Appendix D — Purpose, inventory, retention and processor schedules
Use these linked workpapers together. An inventory locates an object; a purpose decision authorises an activity under stated facts; a retention decision controls why a copy remains; a processor schedule allocates execution and evidence responsibilities. None can stand in for the others. All filled enterprise records here are synthetic teaching artifacts.
D.1 Blank and populated entry points
| Schedule | Reusable surface | Populated working copy |
|---|---|---|
| Purpose / data / ground | Purpose-register template | Purpose decisions |
| Processing inventory | Recommended columns below | Inventory, with declared systems, datasets, flows and unknown set |
| Retention / legal hold / disposal | Recommended decision fields below; withdrawal template for the interface | Retention decisions |
| Processor / subprocessor | Copy the schedule structure into a new entity-specific file | Readable schedule, structured schedule |
| Ownership and escalation | Blank operation template | Pilot and residual owner records |
D.2 The minimum useful inventory row
Record dataset ID, physical system and copy type, data subjects, fields, owner, activity/flow, purposes, recipient roles, origin/destination, discovery method, last verification and confidence limits. An unknown set is part of the inventory, not a denominator silently discarded to claim completeness. A dataset with multiple purposes needs activity-level rows. Supplier name or hosting region alone cannot decide role or lawful use.
In CASE-001, SUB-001’s application and optional marketing grants stay separate. Proposed referral and training paths do not become authorised simply because a receiving system is in the dictionary. Appendix B maps the operating aliases to the relevant control owner and workpaper without turning source coverage into deployed coverage.
D.3 Record a decision, not a universal retention number
For each record class or copy, record triggering event, purpose state, applicable legal minimum and exact source, permitted retained uses, scoped hold authority, custodian, review event and disposal condition. Distinguish logical restriction, physical erasure, failed operation, unknown supplier state and deferred backup treatment. Chapter 14 supplies the source-led decision method; unresolved overlap/reset interpretation is QL-001 in Appendix H.
The integrated example retains ACK-001 as missing. Its local retest cannot prove remote cessation or deletion. HOLD-001 is scoped to the disputed transaction material and needs its specified authority review; it is not a universal marketing archive. EVT-025 is an eligibility review, not a guaranteed erase date. Release of a hold reopens the decision rather than erasing every linked dataset automatically.
A restore must preserve the later history of restrictions and eligible erasures. SNAP-001 predates withdrawal; restoring it into SYS-014 does not recreate current permission. The actual local replay checks include out-of-order history and a later grant after eligible erasure. Their result is in-memory model behavior, not proof of storage-media sanitisation.
D.4 Negotiate without manufacturing completion
The processor schedule should identify activity-level role, instruction scope, safeguards, incident escalation, cessation/erasure responsibilities, subprocessor changes, evidence format, audit access, unresolved conditions and exit. Separate source duties from recommended contract detail. A supplier’s refusal of material evidence can mean restriction or no-go; a commercial discount is not a substitute.
Reuse the completed failure branch: no acknowledgement, no global completion, named vendor owner, next review and evidence required to release. A “completed” callback must identify what operation and scope it covers. An absence query, a signed receipt and a contractual promise support different conclusions. Preserve that distinction in the workpaper and the communication to the person.