juris

Section 33: Record of processing operations

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

33. Record of processing operations (1) Every controller or processor shall maintain a record of all processing operations under his or its responsibility. (2) The record shall set out – (a) the name and contact details of the controller or processor, and, where applicable, his or its representative and any data protection officer; (b) the purpose of the processing; (c) a description of the categories of data subjects and of personal data; (d) a description of the categories of recipients to whom personal data have been or will be disclosed, including recipients in other countries; (e) any transfers of data to another country, and, in the case of a transfer referred to in section 36, the suitable safeguards; (f) where possible, the envisaged time limits for the erasure of the different categories of data; and (g) the description of the mechanisms referred to in section 22 (3). (3) The controller or processor shall, on request, make the record available to the Office. PART V – PROCESSING OPERATIONS LIKELY TO PRESENT RISK

Ask juris about this section Official source