GDPR
Evidence request list. 40 controls, 40 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Chapter II - Principles
Process personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensive register of criminal convictions may be kept only under the control of official authority. An Article 6 lawful basis is required in addition.
- Identification of where conviction and offence data is processed, including screening and vetting results and incident records
- The Union or Member State provision authorising the processing, and the safeguards that provision requires
- Evidence the required safeguards are actually implemented rather than merely cited
- Access restriction and retention applied specifically to this data, tighter than for ordinary personal data
- Confirmation that no comprehensive register of convictions is maintained outside official authority
- Background screening results retained on the personnel file indefinitely after the hiring decision is made
- Reliance on the candidate's consent where national law, not consent, is the authorisation the Article requires
- Offence data captured in incident reports or free text fields and never treated as Article 10 data
- The authorising law identified but the specific safeguards it mandates never mapped to a control
Where the purposes of processing do not or no longer require the controller to identify the data subject, the controller is not obliged to maintain, acquire or process additional information solely in order to comply with the Regulation. Where the controller can demonstrate it is not in a position to identify the data subject, it must inform the data subject accordingly if possible, and Articles 15 to 20 then do not apply unless the data subject provides additional information enabling identification in order to exercise those rights.
- Analysis of which datasets are processed without the ability to identify the individual, and the basis for that conclusion
- The documented position on why additional identifying information is not held, showing it was not discarded to avoid rights requests
- The response given to a data subject whose request cannot be met for want of identification, including the invitation to supply identifying information
- The procedure for accepting and using additional information a data subject supplies to enable identification
- Article 11 claimed for data that is in fact linkable through a device identifier, an account key or a join with another held dataset
- The data subject never informed that the controller cannot identify them, so the request simply goes unanswered
- Additional identifying information supplied by a data subject refused or ignored rather than used to service the right
- Extra identifiers demanded from every requester as a matter of routine, which is the opposite of what the Article permits
Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
- The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it
- Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs
- Minimisation analysis per collection point showing why each field is necessary for the stated purpose
- Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay
- The compatibility assessment for any further processing carried out for a new purpose
- Assurance output that demonstrates compliance rather than asserts it, such as control testing, internal audit or DPO reporting
- Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them
- Retention periods published in a policy but implemented in no system, so data is in fact kept indefinitely
- Accountability treated as holding the documents rather than being able to show the principles were applied
- Minimisation never revisited after launch, so fields added for a discontinued feature keep being collected
Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the
- A lawful basis recorded per processing activity, not per system or per department
- Legitimate interests assessments showing the interest pursued, the necessity test and the balancing against the data subject's rights
- The Union or Member State provision cited where the basis is legal obligation or public task
- Compatibility assessments for each secondary use, covering the five factors Article 6(4) names
- Evidence that the basis stated to the data subject in the privacy information matches the one recorded internally
- Consent recorded as the basis where the processing would happen regardless of the answer, which makes it neither free nor the real basis
- Legitimate interests asserted with no balancing test on file, or a balancing test that never reaches an adverse conclusion for any activity
- One lawful basis applied to a whole system that covers several distinct processing purposes
- The basis switched after the fact when the first one fails, rather than settled before processing began
Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.
- Consent records capturing who consented, when, to what wording, and through what mechanism
- The consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown
- The withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
- Evidence that consent requests bundled inside terms or a wider declaration are visually and textually separated
- Per service, the analysis of which processing is genuinely necessary for the contract and which rests on consent
- Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to
- Withdrawal routed through a support ticket or a postal address while giving consent was a single click
- Service access blocked on consent to analytics or marketing the service does not need
- Pre-ticked boxes, silence, or continued use of a site treated as consent
Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.
