
How to Create a Lawful Basis Register for Your Data Uses

A lawful basis register is one of the most useful compliance records an organisation can keep. It connects each use of personal data to the legal reason for processing it, the evidence supporting that decision and the person responsible for keeping it accurate.
For organisations in Jamaica, this register helps turn the Data Protection Act, 2020 from a set of legal duties into a practical control. It also helps management answer a question that comes up in audits, customer due diligence, regulator queries and board reporting: can we show why we are allowed to use this personal data?
A good lawful basis register does not need to be complicated. It needs to be specific, maintained and aligned with what the organisation actually does.
What is a lawful basis register?
A lawful basis register is a structured record of the purposes for which an organisation processes personal data and the lawful condition or basis relied on for each purpose. In Jamaica, it should support the requirement that personal data be processed fairly and lawfully, with clear purposes and appropriate safeguards.
The register is not just a list of systems. One system may support several different data uses, each with a different purpose and legal basis. For example, a customer relationship management system may be used to manage contracts, handle complaints, send marketing messages and run customer analytics. Those are separate uses and should usually be recorded separately.
The register also differs from a consent log. Consent may be relevant in some cases, but it is not the only route to lawful processing. Depending on the facts, processing may be necessary for a contract, a legal obligation, vital interests, public functions or a legitimate interest that does not override the rights and freedoms of the individual. The exact wording and conditions should be checked against Jamaica’s Data Protection Act and applicable guidance from the Office of the Information Commissioner.
Why your organisation needs one
A lawful basis register helps teams make consistent privacy decisions instead of relying on memory, assumptions or old templates. It also supports accountability because it records who made the decision, when it was reviewed and what evidence supports it.
In 2026, Jamaican organisations should treat this as part of normal data protection compliance, not as a one-off implementation document. If your business launches a new service, adds a vendor, starts using monitoring tools or collects a new category of customer data, the lawful basis register should be updated before the processing becomes routine.
It is also useful when building other compliance documents. A privacy notice should reflect the purposes and lawful bases in the register. Retention schedules should match the purposes recorded. Risk assessments should flag any processing where the legal basis is unclear or the data is especially sensitive. If your organisation is still building out its wider privacy programme, PLMC’s guide to a practical Data Protection Act implementation roadmap gives helpful context for sequencing this work.
Decide what counts as a data use
Before creating the register, agree on what a data use means. A practical definition is: a distinct activity involving personal data for a specific business, legal, operational or public interest purpose.
Examples include employee payroll, customer onboarding, vendor due diligence, CCTV monitoring, AML screening, website contact forms, marketing emails, incident response, debt collection, training attendance records and access control logs.
The key is purpose. If the purpose changes, create a separate entry. If the same data is reused for a new purpose, create a separate entry. If a department uses the same system for different reasons, separate the entries so each legal basis can be justified on its own facts.
Core fields to include in the register
A simple spreadsheet can work at first, provided it has ownership, version control and review dates. Larger organisations may use a GRC tool, privacy management platform or integrated risk system. The format matters less than the quality of the information.
Register field | What to record | Why it matters |
Data use name | A plain-language name such as customer onboarding or staff payroll | Makes the register easy for business teams to understand |
Business owner | The department or role accountable for the activity | Prevents privacy from becoming an orphaned compliance task |
Purpose | The specific reason the data is processed | Supports purpose limitation and transparency |
Categories of individuals | Customers, employees, contractors, visitors, patients, students or others | Helps assess rights, expectations and risk |
Categories of data | Contact details, ID records, payment data, health data, CCTV footage or other data types | Shows whether higher-risk data is involved |
Sensitive personal data flag | Yes or no, with the sensitive category identified where applicable | Triggers additional legal and security review |
Lawful basis or condition | The condition relied on for the processing | Documents why the processing is lawful |
Reasoning | A short explanation of why the condition applies | Gives auditors and reviewers more than a label |
Evidence | Consent record, contract clause, law, policy, assessment or approval | Proves the decision was not speculative |
Privacy notice link | Where individuals are told about the processing | Supports fairness and transparency |
Retention period | How long the data is kept and why | Reduces over-retention and unnecessary exposure |
Sharing and processors | Third parties, processors or public authorities receiving the data | Connects the register to vendor and sharing controls |
Security controls | Key access, encryption, monitoring or segregation controls | Shows the basis decision is supported by safeguards |
Review date | Last review and next scheduled review | Keeps the register current |
How to create the register step by step
Start with real data flows
Begin by mapping what actually happens, not what a policy says should happen. Interview process owners in HR, finance, sales, marketing, operations, IT, compliance and customer service. Ask what data they collect, where it comes from, who sees it, who receives it and when it is deleted.
