Recording Personal Data Processing Activities
A personal data processing activity record (also called an evidence chain) summarizes data processing activities throughout the lifecycle of a single personal data business. These records typically include data inventories, risk assessment reports, privacy statements, data processing agreements with third parties, and cross-border transfer agreements. Business departments can present the chains systematically to regulators, thereby enhancing Huawei's transparency in privacy protection.
Generating and Exporting Evidence Chains
- You can generate an evidence chain for an DI only when DI Status is Approved.
- You can export an evidence chain only when Evidence Chain Status is Approving or Approved.
- Log in to the PCMC.
- In the navigation pane, choose Record of Personal Data Processing Activities. The Personal Data Life Cycle page is displayed.
- Locate the target DI and click Generate Evidence Chain in the Operation column. A success message will be displayed in the upper part of the page.
- Click
next to the DI in the Personal Data Business Name column to view the included evidence chains. - Locate the target evidence chain and click Edit in the Operation column. The Evidence Chain Editing page is displayed.
- In the Data Inventory module:
- If any DI is approved, Data Inventory is marked as Complete. You can view the DI information and approval records.
- If no DI is approved, Data Inventory is marked as Missing. In this case, complete the DI approval on the DI Management page.
- You can click Whether to Display in the upper right corner to show or hide the module content. If the toggle is turned off, the module will be hidden in the exported evidence chain.
Click Save and Proceed to Next Step.
- In the Risk Assessment module, to add a risk assessment report from the system, select System Selection under Add Risk Assessment Report. Then, click Select Report Version, select an assessment report version, and click Confirm. To upload a risk assessment report completed offline, select Offline Upload and click Add File to upload the report.
- If there is an approved risk assessment report available and an offline risk assessment report has been uploaded, Risk Assessment is marked as Complete. You can view the DI information and approval records.
- If there is no approved risk assessment report available or no offline risk assessment report has been uploaded, Risk Assessment is marked as Missing. In this case, complete the PIA/DPIA approval on the PIA/DPIA Management page.
- You can click Whether to Display in the upper right corner to show or hide the module content. If the toggle is turned off, the module will be hidden in the exported evidence chain.
Click Save and Proceed to Next Step.
- In the Privacy Declaration module, to add a privacy statement from the system, select System Selection under Add Privacy Statement. Then, click Select Privacy Statement Version, select a privacy statement version, and click Confirm. To upload a privacy statement completed offline, select Offline Upload and click Add File to upload the offline privacy statement. Enter the privacy statement URL or attachment in the text box. The URL must start with http:// or https://.
- If there is an approved privacy statement assessment report available and an offline privacy statement has been uploaded, Privacy Declaration is marked as Complete. You can view the DI information and approval records.
- If there are no approved privacy statements available or the offline risk assessment report has not been uploaded, Privacy Declaration is marked as Missing. In this case, complete the privacy statement report approval on the Privacy Statement Management page.
- You can click Whether to Display in the upper right corner to show or hide the module content. If the toggle is turned off, the module will be hidden in the exported evidence chain.
Click Save and Proceed to Next Step.
- In the Processing Purpose module, click Whether to Display in the upper right corner to show or hide the module content. If the toggle is turned off, the module will be hidden in the exported evidence chain.
- Basic Information: It displays the basic DI information.
- Third-Party Privacy Protection Assessment Report (Optional): Under Data Processing Agreement (DPA) and DPA Signature Record and Controller's Authorization Record for Processor to Engage Sub-Processors, click Add File to upload the required files, respectively.
- Personal Data Usage and Retention: The data is automatically obtained from the DI. Paste the data deletion records upon expiration in the text box or click Add File to upload the required file. (This step is optional.)
- Cross-border Transfer:
- Click Select Version, select a cross-border assessment version, and click Confirm.
- Paste the cross-border personal data transfer assessment report in the text box or click Add File to upload the required file. (This step is optional.)
- Click Select Version, select the approved DTA, and click Confirm.
- Paste the DTA and DTA signature in the text box or click Add File to upload the required file. (This step is optional.)
- If there is any approved DI and approved cross-border transfer assessment and DTA, Processing Purpose is marked as Complete.
- If there is no approved DI, or no approved cross-border transfer assessment or DTA is available, Processing Purpose is marked as Missing. In this case, complete the DI approval on the DI Management page, and complete other approvals on the Cross-border Transfer Assessment and Data Transfer Agreement Batch Signing page.
Click Save and Proceed to Next Step.
- After editing all steps, click Submit Audit.
- After the approval is complete (see Approval Process for details) and Evidence Chain Status changes to Approved, choose More > Export Evidence Chain > Export All Information/Export Information with "Display Enabled" in the Operation column to export the evidence chain.
- Export All Information: Export all evidence chain information.
- Export Information with "Display Enabled": Export the evidence chain information for which Whether to Display is turned on.
- Open the downloaded file to view the evidence chain information.
Viewing Records of Personal Data Processing Activities
- Log in to the PCMC.
- In the navigation pane, choose Record of Personal Data Processing Activities. The Personal Data Life Cycle page is displayed.
- View the parameters. Table 1 explains them in detail.
Table 1 Personal data lifecycle parameters Parameter
Description
Personal Data Business Name
The name of the personal data business
DI Version
The version of the DI
DI Status
The status of the DI
Evidence Chain Name/Evidence Chain Version
The name or version of the generated evidence chain
Evidence Chain Status
The status that indicates whether the evidence chain is generated:
- Draft: Editing is available.
- Approving: Editing is unavailable.
S Code
The corresponding S code
Creation Time
The data creation time
Creator
The creator of the data
Update Time
The data update time
Updated By
The person who updates the data
Current Processor
The current approver for the evidence chain
- Locate the target DI and click DI Details in the Operation column. The DI Details page is displayed.
- Click
next to the DI in the Personal Data Business Name column to view the included evidence chains. Click View details in the Operation column of an evidence chain to view its details. - View the data under Business Information, Processing Purpose, and Audit History Log.
Related Operations
Click
next to the S code in the Personal Data Business Name column to view the included evidence chains.
- Choose More > Copy in the Operation column to copy an evidence chain.
- Choose More > Delete in the Operation column to delete an evidence chain.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