- The assessment of whether the service is an information society service offered directly to children
- The age threshold applied per Member State, with evidence the applicable national lower age was checked rather than assumed
- The age assurance mechanism, and the reasoning for why it is a reasonable effort given available technology
- Parental authorisation records where the user is below the threshold, including the verification carried out on the parent
- The procedure and records for what happens when a user is identified as under age after registration
- A self declared date of birth with no verification at all treated as reasonable effort
- A single threshold of 16 applied across the Union without checking the Member States that set 13, 14 or 15
- Parental consent captured from an email address that is never verified as belonging to a parent
- The service judged not child directed on the basis of its terms of use rather than its actual audience
Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to
- An inventory identifying where special category data is held, including where it is inferred rather than collected
- The Article 9(2) condition recorded per activity alongside its separate Article 6 basis
- The Union or Member State law relied on where the condition requires one, cited to the provision
- Explicit consent records showing the consent was explicit and specific to the special category processing
- Professional secrecy or equivalent confidentiality obligations evidenced for staff handling health data under point (h)
- Special category data inferred from behaviour, purchases or free text and never recognised as in scope
- An Article 6 basis recorded with no Article 9 condition, or the two conflated into a single entry
- Explicit consent asserted from the same tick box used for ordinary consent
- Substantial public interest claimed without identifying the Union or Member State law that authorises it
Chapter III - Rights of the Data Subject
Provide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek
- The request register showing receipt date, response date, and any extension with its notification and stated reasons
- Readability evidence for the privacy information, such as a plain language review or a reading age assessment
- The identity verification standard applied, with the reasoning that it is proportionate rather than routine
- Every refusal or fee decision with the manifestly unfounded or excessive justification recorded against it
- Refusal responses showing both the supervisory authority complaint route and the judicial remedy were given
- The one month clock started when the request reached the privacy team rather than when it reached the organisation
- Extensions taken without notifying the data subject inside the first month, which is the condition attached to the extension
- Identity verification demanded as standard from every requester, adding friction Article 12(6) does not permit
- Refusals issued without the complaint and judicial remedy information, which is a breach separate from the refusal itself
Where personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractua
- The privacy notice mapped item by item against every information element Article 13 lists
- Evidence of the point and timing at which the notice is presented for each collection channel, including forms, telephone and in person
- The storage periods or criteria as published, reconciled against the actual retention schedule
- The published description of automated decision-making logic, and the reasoning for why it is meaningful to a data subject
- Records showing new purpose information was given before the further processing started, with dates
- Recipients described only as third parties or trusted partners, which names neither a recipient nor a category
- Retention shown as for as long as necessary, which is neither a period nor a criterion
- The notice linked from a page footer but not presented at the point of collection, so it is not provided at the time the data is obtained
- Automated decision-making logic described in terms that would fit any system, leaving the data subject nothing to contest
Where personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressl
- A source register showing, per dataset, where the data came from and whether the source was publicly accessible
- Evidence of the notification sent with its date, tested against the one month, first communication and first disclosure triggers
- The disproportionate effort assessment where the exemption is relied on, showing what was weighed rather than only that a conclusion was reached
- The alternative protective measures put in place under that exemption, including where the information was made publicly available
- Supplier contract terms requiring the source of the data and the lawfulness of its collection to be disclosed
- Purchased or enriched marketing data used with no Article 14 notification at all, which is the most common finding in this area
- Disproportionate effort claimed because notifying is inconvenient or costly rather than genuinely disproportionate
- The source recorded as a vendor name with no indication of where the vendor itself obtained the data
- Notification sent at the first marketing contact months after the data was obtained, missing the one month limit
On request, confirm whether personal data concerning the data subject is being processed and, where it is, provide access to that data together with the purposes, the categories of personal data, the recipients or categories of recipient including any in third countries or international organisations, the envisaged storage period or the criteria setting it, the existence of the rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, any available information on the source where the data was not collected from the data subject, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Where data has been transferred to a third country, inform the data subject of the Article 46 safeguards relating to the transfer. P
- The search methodology showing every system, archive and unstructured store searched, and how completeness was assured
- A worked response covering all the supplementary information items, not only the copy of the data
- The redaction position and the applied redaction log where third party data was withheld, with a reason recorded per redaction
- Timeliness records for the last twelve months of requests measured against the one month limit
- The source information provided where the data was not collected from the data subject
- Structured database records returned while email, chat, ticketing and free text notes naming the person are never searched
- The copy of the data provided with none of the supplementary information the Article requires alongside it
- Blanket redaction of anything mentioning another person, rather than a balance carried out item by item
- A fee charged for the first copy, or the request refused for effort where it is not manifestly unfounded or excessive
On request, rectify inaccurate personal data concerning the data subject without undue delay, and, having regard to the purposes of the processing, complete incomplete personal data, including by means of the data subject providing a supplementary statement.
