INTRA/GV/GV004Roles and decision rights
The statement of which decisions the program may take, of the role entitled to take each, and of the person holding that role. The decisions are the ones the framework names elsewhere: to open a case on a person, to reach for the content of what they wrote, to withdraw their access before any finding, and to recommend a consequence.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| GV004/ITMandatory | Italy | Provvedimento del 17 aprile 2026, Framos ItaliaGarante per la protezione dei dati personali · read 29 Aug 2026 | That a company mailbox left running after the employment ends is a processing needing a ground of its own, and that a smooth handover and the chance of wanting something later are not one. | The technician who reached into the accounts held the role and not the instruction. A signed confidentiality undertaking is not the documented instruction the Regulation asks of anyone processing on the controller’s behalf. |
| Recommended | United Kingdomwhere written | Insider Risk Practitioners and StakeholdersNPSA · read 29 Aug 2026Board Engagement and GovernanceNPSA · read 29 Aug 2026 | That a program needs a senior stakeholder group drawn from named functions, and a director who carries the board’s strategy into policy. | One board member holds overall responsibility for protective security, and a non-executive director acts as an independent champion for it. Below them a director carries the strategy into policy, and senior staff in each business area answer for the risk assessment and for implementation in their own. |
