06 / In your browser / VERSION 0.3.0

Processor Register

Make vendor instructions, access, safeguards, deletion and exit plans reviewable together.

LOCAL INSTRUMENT / SYNTHETIC EXAMPLE INCLUDED

Method

Builds four source-labelled review lanes and opens the first 50 bounded vendor or sub-processor records in an editable local table.

Use it safely

Begin with the synthetic example in the toolbench, then minimise any real-world input. Inspect each finding, its source/status note and the facts behind it before exporting a result.

What it cannot determine

It cannot determine legal roles, read a contract, assess a provider, discover sub-processors, verify safeguards, contact an incident route or prove deletion, return or exit.

Processing boundary. This preview processes current input in browser memory. No input is submitted or stored by dpdp.store. Results are evidence-building aids, not legal approval, certification or an official schema.

8 minute working guide / SYNTHETIC WALKTHROUGH

From input to a reviewable handoff.

GUIDE 0.5
Reviewed
2026-08-26
Legal status
editorial analysis
Changelog
0.5.0 — first public static working guide.

What this produces: A bounded 18-field local register with four review lanes, per-row open/date states, editable records and current JSON/CSV exports that can be re-imported.

FICTIONAL PRACTICE SCENARIO

A fictional internal team records a hosting provider and support platform using category-level descriptions, contract references and review dates.

Before you begin

  • Start from a confirmed data-inventory row and the current contract or instruction record.
  • Use vendor and service labels only where authorised; never paste credentials, contract secrets or personal records.
  • Identify the business owner who can confirm actual access and the exit plan.

Walk the evidence sequence

  1. Load the register structure

    Open the synthetic CSV, compare the required headers with your controlled register and import a minimised copy locally.

    Evidence to inspect
    The tool accepts the 12 mandated columns, normalises six optional chain/owner/evidence columns, reports excluded unknown headers and fails closed above its local limits before enabling current exports.
    Human review
    A valid row is only an assertion; it does not prove that the supplier is a processor or that the contract matches practice.
  2. Reconcile purpose, data and instructions

    Describe the service purpose, category-level data, documented instructions, locations and access path using the linked inventory evidence.

    Evidence to inspect
    The role/purpose and instruction/contract lanes give reviewers one place to compare the business claim, processing chain, evidence reference and technical access.
    Human review
    Escalate role or instruction ambiguity instead of assigning a legal label from the vendor name.
  3. Inspect safeguards and incident handoff

    Record the safeguard evidence, review date and verified breach contact or escalation route.

    Evidence to inspect
    Open cells, date-shape issues and the locations/access/safeguards lane expose missing review material without contacting the provider.
    Human review
    Confirm the cited evidence is current, accessible to reviewers and specific to the service in scope.
  4. Test deletion, return and exit planning

    Document what happens to active data, backups, exports and sub-processors when instructions end, then export a formula-safe review copy.

    Evidence to inspect
    The current formula-safe CSV can be re-imported after controlled review; the JSON retains lane, source/status and completeness context.
    Human review
    Exercise the exit plan and retain evidence; contract wording alone does not prove completion.

Handoff check

  • Is the role and instruction record grounded in facts and current agreements?
  • Are locations, access, safeguards and incident contacts verified?
  • Does the exit plan cover return, deletion, backups and downstream providers?
STOP / REVIEW BOUNDARY

The register organises supplied vendor evidence. It does not determine legal roles, assess a provider, read a contract, discover sub-processors, verify controls, contact an incident route or prove deletion, return or exit.

Security and parsing

  • Inputs have byte, row or component limits appropriate to the parser.
  • Imported content is treated as text or data and is never executed.
  • Spreadsheet exports neutralise formula-leading cells.
  • Use the per-tool reset or “Clear current toolbench state” to remove current in-tab input and results. Downloaded files remain under your control.

Version record

0.3.0 · 26 August 2026: deterministic public static implementation, synthetic fixture and bounded local parser. Guide record 0.5 · 26 August 2026.