Know what information the product needs
Identify the purpose of each personal-data field before adding it to a form. The PCPD’s six Data Protection Principles address collection, accuracy and retention, use, security, openness, and access and correction. Use the official guidance with your privacy adviser to establish requirements for the actual service.
Translate a retention decision into test cases
Suppose the responsible adviser approves a retention rule for inactive booking enquiries. Engineering still needs to identify every copy and how the rule behaves when a record must be retained for a separately approved reason. No retention period is prescribed by this example.
| Test | Expected implementation evidence |
|---|---|
| Enquiry reaches its approved deletion date | Scheduled process removes or de-identifies the covered record and logs the outcome |
| Data exists in an export or connected service | Operational owner tracks the copy and applies the agreed process |
| Access request from the wrong account | Identity and authorisation are checked before any disclosure |
Include administration and deletion
A privacy notice alone does not determine who can export a database or how old records are removed. Specify role access, logs, retention actions and the handling of access or correction requests. Include copies in exports, backups and connected services when defining what the operational process must cover.
Test the policy against the product
Walk through collection, use, staff access and the end of the record’s useful life. Verify that an ordinary user cannot reach another user’s information and that staff have only the permissions needed. Have your responsible adviser review the policy and actual implementation together; a generic development checklist is not a legal sign-off.
Before you proceed
- Give each personal-data field a defined purpose.
- Assign access, retention and request-handling owners.
- Test permissions and the complete record lifecycle.



