UK software change file / data scheduleOwner decisions required

Data schedule / 01

Assign the data roles before granting the supplier access.

Remote delivery can involve repositories, support systems, logs, test fixtures, analytics, AI tools and third-party services. Map the path and accountable decisions before real information enters it.

DecisionQuestions to recordImplementation evidence
Purpose and minimum fieldsWhich outcome requires the information? Which fields are necessary, optional, derived, sensitive or prohibited from test environments?Approved field map, synthetic-data fixtures and collection boundaries.
Controller and processor rolesWho determines purpose and means? Is the supplier a processor for any route? Which sub-processors or independent controllers are involved?Role schedule, contract instructions, access list and disclosed third parties.
UK-to-US accessDoes remote access or a hosted service create a restricted transfer? Who applies the ICO test and selects any required mechanism or assessment?Organisation/adviser decision, documented transfer path and configured controls.
Retention and deletionHow long are production, backup, log, support, analytics and test records useful? Who approves and verifies deletion?Retention jobs, backup treatment, deletion evidence and exception log.
Incidents and rightsWho detects, contains, assesses and communicates an incident? How are access, correction, export or deletion requests routed?Runbook, named contacts, audit events and controlled response tests.

Data schedule / 02

The ICO guidance is a decision source, not a compliance badge.

The Information Commissioner’s Office provides current guidance on controllers and processors and, as updated in January 2026, a detailed guide to international transfers. Its international-transfer material introduces a three-step test and explains that responsibility depends on the actual transfer and roles.

The UK organisation and its appropriately qualified advisers must decide what applies. Faith Forge Labs can turn confirmed decisions into technical controls: role boundaries, field minimisation, access expiry, audit events, retention routines, export restrictions, synthetic test data and an incident route.

No automatic AI lane: do not put personal, confidential or commercially sensitive information into an AI service simply because it is available. Record the provider, purpose, permitted inputs, retention/training settings, location, human review and failure response first.

Supplier-access pack

  • Named access approver and time-limited accounts.
  • Separate production, staging and local-test data rules.
  • Credential transfer and revocation route.
  • Approved third-party and sub-processor inventory.
  • Data export, handover and relationship-end procedure.
  • Evidence required before production access expands.

Start with the ICO’s controller and processor guidance and international transfer guide.

Next record

Map one real data route with sensitive values removed.

Start the data schedule