Operational Checklist for Controllers
Maintain a living record of processing that identifies DeskGate modules, affected locations and teams, personal-data categories, recipients, retention, security measures, and international transfers. Revisit this record after organizational changes, product updates, new reports, or expanded endpoint coverage. Involve the data protection officer, employee representatives, human resources, information security, and legal advisers where their participation is required or useful.
Train managers not to interpret productivity labels as objective measures of performance. Application and website categories can be incomplete, time records can reflect technical or operational conditions, and a device user may not be the person assumed. Establish a documented path from a report or alert to verification, contextual review, an opportunity to respond, and a proportionate outcome. Avoid special-category data and private communications unless a narrowly defined legal need has been reviewed.
When a customer asks DeskGate for support, provide the minimum diagnostic information necessary, remove credentials and unrelated personal data, use approved secure channels, and authorize access for a limited period. Record who requested the assistance and close access after resolution. Periodically test restoration, deletion, account revocation, incident escalation, and data-subject request searches so written procedures work under real deadlines.