- Rectification records showing the date received, the date the correction took effect, and every system changed
- The procedure for propagating a correction to every copy, including downstream warehouses, reports and exports
- Where a correction is disputed, the data subject's supplementary statement recorded alongside the data rather than filed separately
- Evidence of the Article 19 notification to recipients following each rectification
- The record corrected in the system of origin while copies in the warehouse, the CRM and the backup restore path keep the old value
- Rectification refused because the controller regards its own record as accurate, with no supplementary statement recorded
- Without undue delay interpreted as the full one month by default rather than as promptly as the systems allow
- Corrections made but recipients never told, so the inaccurate value persists outside the organisation
Erase personal data without undue delay where the data is no longer necessary for the purposes it was collected or processed for, where consent is withdrawn and no other legal ground applies, where the data subject objects under Article 21(1) and there are no overriding legitimate grounds or objects to direct marketing under Article 21(2), where the data has been unlawfully processed, where erasure is required by Union or Member State law, or where the data was collected in relation to information society services offered to a child. Where the data has been made public, take reasonable steps including technical measures, allowing for available technology and the cost of implementation, to inform other controllers processing it that erasure of any links to, or copies or replications of, the data has been requested. The obligation does not apply to the extent processing is necessary for fr
- Erasure records showing the ground relied on, the decision, and the date the data actually left each system
- A deletion capability map covering production, replicas, warehouses, logs, search indexes, backups and processors, with method and lag for each
- Where an exemption is applied, the specific Article 17(3) ground and the necessity reasoning for the data actually retained
- Evidence of the reasonable steps taken to inform other controllers where the data had been made public
- Processor deletion confirmations obtained under the Article 28(3)(g) contract term
- Records flagged as deleted in the application while remaining fully readable in the database, the warehouse and the search index
- Backups excluded from erasure with no documented policy on the retention window and on not reinstating erased data at restore
- Legal claims cited as a blanket exemption across all data rather than for the data actually needed for an identified claim
- Erasure performed in house while processors and sub-processors holding the same data are never instructed
Restrict processing on request where the data subject contests the accuracy of the data, for a period enabling the controller to verify it; where the processing is unlawful and the data subject opposes erasure and asks for restriction instead; where the controller no longer needs the data but the data subject requires it for the establishment, exercise or defence of legal claims; and where the data subject has objected under Article 21(1), pending verification of whether the controller's legitimate grounds override theirs. Restricted data may be stored but otherwise processed only with the data subject's consent, for legal claims, for the protection of another person's rights, or for reasons of important public interest. Inform the data subject before a restriction is lifted.
- The technical mechanism that enforces restriction, such as a flag that blocks processing rather than one that is advisory only
- Restriction records showing the ground, the date applied, and the date and reason for lifting
- Evidence the data subject was informed before each restriction was lifted
- Testing showing restricted records are excluded from downstream processing, marketing selections and analytics
- Evidence of the Article 19 notification to recipients following each restriction
- Restriction implemented as a note on the record that no system enforces, so processing continues unchanged
- Restriction lifted the moment the accuracy check completes, with no prior notice to the data subject
- Restricted records still flowing into exports, reports and model training because only the customer facing application reads the flag
- No distinction maintained between restriction and erasure, so the request is actioned as a deletion the data subject did not ask for
Communicate every rectification, erasure or restriction of processing carried out under Articles 16, 17(1) and 18 to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. Inform the data subject about those recipients if the data subject requests it.
