Method
Builds four source-labelled review lanes and opens the first 50 bounded vendor or sub-processor records in an editable local table.
Use it safely
Begin with the synthetic example in the toolbench, then minimise any real-world input. Inspect each finding, its source/status note and the facts behind it before exporting a result.
What it cannot determine
It cannot determine legal roles, read a contract, assess a provider, discover sub-processors, verify safeguards, contact an incident route or prove deletion, return or exit.
8 minute working guide / SYNTHETIC WALKTHROUGH
From input to a reviewable handoff.
- Reviewed
- 2026-08-26
- Legal status
- editorial analysis
- Source/method records
- act-2023act-commencement-843erules-2025rules-2025-corrigendumdpdp-store-method-0.2
- Changelog
- 0.5.0 — first public static working guide.
What this produces: A bounded 18-field local register with four review lanes, per-row open/date states, editable records and current JSON/CSV exports that can be re-imported.
A fictional internal team records a hosting provider and support platform using category-level descriptions, contract references and review dates.
Before you begin
- Start from a confirmed data-inventory row and the current contract or instruction record.
- Use vendor and service labels only where authorised; never paste credentials, contract secrets or personal records.
- Identify the business owner who can confirm actual access and the exit plan.
Walk the evidence sequence
Load the register structure
Open the synthetic CSV, compare the required headers with your controlled register and import a minimised copy locally.
- Evidence to inspect
- The tool accepts the 12 mandated columns, normalises six optional chain/owner/evidence columns, reports excluded unknown headers and fails closed above its local limits before enabling current exports.
- Human review
- A valid row is only an assertion; it does not prove that the supplier is a processor or that the contract matches practice.
Reconcile purpose, data and instructions
Describe the service purpose, category-level data, documented instructions, locations and access path using the linked inventory evidence.
- Evidence to inspect
- The role/purpose and instruction/contract lanes give reviewers one place to compare the business claim, processing chain, evidence reference and technical access.
- Human review
- Escalate role or instruction ambiguity instead of assigning a legal label from the vendor name.
Inspect safeguards and incident handoff
Record the safeguard evidence, review date and verified breach contact or escalation route.
- Evidence to inspect
- Open cells, date-shape issues and the locations/access/safeguards lane expose missing review material without contacting the provider.
- Human review
- Confirm the cited evidence is current, accessible to reviewers and specific to the service in scope.
Test deletion, return and exit planning
Document what happens to active data, backups, exports and sub-processors when instructions end, then export a formula-safe review copy.
- Evidence to inspect
- The current formula-safe CSV can be re-imported after controlled review; the JSON retains lane, source/status and completeness context.
- Human review
- Exercise the exit plan and retain evidence; contract wording alone does not prove completion.
Handoff check
- Is the role and instruction record grounded in facts and current agreements?
- Are locations, access, safeguards and incident contacts verified?
- Does the exit plan cover return, deletion, backups and downstream providers?
The register organises supplied vendor evidence. It does not determine legal roles, assess a provider, read a contract, discover sub-processors, verify controls, contact an incident route or prove deletion, return or exit.
Security and parsing
- Inputs have byte, row or component limits appropriate to the parser.
- Imported content is treated as text or data and is never executed.
- Spreadsheet exports neutralise formula-leading cells.
- Use the per-tool reset or “Clear current toolbench state” to remove current in-tab input and results. Downloaded files remain under your control.
Version record
0.3.0 · 26 August 2026: deterministic public static implementation, synthetic fixture and bounded local parser. Guide record 0.5 · 26 August 2026.