DPIA Support
Resources to help you with a Data Protection Impact Assessment (DPIA) in relation to using Wyser ASSIST within your organisation.
Getting started with your DPIA
Data protection and lawful processing
Data storage, security and retention
- What should we say about data retention in our own system?
- What question is your article answering?How are subprocessors managed?
- What security measures are included in the DPA?
- Where is customer data stored and processed?
- Are international data transfers involved?
- Who are Wyser's subprocessors?
- How is customer data protected?
- How long is data retained?
- What happens to the audio after transcription?
- Does Wyser retain the final case note?
- What happens if a customer needs a recording deleted urgently?
- Does Wyser have ISO 27001 and Cyber Essentials Plus?
- How does Wyser control access to customer data?
AI, accuracy and human oversight
- How should we describe human oversight?
- Can Wyser use customer data for other purposes?
- What happens to data once it leaves our organisation's systems?
- Does Wyser use customer data to train its AI models?
- Does ASSIST make automated decisions about individuals?
- How is accuracy managed?
- What happens if ASSIST produces an inaccurate transcript or summary?
Integrations and data flows
Data subject rights and organisational responsibilities
- What should we include in our DPIA about staff?
- What rights do data subjects have?
- Can a customer access information held in ASSIST following a DSAR?
- What happens if there is a data breach?
- Is ASSIST GDPR compliant?
- What measures support data minimisation?
- Can third parties be captured in a recording?
DPIA risks and controls
- What should we say about function creep?
- Is there a less intrusive way to achieve the same purpose?
- What should we put for "benefits of processing"?
- What should we put for "purpose of processing"?
- What controls can we include in our DPIA to mitigate risks?
- How should we describe the main privacy risks?