CO
Viewing as
National Administrator · All 47 counties · Cabinet briefings
Regulator-ready

Compliance & ODPC Centre

Data Protection Officer console — DPIA, registers, retention, breach drills, lawful basis, transfers, and audit.

ODPC readiness

Composite score

86
Score
DPIA78%
Retention92%
Breach drills100%
Access reviews64%
DSR SLA88%
Training74%
Open risks
11
DSR pending
8
Access violations
2
Sharing agreements
9

Compliance task register

RefTaskRiskStatus
C-01
DPIA — Iris biometric processing
DPIA · Owner DPO Office
HighIn progress
C-02
Children's data processing register update
Register · Owner DPO Office
MediumDone
C-03
Retention policy — biometric templates
Retention · Owner Legal
HighPending
C-04
Breach notification drill Q2
Drill · Owner SOC
MediumDone
C-05
Data sharing agreement — MoH
Agreement · Owner Legal
LowDone
C-06
Data sharing agreement — MoE
Agreement · Owner Legal
MediumIn progress
C-07
Access review — privileged roles
Access · Owner Security
HighOverdue
C-08
Consent / lawful basis register refresh
Register · Owner DPO Office
MediumIn progress
C-09
Cross-border transfer assessment
DPIA · Owner DPO Office
HighPending
C-10
Vendor due diligence — iris device OEMs
Vendor · Owner Procurement
MediumIn progress
C-11
Privacy notice review
Notice · Owner DPO Office
LowDone
C-12
Subject access response template
Rights · Owner DPO Office
LowDone
C-13
Encryption key rotation
Security · Owner Security
HighIn progress
C-14
Audit log immutability verification
Audit · Owner Security
MediumDone
C-15
Officer privacy training
Training · Owner HR
MediumIn progress

Privacy notice

Processing of children's data and iris biometrics is governed by the Births & Deaths Registration Act, Data Protection Act 2019, and ODPC guidance. Lawful basis is primarily legal obligation / public task with consent recorded for ancillary contact channels. All sensitive decisions require human approval, with immutable audit trails. Cross-border transfer is not permitted without a transfer impact assessment.