- A recipient register per dataset, current enough to answer who must be told when a record changes
- Notification records tied to individual rectification, erasure and restriction actions, with dates and recipients
- The impossible or disproportionate effort assessment for any recipient not notified
- The response given to a data subject who asked which recipients were informed
- No recipient register exists, so the obligation cannot be performed and is silently skipped
- Notification treated as covered by the processor contract rather than as an act the controller must carry out and evidence
- Recipients told about erasures but not about rectifications or restrictions, which the Article treats identically
- A data subject's request to know the recipients answered with categories when the specific recipients are known
Where processing is based on consent or on a contract and is carried out by automated means, provide the personal data the data subject has provided to the controller in a structured, commonly used and machine-readable format, and do not hinder its transmission to another controller. Where technically feasible, transmit the data directly from one controller to another at the data subject's request. The right is without prejudice to the right to erasure, does not apply to processing necessary for the performance of a public interest task or the exercise of official authority, and must not adversely affect the rights and freedoms of others.
- Identification of which datasets are in scope, being data provided by the data subject under consent or contract and processed by automated means
- The export format and a sample export, showing it is structured and machine-readable rather than a rendered document
- The direct controller to controller transmission capability where one exists, and the technical feasibility assessment where it does not
- The rule applied for excluding data about other people from an export, and evidence it was applied
- A rendered document or a printed screen supplied and described as a machine-readable format
- Observed data such as usage history and device telemetry excluded on the view that only typed form fields were provided by the data subject
- Portability conflated with access, so the response is an access pack rather than a reusable dataset
- Export delayed or made difficult to discourage switching, which is the hindrance the Article prohibits
Where processing is based on the performance of a public interest task, official authority or legitimate interests, including profiling on those bases, the data subject may object at any time on grounds relating to their particular situation, and processing must stop unless the controller demonstrates compelling legitimate grounds that override the data subject's interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. Where personal data is processed for direct marketing, including profiling related to that marketing, the objection is absolute and processing for that purpose must stop with no balancing. Bring the right explicitly to the data subject's attention at the latest at the time of the first communication, presented clearly and separately from any other information. In the context of information society services, allow the
- Objection records that distinguish direct marketing objections, which are absolute, from Article 21(1) objections, which are balanced
- The compelling legitimate grounds analysis for every Article 21(1) objection that was refused
- Evidence the right to object was presented clearly and separately at first communication, such as the template or screen as sent
- Suppression list operation showing an objection propagates to every marketing channel and survives the next data import
- The automated objection mechanism offered on information society services
- A direct marketing objection put through a balancing test, when Article 21(3) allows no balancing at all
- Suppression applied in one channel while the same person is marketed to again by another channel or through a partner list
- The right to object buried in a privacy notice rather than presented clearly and separately at first contact
- Suppression records deleted in the name of data minimisation, so the objection is lost and the person is contacted again
Do not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in p
- An inventory of automated decisions with the assessment of whether each produces legal or similarly significant effects
- The exception relied on for each in scope decision, and for contract based ones the necessity reasoning rather than a convenience argument
- The human intervention process, showing the reviewer has the authority and the information to change the outcome
- Records of contested decisions and the outcome of each review
- Confirmation of whether special category data, including proxies for it, enters the model, and the safeguards applied where it does
- A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance
- Necessity for a contract asserted where a manual or hybrid process would work and is merely more expensive
- Special category data entering the model through proxies such as postcode, name or purchase history with no assessment
- No route for the data subject to contest the decision, only a route to complain about service
Chapter IV - Controller and Processor
Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that processing is performed in accordance with the Regulation, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Review and update those measures where necessary. Where proportionate in relation to the processing activities, the measures must include implementing appropriate data protection policies. Adherence to an approved code of conduct or an approved certification mechanism may be used as one element by which to demonstrate compliance, not as a substitute for it.
