Accountability, data rights and responsible operations
Service: ClueCheck governance centre
Effective date: 26 August 2026
Applies to: Clients, Shoppers, applicants, authorised portal users, Staff and suppliers
Every new Client project should record the purpose and lawful basis for each material data flow, the parties' controller or processor roles, the approved suppliers, the retention instruction, the responsible owner and the incident contact. A project should not collect additional staff, customer, health, identity or location data merely because a portal field exists.
| Decision | Required record |
|---|---|
| Role | Controller, processor, joint controller or independent controller, with named parties and written instructions. |
| Purpose | Specific business purpose, data categories, lawful basis, recipients and whether fields are mandatory or optional. |
| Risk | Necessity, proportionality, alternatives, access controls, retention and DPIA decision. |
| Ownership | Accountable owner, review date, deletion owner, incident contact and escalation route. |
People may request access, correction, deletion, restriction, objection or portability through the route described in the Privacy Policy. Shoppers and Clients may also challenge inaccurate profile information, report content, evidence attribution, rejection, payment holds or unsafe instructions. Each request should receive an acknowledgement, an owner, a target response date and an escalation route.
ClueCheck maintains a working retention schedule by data category rather than a single blanket period. Data should be deleted or anonymised when the purpose and approved retention period end, unless a documented legal, accounting, fraud-prevention, security or dispute hold applies. See the Retention & Records Standard.
Supplier categories, processing locations, international-transfer safeguards and deletion settings should be recorded before a feature is used in a Client project. Precise location, systematic monitoring, extensive evidence processing, matching or sensitive assignments should receive a documented risk assessment and, where required, a DPIA. See Suppliers & Transfers and Risk Assessments & DPIA.
Suspected personal-data or security incidents should be reported promptly, contained, logged, investigated and assessed for notification obligations. Access permissions, suppliers, retention schedules, notices and portal workflows should be reviewed when processing changes. See the Incident Response Standard.
Related information: Privacy Governance · Privacy Policy · Terms & Conditions · Contact ClueCheck