Delegation of Authority Matrix Validator
Regime

GDPR: what it asks of an approval matrix

For a company with EU or UK operations: the rule on decisions based solely on automated processing, added on lines that decide something about a person.

Quoted when the company has EU or UK operations.

Named, not quoted, beside it: the UK Corporate Governance Code provision on risk management and internal control.

Approval families anchored here

4
FamilyClause
New hires and headcountGDPR Art. 24 · GDPR Art. 29
Pay changesGDPR Art. 24 · GDPR Art. 29
Terminations and severanceGDPR Art. 24 · GDPR Art. 29
Bonuses and incentivesGDPR Art. 24 · GDPR Art. 29

GDPR: every clause cited, quoted

3 of the 40 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

GDPR Art. 22 Automated individual decision-making, including profiling

Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.

What an auditor asks to see: An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects; The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument; The human intervention process, showing the reviewer has the authority and the information to change the outcome; Records of contested decisions and the outcome of each review; Confirmation of whether special category data, including proxies for it, enters the model, and the safeguards applied where it does
Where matrices usually fall short: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance; Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive; Special category data entering the model through proxies such as postcode, name or purchase history with no assessment; No route for the data subject to contest the decision, only a route to complain about service
Source: GDPR
GDPR Art. 24 Responsibility of the controller

Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.

What an auditor asks to see: The data protection policy set, each with an approval authority, an effective date and a review cycle; The risk assessment that drove the choice of measures, referencing nature, scope, context, purposes and risk to individuals; Review records showing the measures were reassessed and updated after material changes to the processing; The assignment of data protection responsibilities across the organisation, and evidence the assignees act on them; Assurance output such as internal audit, control testing or DPO reporting that demonstrates rather than asserts compliance
Where matrices usually fall short: A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out; Measures selected from a generic checklist with no link to the risk this organisation's own processing presents; Accountability documentation that records what should happen with no evidence that it does; Certification or code adherence presented as the whole of compliance rather than as one element of it
Source: GDPR
GDPR Art. 29 Processing under the authority of the controller or processor

The processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.

What an auditor asks to see: The documented instructions issued to each processor, and the mechanism by which they are kept current; Employment or contract terms binding staff and contractors to process personal data only as instructed; Access controls that make the technical scope of access match the instructions actually given; Monitoring or logging capable of detecting processing outside instruction, and records of any detection; Where a legal requirement overrides instructions, the record of the requirement and the notification given to the controller
Where matrices usually fall short: Instructions existing only as the original contract, never updated as the processing changed over years of service; Staff holding broad standing access to production personal data far beyond what their instructed tasks require; No means of detecting processing outside instruction, so the obligation is asserted and never tested; Processor use of controller data for its own purposes, such as service improvement or model training, permitted by a clause nobody negotiated
Source: GDPR