- The data protection policy set, each with an approval authority, an effective date and a review cycle
- The risk assessment that drove the choice of measures, referencing nature, scope, context, purposes and risk to individuals
- Review records showing the measures were reassessed and updated after material changes to the processing
- The assignment of data protection responsibilities across the organisation, and evidence the assignees act on them
- Assurance output such as internal audit, control testing or DPO reporting that demonstrates rather than asserts compliance
- A policy suite adopted once and never reviewed, so it describes processing the organisation no longer carries out
- Measures selected from a generic checklist with no link to the risk this organisation's own processing presents
- Accountability documentation that records what should happen with no evidence that it does
- Certification or code adherence presented as the whole of compliance rather than as one element of it
Both at the time the means of processing are determined and at the time of the processing itself, implement appropriate technical and organisational measures such as pseudonymisation which are designed to implement the data protection principles, in particular data minimisation, in an effective manner and to integrate the necessary safeguards into the processing, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons. Separately, implement measures ensuring that by default only the personal data necessary for each specific purpose is processed, covering the amount of data collected, the extent of the processing, the period of storage and the accessibility of the data, and in particular ensuring that personal data is not by d
- Design stage privacy review records for new and materially changed processing, dated before the means of processing were fixed
- The default configuration of each product surface, showing what is on out of the box for collection, sharing, visibility and retention
- The pseudonymisation, aggregation or separation techniques applied, and where they were considered and rejected the reason recorded
- Change records showing privacy requirements were tracked as delivery requirements rather than as advice
- Evidence that no personal data is by default accessible to an indefinite audience without an act by the individual
- Privacy review performed at launch approval rather than at design, when the decisions it should influence are already sunk
- Defaults set to the widest sharing and the longest retention, putting the burden on the individual to reduce them
- By design treated as satisfied by encryption alone, with no minimisation of what is collected in the first place
- The Article read as a single obligation, so the by default limb on amount, extent, storage period and accessibility is never separately evidenced
Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Union or Member State law, covering in particular the exercise of the data subject's rights and each party's duty to provide the Article 13 and 14 information. The arrangement may designate a contact point for data subjects. It must duly reflect the parties' respective roles and relationships towards data subjects, and its essence must be made available to the data subject. Irrespective of the terms of the arrangement, a data subject may exercise their rights in respect of and against each of the controllers.
- The joint controllership assessment identifying every relationship where purposes and means are jointly determined
- The Article 26 arrangement for each, allocating responsibility for rights handling, transparency, security and breach response
- The essence of the arrangement as published or otherwise made available to data subjects
- Evidence the allocation reflects the real roles, such as which party holds the data and which faces the data subject
- The operating process showing a rights request is honoured whichever joint controller receives it
- A controller to processor agreement used where the relationship is in substance joint controllership
- An arrangement signed but its essence never made available to data subjects, which is a separate obligation
- Rights requests passed back and forth between joint controllers, when the data subject may exercise them against either
- The allocation written to suit the commercial balance of power rather than the actual roles towards data subjects
Where the Regulation applies under Article 3(2) to a controller or processor not established in the Union, designate a representative in the Union in writing, established in one of the Member States where the data subjects whose data is processed in relation to the offering of goods or services, or whose behaviour is monitored, are located. Mandate the representative to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues related to processing. The obligation does not apply to processing which is occasional, does not include large scale processing of special category or criminal offence data and is unlikely to result in a risk to the rights and freedoms of natural persons, nor to a public authority or body. Designating a representative is without prejudice to legal actions against the controller or processor th
- The Article 3(2) applicability assessment covering the offering of goods or services to, and the monitoring of behaviour of, data subjects in the Union
- The written mandate appointing the representative, with scope covering supervisory authorities and data subjects on all processing issues
- The representative's contact details as published in the privacy information and otherwise made available to data subjects
- The reasoning where the Article 27(2) exemption is relied on, addressing occasional, large scale and risk in turn
- Evidence the representative can access records and respond, such as an escalation procedure and actual response records
- A representative appointed in a Member State chosen for administrative convenience rather than where the data subjects are
- The appointment made but the contact details never published, so no data subject can actually use it
- A group entity named as representative with no written mandate defining what it is authorised to receive
- The occasional processing exemption claimed for a continuously available online service, which is not occasional
Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised t
- A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it
- The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names
- Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract
- The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified
- Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
- The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
- A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
- Sufficient guarantees evidenced only by the existence of the contract, with no assessment carried out before appointment
- Sub-processor lists published by the processor and never actually reviewed, so the right to object is theoretical
The processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.