Do not stop at the main database. Personal data often lives in email inboxes, shared drives, WhatsApp messages, exported spreadsheets, paper files and outsourced service platforms. A lawful basis register is only useful if it reflects those real working practices.
Separate purpose from convenience
A common mistake is to write a broad purpose such as business operations or customer management. That wording is too vague to support a serious lawful basis decision.
Instead, describe the actual purpose. Managing a customer contract, verifying identity for onboarding and sending promotional offers are different purposes. They may involve some of the same data, but they should not automatically share the same lawful basis.
This discipline also improves privacy notices. If your register says one thing and your public notice says another, the organisation has a transparency problem. PLMC’s article on how to build a legal privacy policy that holds up explains why privacy notices should be based on real data flows rather than generic wording.
Identify the lawful condition for each purpose
For each data use, identify the condition that makes the processing lawful. Common conditions to evaluate include consent, necessity for a contract, compliance with a legal obligation, protection of vital interests, public functions and legitimate interests. The correct condition depends on the organisation’s role, the purpose, the relationship with the individual and the applicable law.
Use the terminology of Jamaica’s Data Protection Act rather than copying GDPR labels without analysis. GDPR can be useful for organisations that process EU personal data or benchmark against international practice, but Jamaica data privacy compliance should be grounded in the local Act and regulator expectations.
Document the reasoning in one or two clear sentences. A label alone is not enough. For example, do not simply write consent. Record how consent is requested, how it is captured, whether it can be withdrawn and what happens if the individual refuses.
Treat sensitive personal data as a separate decision
Sensitive personal data needs extra care because misuse can cause greater harm. This may include health information, biometric information, certain identification records or other categories that require heightened protection under the Act.
When sensitive personal data is involved, do not stop at the ordinary lawful basis. Record the additional condition or justification, the necessity of collecting that data and the safeguards in place. This is especially important for employers, healthcare providers, financial institutions, educational institutions and organisations conducting due diligence or security screening.

Record evidence, not just conclusions
The register should point to evidence. If the basis is contract, link to the contract terms or onboarding process. If the basis is legal obligation, identify the relevant law, regulation or statutory requirement. If the basis is legitimate interests, keep the assessment that balances the organisation’s interest against the individual’s rights and expectations.
This does not mean placing confidential legal advice inside a general spreadsheet. Where needed, the register can reference a secure location or document ID. The aim is to make the decision auditable without exposing sensitive internal material to unnecessary access.
Check privacy notices, retention and sharing
Once the draft register is complete, compare it against your privacy notices, consent forms, retention schedule, contracts and processor arrangements. Misalignment is a strong sign that the organisation’s privacy governance is not yet embedded.
For example, if the register records marketing analytics but the privacy notice only mentions order fulfilment, the notice may be incomplete. If the register says CCTV is retained for 30 days but the security team keeps footage indefinitely, the retention control is not working. If a vendor receives employee data but is not listed in a processor inventory or contract register, vendor risk needs attention.
Where the register reveals unresolved issues, treat them as compliance risks, not merely drafting tasks. PLMC’s guide on how to add data protection to your risk register can help organisations escalate and track those issues properly.
Example entries for common data uses
The examples below are not legal advice. They show how to think about documentation. Each organisation should confirm the correct basis based on its facts, sector and legal obligations.
