Compass
Assessments
Scope · Client personal data (all entities)

Data Protection — Client RecordsActive

Group-wide assessment of GDPR risks relating to retention and access to client personal data.

R-3001

Client data retained beyond legal period

Personal data of former clients is stored longer than permitted by the retention schedule.

Data ProtectionData LifecycleGDPR Art. 5(1)(e)
Impact
Moderate
Likelihood
Likely
Inherent
Medium
Residual
Low

Mitigating controls (1) · Owner: Thomas Becker

  • C-5008Annual data retention purge
    Corrective · Semi automated · Annual · 31 Mar
    Weight 1Effective
R-3002

Unauthorised access to client records

Staff retain or obtain access to client records not required for their role.

Data ProtectionAccess ManagementGDPR Art. 32DORA Art. 9
Impact
Severe
Likelihood
Unlikely
Inherent
Medium
Residual
Low

Mitigating controls (2) · Owner: Thomas Becker

  • C-5009Semi-annual access recertification
    Detective · Semi automated · Semi annual
    Weight 0.7Strong
  • C-5010Data loss prevention monitoring
    Preventive · Automated · Ongoing
    Weight 0.3Effective