- The documented instructions issued to each processor, and the mechanism by which they are kept current
- Employment or contract terms binding staff and contractors to process personal data only as instructed
- Access controls that make the technical scope of access match the instructions actually given
- Monitoring or logging capable of detecting processing outside instruction, and records of any detection
- Where a legal requirement overrides instructions, the record of the requirement and the notification given to the controller
- Instructions existing only as the original contract, never updated as the processing changed over years of service
- Staff holding broad standing access to production personal data far beyond what their instructed tasks require
- No means of detecting processing outside instruction, so the obligation is asserted and never tested
- Processor use of controller data for its own purposes, such as service improvement or model training, permitted by a clause nobody negotiated
Maintain a written, including electronic, record of processing activities under the controller's responsibility containing the name and contact details of the controller, any joint controller, the representative and the data protection officer, the purposes of the processing, a description of the categories of data subjects and of personal data, the categories of recipients including those in third countries and international organisations, any transfers to a third country or international organisation with that destination identified and, for transfers under the second subparagraph of Article 49(1), the documentation of suitable safeguards, the envisaged time limits for erasure of each category where possible, and a general description of the Article 32(1) technical and organisational security measures where possible. A processor must maintain an equivalent record of the categories of p
- The record of processing activities in full, checked against the seven controller elements, or the four processor elements, the Article lists
- Version history showing when each entry was last reviewed and by whom
- Reconciliation of the record against a system inventory or data flow map, to show nothing is missing rather than that the entries read well
- The transfer entries with the third country identified and the safeguard documentation referenced
- Where the fewer than 250 persons exemption is claimed, the assessment against all three disqualifying conditions
- Records written once during the implementation project and never updated against reality, so they describe systems long replaced and omit those adopted since
- Entries written at the level of a department or a system rather than a processing activity, which loses the purpose that everything else hangs off
- Erasure time limits left blank throughout on the where possible qualifier, while a retention schedule exists elsewhere in the organisation
- The small organisation exemption claimed on headcount alone, ignoring that regular non-occasional processing disqualifies it
The controller and the processor and, where applicable, their representatives must cooperate, on request, with the supervisory authority in the performance of its tasks. In practice that means responding to the authority's requests for information, access and assistance within the time it sets, completely and accurately, whether the request arises from a complaint, an investigation, an audit or an own initiative inquiry, and ensuring the records the authority is entitled to see can actually be produced.
