Data protection
A GDPR compliance dashboard that tells the truth
Ask most small businesses how their data protection is going and you get a feeling, not a figure. "Fine, I think." The trouble with a feeling is that it is usually a month behind the facts. There is an open access request nobody has diarised, a breach logged in an email thread and never risk-assessed, and a retention rule that lapsed in spring. None of it is visible, because it lives in four different places.
A compliance dashboard exists to replace the feeling with a number. Not a certificate, not a score out of a hundred - just an honest, current picture of the things a regulator would actually ask about, gathered onto one page you can open before any review.
Why four spreadsheets always drift apart
The natural way to keep data-protection records is one file per job: a RoPA here, a DSAR tracker there, a breach log somewhere else, a retention list in a fourth tab that nobody has opened since it was made. Each is fine on its own. The problem is that no single view ever pulls them together, so the overall position is something you have to reconstruct by hand, which means in practice nobody does. The record that falls behind is always the one you are not looking at.
Putting all four registers in one workbook and rolling them into a single dashboard fixes the structural flaw, not just the tidiness. When the summary reads from the same rows you enter your data into, it cannot be out of date. The dashboard is the registers, counted.
The two clocks that matter most
Of everything a data-protection dashboard can show, two numbers carry disproportionate weight, because they are the two a regulator asks about first.
The one-month DSAR clock. A subject access request must be answered within a calendar month. Miss it and you have breached the individual's rights - a clean, bright-line failure with no ambiguity to hide behind. A good dashboard shows how many requests are open and how many have already gone overdue, without you counting a single day.
The 72-hour breach window. A reportable personal-data breach must reach the ICO within 72 hours of detection. In the middle of an incident, the deadline is the easiest thing to lose. The dashboard should surface how many breaches are in play this year and how many have passed their report-by window - and it should turn that red on its own, not wait for you to notice.
The point of computing these rather than tracking them by hand is not convenience. It is that the failure mode of manual tracking is silence: nothing tells you the deadline has passed. A clock that works itself out fails loudly instead, which is the only kind of failure you can act on.
What belongs on the page
Beyond the two clocks, a dashboard earns its place by answering the questions a review actually asks:
- How many processing activities do we have on record? The RoPA count, so you know the scope of what you handle.
- Open and overdue DSARs. The live request load and anything already late.
- Breaches this year, and how many past their report window. The incident picture at a glance.
- Retention items due. Records that have reached the end of their keep-period and need disposing of.
- A lawful-basis breakdown. The mix of grounds you rely on - useful when someone challenges whether you should hold something at all.
Each of these is a single figure or a small chart. Together they are the difference between "fine, I think" and "here, look."
Using it as an instrument, not an ornament
A dashboard only tells the truth if the records underneath it are kept current, so the discipline is simple: log the request when it arrives, record the breach when it is detected, set the retention rule when the record type is created. Do that and the summary maintains itself. Then open it at every management or data-protection review and let the flagged work set the agenda - the overdue rows have already put their hands up.
That is the whole idea. Not a compliance theatre of green ticks, but one page that reflects reality closely enough that you would be comfortable turning the screen round.
Four registers, one honest page
RoPA, DSAR log, breach log and retention schedule in a single workbook, rolled into a dashboard where the one-month and 72-hour clocks compute themselves and flag what is overdue. A template to run your records, not legal advice.