DATA PROTECTION COMPLIANCE REGISTERS

Confidential – Internal Company Records

These registers should be maintained by Luxeromo.com’s management and updated regularly as part of the Company’s data protection and compliance programme.

REGISTER 1 – PERSONAL DATA BREACH REGISTER

Purpose

To record every actual or suspected personal data breach involving customer, supplier, employee or company information.

Record the Following:

Reference

Description

Incident Number

Unique reference number

Date & Time Reported

 

Date & Time of Incident

 

Reported By

 

Type of Incident

Loss, unauthorised access, ransomware, phishing, accidental disclosure, etc.

Categories of Data Involved

Customer, supplier, employee, payment, booking data

Number of Individuals Affected

 

Cause of Incident

Human error, cyber attack, technical failure, etc.

Immediate Containment Measures

 

Risk Assessment

Low / Medium / High

Regulatory Notification Required

Yes / No

Individuals Notified

Yes / No

Corrective Actions Taken

 

Lessons Learned

 

Incident Closed Date

 

Approved By

 

REGISTER 2 – DATA SUBJECT REQUEST REGISTER

Purpose

To record requests from individuals exercising their privacy rights.

Record the Following:

  • Request reference number
  • Date received
  • Requester’s name
  • Identity verification completed
  • Type of request (access, correction, deletion, restriction, objection, portability, consent withdrawal)
  • Relevant department
  • Date acknowledged
  • Date completed
  • Outcome
  • Reason if refused (where permitted by law)
  • Staff member responsible

REGISTER 3 – SUPPLIER COMPLIANCE REGISTER

Purpose

To monitor supplier verification and ongoing compliance.

Record the Following:

  • Supplier name
  • Company registration number
  • Country of operation
  • Contact details
  • Verification status
  • Identity verification completed
  • Business licence verified
  • Insurance verified (where applicable)
  • Bank/payment verification completed
  • Agreement accepted
  • Commission payment status
  • Last compliance review
  • Customer complaint history
  • Account status (Active / Suspended / Terminated)
  • Next review date

REGISTER 4 – DATA RETENTION SCHEDULE

Purpose

To document how long different categories of information are retained.

Data Category

Purpose

Retention Period

Disposal Method

Customer Accounts

Booking services

Define by company policy and legal requirements

Secure deletion or anonymisation

Booking Records

Accounting, customer support

Define by company policy and legal requirements

Secure deletion

Supplier Agreements

Contract management

Define by company policy and legal requirements

Secure deletion

Financial Records

Tax and accounting

Define by applicable law

Secure destruction

Marketing Records

Marketing communications

Until consent is withdrawn or no longer needed

Secure deletion

Security Logs

Fraud prevention and security

Define by company policy

Secure deletion

Employee Records

Employment administration

Define by employment law and company policy

Secure destruction

Retention periods should be set according to the legal requirements of the jurisdictions in which Luxeromo.com operates.

REGISTER 5 – INFORMATION ASSET REGISTER

Purpose

To maintain an inventory of the Company’s information assets.

Record the Following:

  • Asset reference number
  • Asset name
  • Description
  • Business owner
  • Department
  • Data categories processed
  • Storage location
  • Access permissions
  • Security classification
  • Backup arrangements
  • Encryption status
  • Third-party access
  • Retention period
  • Last review date

REGISTER 6 – RECORD OF PROCESSING ACTIVITIES

Purpose

To document the Company’s processing of personal data.

For each processing activity record:

  • Activity name
  • Business purpose
  • Categories of individuals
  • Categories of personal data
  • Lawful basis for processing
  • Recipients of the data
  • International transfers
  • Retention period
  • Security measures
  • Responsible department

REGISTER 7 – PRIVACY TRAINING REGISTER

Maintain records of:

  • Employee name
  • Department
  • Training completed
  • Date completed
  • Trainer
  • Refresher training due date
  • Completion status

REGISTER 8 – THIRD-PARTY PROCESSOR REGISTER

Maintain details of service providers that process personal data on behalf of Luxeromo.com, including:

  • Service provider name
  • Service provided
  • Contact details
  • Categories of data processed
  • Countries where data is processed
  • Contract or Data Processing Agreement in place
  • Security assessment date
  • Next review date

REGISTER 9 – CONSENT REGISTER

Where consent is relied upon, record:

  • Individual’s name
  • Type of consent
  • Date consent obtained
  • Method of consent
  • Privacy notice presented
  • Date consent withdrawn (if applicable)

REGISTER 10 – COMPLIANCE REVIEW LOG

Record:

  • Internal audits
  • Policy reviews
  • Risk assessments
  • Security reviews
  • Corrective actions
  • Completion dates
  • Responsible manager
  • Follow-up reviews

Document Control

These registers are confidential and should be maintained securely with access restricted to authorised personnel.

Management should review the registers periodically and update them as business operations, legal requirements or processing activities change.

© Luxeromo.com. All Rights Reserved.