- A named owner and a documented route for handling correspondence from a supervisory authority, covering local languages and absence cover
- The log of authority contacts, complaints and requests, with the response given and its date against any deadline set
- Evidence that requested information was assembled from source records rather than asserted, including the underlying records provided
- Where a deadline was missed or an extension sought, the record of the request and the authority's response
- Contractual and operational arrangements binding processors and representatives to cooperate through the controller
- Authority correspondence arriving at a general or legal mailbox and sitting unactioned past the deadline, which is an infringement separate from the matter under inquiry
- Responses drafted to minimise disclosure, which converts a procedural request into a finding of non-cooperation and aggravates the eventual penalty
- No owner for the relationship, so each request is handled from scratch and successive responses take inconsistent positions
- Records of processing and impact assessments not held in a state where they can be produced on request, so cooperation fails on evidence rather than on intent
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing,
- The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation
- Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate
- Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome
- The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out
- Evidence the measures were reassessed after material change in processing, technology or threat
- Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
- Backups taken and never restore tested, so the ability to restore in a timely manner is assumed rather than demonstrated
- Article 32(1)(d) treated as satisfied by an annual perimeter penetration test, with the organisational measures never evaluated at all
- Encryption stated as in place while key management, backup copies and third party copies sit outside its scope
On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in ph
- The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each
- The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment
- Notifications as submitted, checked against the four content elements Article 33(3) requires
- The methodology used to decide notifiability, and evidence it was applied rather than the decision reached first and documented after
- Processor contract terms requiring notification without undue delay, and the notification times actually achieved
- The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
- Breaches judged not notifiable with no documented assessment, leaving nothing for the authority to verify under Article 33(5)
- The register recording only breaches that were notified, so the unlikely to result in a risk decisions are invisible
- Processor notification terms that say promptly or within a commercially reasonable time, which cannot support the controller's 72 hours
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving at least the contact point, the likely consequences and the measures taken or proposed including mitigation. Communication is not required where the controller had implemented appropriate technical and organisational protection measures and applied them to the affected data, in particular measures such as encryption rendering the data unintelligible to anyone unauthorised, where the controller has since taken measures making the high risk no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be made inst
- The high risk assessment per breach, kept distinct from the Article 33 assessment, which uses a lower threshold
- The communication as sent, assessed for clear and plain language and for the three content elements required
- Where the encryption exemption is relied on, evidence the measure covered the specific affected data and that the keys were not also compromised
- Where disproportionate effort is claimed, the public communication actually made and evidence of the reach it achieved
- Timing records showing the interval between awareness of high risk and communication to individuals
- Communication deferred until the investigation completes, when the Article requires it without undue delay once high risk is identified
- The encryption exemption claimed generally for an encrypted estate without showing it covered the data actually lost
- Notices written in legal or technical language, failing the clear and plain language requirement even where the timing was met
- Individuals told what happened but not the likely consequences or what to do, which is the part that lets them protect themselves
Where a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is de
- The screening or threshold process applied to new and changed processing, with its outcomes recorded including the negative ones
- Completed assessments checked against the four minimum content elements Article 35(7) requires
- The data protection officer's advice sought and given on each assessment, recorded as advice rather than as approval
- Where the views of data subjects were sought, the record of what was asked and what came back, or the reasoning for not seeking them
- Review records showing assessments were revisited when the processing or its risk changed, with the date and the trigger
- An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
- Necessity and proportionality asserted in a sentence, with all the substance of the assessment sitting in the security measures
- Risk assessed to the organisation rather than to the rights and freedoms of the individuals the processing affects
- Screening applied only to new projects, so material change to existing high risk processing never triggers an assessment
- The data protection officer asked to approve the assessment rather than to advise on it, which compromises the independence Article 38(3) requires
Consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate that risk. When consulting, provide the respective responsibilities of the controller, any joint controllers and the processors involved, the purposes and means of the intended processing, the measures and safeguards provided to protect the rights and freedoms of data subjects, the contact details of the data protection officer where applicable, the impact assessment itself, and any other information the authority requests. The authority has up to eight weeks to provide written advice where it considers the intended processing would infringe the Regulation, extendable by six weeks with notification of the extension and its reasons, and may use its Article 58
