Maintain an audit-ready PII processing inventory with lawful basis, ROPA, risk, retention, transfer, and processor linkage controls.
This policy establishes REG02 as the authoritative PII processing inventory and ROPA record. It requires documented purposes, lawful basis or customer instructions, PII categories, recipients, retention, transfers, risk/DPIA linkage, reviews, exceptions, and corrective action evidence before and during PII processing.
Establishes REG02 as the authoritative inventory for PII processing activities, roles, purposes, categories, status, and review evidence.
Requires controller lawful basis validation and processor customer instruction records before new or changed processing begins.
Assigns process, system, privacy, vendor, audit, and management responsibilities across REG02, REG08, REG12, and related records.
Click diagram to enlarge (open in new tab for full size)
REG02 Processing Inventory and ROPA Requirements
Controller Purpose and Lawful Basis Records
Processor, Subprocessor and Joint Controller Records
PII Categories, Recipients, Retention and Transfers
Inventory Change, Review and DPIA Screening Linkage
Exceptions, Enforcement and Corrective Action Evidence
This product is aligned with the following compliance frameworks, with detailed clause and control mappings.
| Framework | Covered Clauses / Controls |
|---|---|
| ISO/IEC 27701:2025 |
Clause 4.1Clause 6.1.2Clause 6.1.3Clause 7.5Clause 8.1Clause 8.2Clause 9.1Clause 10.2Annex A.1.2.2Annex A.1.2.3Annex A.1.2.6Annex A.1.2.8Annex A.1.2.9Annex A.2.2.2Annex A.2.2.3Annex A.2.2.7
|
| EU GDPR |
Article 5(1)(a)Article 5(1)(b)Article 5(1)(c)Article 5(1)(e)Article 5(2)Article 6Article 9Article 10Article 24Article 26Article 28Article 30Article 35
|
| ISO/IEC 29100:2020 |
Clause 5.3Clause 5.4Clause 5.5Clause 5.6Clause 5.10
|
| ISO/IEC 29151:2022 |
Annex A.3Annex A.4Annex A.5Annex A.7
|
| ISO/IEC 29134:2020 |
Clause 5.1Clause 6.2
|
REG02 must link to privacy notice evidence before controller processing is externally communicated or launched.
Controller processing that relies on consent must link REG02 to REG05 before processing begins.
New or materially changed processing must trigger privacy risk and DPIA screening in REG04.
Each processing activity must record a retention rule or retention reference in REG02.
Processor, subprocessor, third-party sharing, and joint controller relationships must link REG02 with REG08.
REG02 must link to REG09 before any international PII transfer begins.
This policy operationalizes the PII processing inventory and lawful basis requirements within a Privacy Information Management System. It defines REG02 as the authoritative inventory and ROPA evidence object for distinct PII processing activities and requires each record to document purpose, PIMS role, owner, PII categories, PII principal categories, lawful basis or customer instruction reference, systems, recipients, retention reference, transfer reference, privacy risk status, and review status. It supports controller, joint controller, processor, and subprocessor contexts by linking REG02 with supporting evidence objects such as REG04 for privacy risk and DPIA screening, REG05 for consent, REG07 for privacy notices, REG08 for supplier and processor relationships, REG09 for international transfers, and REG12 for approvals, reviews, exceptions, metrics, and nonconformities.
Defines REG02 as the single inventory and ROPA evidence object for in-scope PII processing activities.
Requires purpose, lawful basis, customer instruction, role, and key inventory fields before processing begins.
Connects material processing changes to REG04 privacy risk and DPIA screening before processing proceeds.
Assigns responsibilities to privacy, business, system, vendor, audit, and top management roles.
This policy was authored by a security leader with 25+ years of experience deploying and auditing ISMS frameworks for global enterprises. It's designed not just to be a document, but a defensible framework that stands up to auditor scrutiny.
Get all 25 PIMS policies, full registers set and detailed implementation plan for €799, instead of €1,675 if purchased individually.
View Complete 27701 Pack →