Requirement | What it means for Viewee | Owner (Instinct / Alex+Cain / External assessor) | Effort | Status | Evidence needed | Source URL |
|---|
| Map controller/processor roles by processing activity | Viewee is likely processor for care-provider tenant feedback and controller for its own leads, customer contacts, staff and service analytics. Confirm role per purpose rather than for the company as a whole. | Alex+Cain | H | Do now | Role/data-flow map and contract position | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/ |
| Data protection principles and accountability | Process lawfully, fairly and transparently; limit purpose and data; keep accurate; retain no longer than needed; secure it; be able to demonstrate compliance. | Alex+Cain | H | Do now and ongoing | Policies, ROPA, decisions, audits and control evidence | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ |
| Records of processing activities (Article 30) | Maintain electronic controller and processor records covering contacts, purposes, categories, recipients, transfers, retention and security measures; record lawful basis and special-category condition. | Instinct | H | Do now; update before launch | ROPA with controller and processor tabs, version/review record | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/documentation/ |
| Choose and document lawful basis | For each Viewee-controlled purpose choose an Article 6 basis before processing. Do not default to consent; document legitimate-interest assessments where relied on. Customers determine bases for tenant processing, supported contractually by Viewee. | Alex+Cain | H | Do now | Lawful-basis register, LIAs/consent records as applicable | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/ |
| Special-category data and DPA 2018 condition | Feedback may reveal health, disability, ethnicity, religion, sexuality or other special-category data. Identify an Article 9 condition and, where required, a DPA 2018 Schedule 1 condition and appropriate policy document. | Alex+Cain | H | Before real feedback data | Special-category assessment, condition record, appropriate policy document | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/special-category-data/ |
| Complete DPIA before high-risk processing | Screen every major processing operation. A DPIA is mandatory where processing is likely high risk; resident health/vulnerability data, monitoring/profiling, large-scale special-category data or novel AI may trigger it. Consult ICO before processing if high residual risk cannot be reduced. | Alex+Cain | H | Do now, before design locks | DPIA with necessity/proportionality, risks, controls, consultation and approval | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/ |
| Privacy by design and default | Build minimisation, role access, tenant isolation, restricted defaults, pseudonymisation, retention/deletion and auditable support access into product and outreach admin. | Alex+Cain | H | During build before launch | Design decisions, threat model, acceptance tests, configuration defaults | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-by-design-and-default/ |
| Transparent privacy information | Give concise, accessible notices at collection covering identity, purposes, bases, recipients, transfers, retention, rights, complaints and automated decisions. Separate/clear notices may be needed for site visitors, prospects and product users. | Instinct | M | Before data collection/launch | Published privacy notices and version/change log | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/ |
| Controller-processor contracts (Article 28) | Customer DPA must state subject/duration, nature/purpose, data types/categories and controller rights; processor clauses must cover instructions, confidentiality, security, subprocessors, rights assistance, breach/DPIA help, deletion/return and audits. | Alex+Cain | H | Before pilot/customer data | Signed DPA/order terms, instruction record, audit/assistance process | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/ |
| Subprocessor governance | Obtain prior specific/general written authorisation, notify changes and flow equivalent Article 28 obligations to each subprocessor; remain liable to customer for subprocessor performance. | Alex+Cain | H | Before vendors process personal data | Subprocessor register, notices/approvals, vendor DPAs and review evidence | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/ |
| International transfer controls | Map every access/storage/support transfer outside the UK. Use adequacy regulations or an appropriate safeguard such as IDTA/Addendum plus transfer risk assessment and supplementary measures where required. | Alex+Cain | H | Before vendor selection/launch | Transfer register, SCC/IDTA/Addendum, TRA and vendor location evidence | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/ |
| Appropriate technical and organisational security | Use measures appropriate to risk, including access control/MFA, encryption, availability/resilience, backup/restore, logging, vulnerability management, incident response and regular testing/evaluation. | Alex+Cain | H | Build now; prove when live | Security architecture, policies, scans/pen test, restore test, access/log reviews | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ |
| Personal data breach process | Detect, triage and document every breach. Controllers notify ICO without undue delay and where feasible within 72 hours unless unlikely to risk people; notify affected people without undue delay for high risk. Processors notify controllers without undue delay. | Alex+Cain | H | Before real personal data | Incident/breach plan, breach log, decision template, tabletop exercise | https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/ |
| Data subject rights operating process | Support access, rectification, erasure, restriction, portability, objection and automated-decision rights. Verify identity, log deadlines, search/export/delete accurately, and assist customer controllers for tenant requests. | Alex+Cain | H | Design now; test before launch | Rights procedure, request log, tested export/correction/deletion workflows | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/ |
| Retention and secure deletion | Set purpose-specific retention periods for feedback, audit logs, backups, outreach data and support records; implement deletion/anonymisation and deal with backups. | Alex+Cain | H | Do now; automate before launch | Retention schedule, deletion design/tests and disposal logs | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/documentation/ |
| Data quality and minimisation | Collect only data needed, prevent unnecessary free text where possible, let customers correct data and avoid copying live personal data into development/test. | Alex+Cain | M | During design | Field-level data specification, validation, test-data policy and reviews | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ |
| DPO assessment and UK representative check | Document whether a DPO is legally required (eg large-scale regular monitoring or large-scale special-category processing). UK-established Viewee does not need a UK representative for that establishment, but reassess expansion. | Alex+Cain | M | Do now; revisit at scale | DPO decision record and review trigger | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-officers/ |
| ICO data protection fee | Use ICO self-assessment and register/pay unless exempt; keep details current and renew. | Alex+Cain | L | Do now | ICO registration/fee outcome and renewal record | https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee/ |
| Vendor due diligence and ongoing assurance | Assess cloud, analytics, email/outreach, AI and support vendors for role, location, security, retention, training use, incident terms, deletion and audit evidence before sharing data. | Alex+Cain | H | Before vendor commitment | Due diligence questionnaire, risk decision, contract and annual review | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ |
| Children/vulnerable adults and accessibility risk review | Residents are vulnerable adults and feedback may concern people lacking capacity. Although UK GDPR has no separate vulnerable-adult regime equivalent to children, fairness, accessibility and risk controls must reflect the audience. | Alex+Cain | M | During design | User research, accessible notices/consent support, safeguarding escalation boundaries | https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ |