The business or product owner should describe the activity and UK market facts. Privacy or legal should review the Article 2 and 3 analysis and exclusions. Procurement and engineering should confirm supplier roles, hosting, data flows, and whether a non-UK provider processes data in the context of a UK offer or monitoring activity.
The scope record should show the activity, data and people, automation or filing-system status, UK connection, exclusions considered, role analysis, systems and recipients, conclusion, date, reviewer, and events that require reassessment. Lawful basis, notices, rights, security, and transfers follow only after this threshold decision.