Start with one document process
Choose one repeatable workflow first—for example, preparing a document pack for internal staff review. Define the inputs, responsible reviewer, required outputs and completion criteria. Run the pilot with synthetic records. A useful demonstration should show how a request reaches review, how corrections are recorded and how an authorised user obtains the final version.
1. Identify who is responsible
List the agency, software supplier, hosting provider and any external professional involved. Decide who determines each processing purpose and who acts on documented instructions. These roles depend on the actual activities; purchasing a software licence does not decide them automatically.
For procurement, keep a short responsibility matrix covering the agency administrator, case worker, reviewer, client and technical support. Name who approves access changes and who coordinates incident handling.
2. Collect only what the process needs
For an initial enquiry, begin with business contact information and a description of the workflow. Do not request a real client's passport merely to demonstrate the software. For an active case, record why each data category is required and when it will be reviewed or removed.
Data protection principles such as purpose limitation, data minimisation, accuracy and storage limitation should be reflected in the operating design. Any sector-specific retention duties must be assessed for the real service.
3. Control templates and review
For every template, record its owner, version, source and intended use. Keep draft and approved versions distinguishable. A generated file should be traceable to the approved inputs and template used.
Treat generated, reviewed and submitted as separate states. Producing a DOCX or PDF does not establish that an authority will accept it.
4. Test access and recovery
Use at least two synthetic cases and two separate users. Verify that each user can access only the records assigned to them. Test invitation expiry, access revocation and whether a former user can still download a file. Then perform a backup restore in an isolated environment and retain the result.
Access should follow need-to-know principles. A login screen alone is not evidence that the entire workflow is appropriately protected.
5. Separate licence, implementation and support
Document permitted users, software modules, licence duration, deployment location and any authorised customer branding. Define migration and template work separately from the licence. Record support hours, response targets, exclusions, acceptance criteria and data-export arrangements for the end of the relationship.
For a non-exclusive licence, describe the rights granted and retained rather than presenting the transaction as an outright transfer of the technology.
6. Use a short acceptance record
| Check | Evidence to retain |
|---|---|
| Request to review | Synthetic case reference and status history |
| Document correction | Input version, template version and reviewer |
| Access separation | Allowed and denied actions for each test role |
| Recovery | Restore result in an isolated environment |
| Exit | Usable export and documented retention decision |
| Support | Named contact, scope and agreed response targets |
Move into production only after the agreed checks pass and responsible staff accept the workflow. Unresolved limitations should be documented rather than hidden.
Discuss an agency workflow with SMG
For a scoped implementation, non-exclusive licensing and support discussion, contact SMG with your workflow, approximate case volume, languages and required outputs. Synthetic examples are preferred at the initial stage. Service scope, contracting party, licence rights and support terms are agreed separately.
Official sources
- European Data Protection Board — Data controller or data processor
- European Data Protection Board — Controller–processor contract
- European Commission — Principles of the GDPR
- European Commission — Data protection obligations
Source review checkpoint: 27 September 2026.