HERMES GDPR Scoping Meeting

1. Identification of 'Individuals' and primary department owners

2. In Scope

2.1. For each individual

2.1.1. Identify datasets Categories of personal data to field level Document justification for holding identified data sets

2.1.2. Document which systems the identified datasets reside within System Name Systems general purpose System access controls Security Analyst Input needed System business owner Data retention periods for each identified system Security Analyst Input needed

2.1.3. Dataset flow Identify the 'life cycle' of an individuals dataset Document the process data flow between Hermes systems For each system touch point Identify Data source Identify Data outputs Identify data transfer methods

2.1.4. Data Use Identify touch point of the data set Identify are the triggers for process? Identify processing activity Identify the role of the accessor

3. Out of Scope

3.1. Processes to facilitate individuals rights requests

3.1.1. For 8 GDPR individual rights

3.2. Data Process improvement

3.3. Review or updating of privacy notices

3.4. ICO Breach response

3.4.1. Definition of Breach

4. Timeline

4.1. End of Jan 2018

4.1.1. Individual Focus Sender Re-seller Client Customer Employee Employee applicant

4.2. TBA

4.2.1. Sub-depot Controller

4.2.2. Shop Keeper

4.2.3. Shop Manager

4.2.4. Shop Owner

4.2.5. Self employed courier

4.2.6. Self employed courier applicant

4.2.7. Parcel Recipiant

4.2.8. Neighbour