Regmindr
Guides

How often should you review your ROPA, privacy notices and DPIAs?

Updated

UK GDPR rarely sets a fixed interval. It asks you to maintain a record of processing (Art. 30), give accurate privacy information (Arts. 13 and 14), review your data protection measures where necessary (Art. 24), regularly test your security (Art. 32(1)(d)) and review DPIAs at least when the risk changes (Art. 35(11)). A yearly review on a fixed date, with an earlier one whenever your processing changes, is the simplest way to show you keep them current.

Table of data protection documents and what UK GDPR says about reviewing them: record of processing, maintain a written record (Art. 30); privacy notices, accurate information at collection (Arts. 13 and 14); data protection policies, review and update where necessary (Art. 24); security measures, test and evaluate regularly (Art. 32(1)(d)); processor contracts, required terms in writing (Art. 28); retention and deletion, no longer than necessary (Art. 5(1)(e)); DPIAs, review at least when risk changes (Art. 35(11)); breach log, record every breach (Art. 33(5)).
What each article asks for. None sets a fixed interval, so the cycle is yours to set and justify.

Record of processing activities

Your record covers why you process personal data, the categories of people and data, who receives it, transfers abroad, retention periods and, where possible, your security measures (Art. 30). Organisations with fewer than 250 staff are exempt only if the processing is occasional, unlikely to result in a risk and doesn't include special category or criminal offence data, so most firms that handle customer data keep one.

Review it once a year, and update it whenever you add a system, a supplier or a new purpose.

Privacy notices

People must get accurate information about the processing when you collect their data (Arts. 13 and 14). Review your notices straight after the record of processing, so any new purpose, recipient or retention period appears in both.

Policies and security

Your data protection measures must be "reviewed and updated where necessary" (Art. 24(1)), and you need a process for regularly testing, assessing and evaluating how well your security measures work (Art. 32(1)(d)).

Processors, retention and DPIAs

  • Processors: each needs a written contract with the terms in Art. 28. Review your suppliers, their contracts and where they store the data.
  • Retention: keep personal data no longer than you need it (Art. 5(1)(e)). Check that data past its retention period has been deleted or anonymised.
  • DPIAs: review each one where necessary, and at least when the risk of the processing changes (Art. 35(11)).

Training and the breach log

No article sets a training interval, but where you have a data protection officer their tasks include raising awareness and training staff (Art. 39(1)(b)). Every breach goes in your breach log, reported or not (Art. 33(5)). See data breach reporting: the 72-hour deadline.

Make the cycle visible

Put each review on a fixed date with an owner and keep the evidence when it's done. The data protection compliance checklist adds each one as a yearly reminder, and you can download it as a spreadsheet.

Get reminded before each deadline

Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related