Data schedule / 01
Assign the data roles before granting the supplier access.
Remote delivery can involve repositories, support systems, logs, test fixtures, analytics, AI tools and third-party services. Map the path and accountable decisions before real information enters it.
| Decision | Questions to record | Implementation evidence |
|---|---|---|
| Purpose and minimum fields | Which outcome requires the information? Which fields are necessary, optional, derived, sensitive or prohibited from test environments? | Approved field map, synthetic-data fixtures and collection boundaries. |
| Controller and processor roles | Who determines purpose and means? Is the supplier a processor for any route? Which sub-processors or independent controllers are involved? | Role schedule, contract instructions, access list and disclosed third parties. |
| UK-to-US access | Does remote access or a hosted service create a restricted transfer? Who applies the ICO test and selects any required mechanism or assessment? | Organisation/adviser decision, documented transfer path and configured controls. |
| Retention and deletion | How long are production, backup, log, support, analytics and test records useful? Who approves and verifies deletion? | Retention jobs, backup treatment, deletion evidence and exception log. |
| Incidents and rights | Who detects, contains, assesses and communicates an incident? How are access, correction, export or deletion requests routed? | Runbook, named contacts, audit events and controlled response tests. |
Data schedule / 02
The ICO guidance is a decision source, not a compliance badge.
The Information Commissioner’s Office provides current guidance on controllers and processors and, as updated in January 2026, a detailed guide to international transfers. Its international-transfer material introduces a three-step test and explains that responsibility depends on the actual transfer and roles.
The UK organisation and its appropriately qualified advisers must decide what applies. Faith Forge Labs can turn confirmed decisions into technical controls: role boundaries, field minimisation, access expiry, audit events, retention routines, export restrictions, synthetic test data and an incident route.
Supplier-access pack
- Named access approver and time-limited accounts.
- Separate production, staging and local-test data rules.
- Credential transfer and revocation route.
- Approved third-party and sub-processor inventory.
- Data export, handover and relationship-end procedure.
- Evidence required before production access expands.
Start with the ICO’s controller and processor guidance and international transfer guide.
Next record