Data use | Condition to evaluate | Evidence to keep | Watch point |
Customer onboarding | Contract necessity, legal obligation or legitimate interests depending on the activity | Application form, service terms, KYC checklist or approval record | Separate service delivery from marketing or profiling |
Employee payroll | Legal obligation and employment-related necessity | Payroll policy, tax and statutory deduction requirements, employment contract | Restrict access because payroll data is highly confidential |
CCTV at business premises | Legitimate interests or security-related necessity | CCTV assessment, signage, retention schedule, access log | Avoid excessive coverage and unnecessary audio recording |
Direct marketing | Consent or legitimate interests depending on channel and context | Consent record, opt-out log or balancing assessment | Make withdrawal or opt-out easy and respected promptly |
AML screening | Legal obligation and compliance necessity | AML policy, screening records, statutory references | Ensure screening data is accurate, proportionate and retained only as needed |
Workplace health accommodation | Sensitive data condition plus employment or legal justification | Accommodation request, medical information handling procedure, restricted access record | Collect the minimum information needed for the decision |
Governance: who should own the register?
The privacy or compliance lead should coordinate the register, but business owners must be accountable for their own data uses. They know why data is collected, how decisions are made and whether practices have changed.
A practical ownership model looks like this:
Role | Responsibility |
Privacy or data protection lead | Maintains the register, sets standards, reviews basis decisions and monitors completion |
Process owner | Confirms the purpose, data categories, actual workflow and business necessity |
Legal or compliance team | Reviews legal basis decisions, regulatory obligations and higher-risk entries |
IT or security team | Confirms systems, access controls, logging, retention tools and security safeguards |
Senior management | Approves risk appetite, resources and remediation for unresolved gaps |
The register should be reviewed at least annually and whenever a material change occurs. Triggers include new systems, new vendors, new data categories, new jurisdictions, new marketing channels, new monitoring tools, mergers, incidents and regulator guidance.
Common mistakes to avoid
Many organisations create a lawful basis register once, then allow it to drift away from reality. That creates a false sense of compliance. The register should remain close to operational change and should be reviewed before new processing starts.
Other common mistakes include:
Using consent as the default basis when another condition is more appropriate
Recording one generic purpose for several unrelated activities
Failing to identify sensitive personal data and extra safeguards
Copying GDPR language without checking Jamaica’s Data Protection Act
Leaving the reasoning column blank
Forgetting paper records, exports and informal communication channels
Failing to align the register with privacy notices, retention rules and vendor contracts
A lawful basis register is most valuable when it is specific enough to support decisions but simple enough for teams to maintain. If it becomes a legal archive that only one person understands, it will not survive day-to-day business change.
How to keep the register alive
Build the register into existing governance processes. New projects should include a lawful basis check before approval. Procurement should ask whether a vendor will process personal data. Marketing should confirm the basis before launching a campaign. HR should review the register before collecting new employee information. IT should involve privacy when deploying tools that monitor users, analyse behaviour or change retention settings.
The best approach is to make the lawful basis register part of change management. When a team asks for a new form field, integration, report or data export, the approval process should ask: what is the purpose, what is the lawful basis, who is affected and how long will the data be kept?
This turns the register from a static compliance document into a working control.
Frequently Asked Questions
Is a lawful basis register required by Jamaica’s Data Protection Act? The Act may not require a document with that exact title, but organisations need to be able to show that personal data is processed fairly, lawfully and for specified purposes. A lawful basis register is a practical way to evidence that accountability.
Is a lawful basis register the same as a data inventory? No. A data inventory records what personal data exists, where it is stored and how it flows. A lawful basis register focuses on why each use is lawful. The two records should be connected.
Can we rely on consent for every data use? Usually not. Consent must be meaningful, informed and capable of being withdrawn. In employment, statutory or essential service contexts, another condition may be more appropriate. Each purpose should be assessed on its own facts.
How often should the register be reviewed? Review it at least once a year and whenever a material processing change occurs. New systems, vendors, data categories, marketing activities and monitoring tools should trigger a review before launch.
What should we do if there is no clear lawful basis? Pause or limit the processing until the issue is resolved. Clarify the purpose, check whether the data is necessary, seek legal or privacy advice and record the final decision. If the activity cannot be justified, it should not proceed in its current form.
Need help building a lawful basis register?
A lawful basis register should be practical, defensible and aligned with your real operations. Privacy & Legal Management Consultants Ltd. supports organisations in Jamaica with data protection implementation, GRC integration, training, risk assessment and compliance documentation.
If your organisation needs help reviewing data uses or preparing for data protection compliance, you can contact PLMC for support and discuss the right next step for your team.