- The decision record for each impact assessment that concluded on residual high risk, showing whether consultation was triggered and on what reasoning
- The consultation submission carrying all six information items Article 36(3) requires
- The authority's written advice and the changes made to the processing in response, tracked to closure
- Evidence that the processing did not begin before the consultation concluded
- Where national law requires prior authorisation for public interest processing, the authorisation obtained
- Residual risk written down to medium in the assessment precisely to avoid the consultation trigger, with no measure actually added to justify the reduction
- Processing launched while the consultation is still open, which defeats the word prior in prior consultation
- The consultation submitted without the impact assessment attached, so the authority cannot assess what it is being asked about
- Authority advice received and filed without tracking whether the recommended changes were made
Designate a data protection officer where the processing is carried out by a public authority or body, except for courts acting in their judicial capacity, where the core activities consist of processing operations which by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of processing on a large scale of special category data or of personal data relating to criminal convictions and offences. A group of undertakings may appoint a single data protection officer provided that officer is easily accessible from each establishment. Designate on the basis of professional qualities, in particular expert knowledge of data protection law and practice and the ability to fulfil the Article 39 tasks. The officer may be a staff member or fulfil the tasks under a service contract. Publish the officer's con
- The Article 37(1) assessment, made whether or not an officer was appointed, showing how core activities, large scale and regular and systematic monitoring were judged
- The designation record, with evidence the contact details were both published and communicated to the supervisory authority
- The officer's qualifications and experience measured against the data protection risk the organisation's processing presents
- Where a group officer is appointed, evidence of accessibility from each establishment including language and working hours
- The officer's other roles and duties, with the conflict of interests analysis for each
- No appointment made and no assessment on file, so the absence of an officer cannot be justified when it is challenged
- Contact details published on the website but never communicated to the supervisory authority, which is a separate requirement
- The role given to the head of information technology, legal or compliance, who determines purposes and means and therefore cannot independently monitor them
- A single group officer with no realistic capacity or language coverage for the establishments nominally served
Ensure the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data. Support the officer in performing the Article 39 tasks by providing the resources necessary to carry them out, access to personal data and processing operations, and the means to maintain expert knowledge. Give the officer no instructions regarding the exercise of those tasks, do not dismiss or penalise the officer for performing them, and have the officer report directly to the highest management level. Data subjects may contact the officer on all issues related to the processing of their personal data and the exercise of their rights. The officer is bound by secrecy or confidentiality concerning the performance of the tasks. The officer may fulfil other tasks and duties, and the controller or processor must ensure those do not result in a confl
- Evidence of timely involvement, such as standing membership of change, project and incident forums with attendance records
- The reporting line as documented and as actually practised, including direct access to the highest management level and records of that access being used
- The resource position: budget, staff, training days and system access rights granted to the officer
- The conflict of interests assessment for any other duties the officer holds, refreshed when those duties change
- Terms of engagement evidencing protection from dismissal or penalty for performing the tasks
- The officer consulted after decisions are taken, at approval rather than at design, which is not timely involvement
- A reporting line to the highest management level that exists on paper and has never been used, with all real reporting through a manager whose work the officer must assess
- The role held alongside responsibility for the systems and processing being assessed, which the Article treats as a conflict of interests
- No budget or training allocation, so maintaining expert knowledge depends on the officer's own time
The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection provisions; monitor compliance with those provisions and with the controller's or processor's own data protection policies, including the assignment of responsibilities, awareness raising, the training of staff involved in processing operations, and the related audits; provide advice where requested on the data protection impact assessment and monitor its performance under Article 35; cooperate with the supervisory authority; and act as the contact point for the supervisory authority on processing issues including the Article 36 prior consultation, consulting on any other matter where appropriate. In performing these tasks the officer must have due regard to the risk ass
- The officer's monitoring plan and its output, such as a review or audit programme with findings and their closure
- Advice given, recorded with its date and outcome including where it was not followed and by whose decision
- Training and awareness activity delivered or overseen, with coverage figures for the staff involved in processing operations
- The officer's record of contacts as supervisory authority contact point, and of impact assessment advice given under Article 35(2)
- Evidence the monitoring effort is weighted by processing risk rather than spread evenly across the organisation
- The officer acting as the compliance delivery function, writing and running the very controls they are meant to independently monitor
- Advice given verbally and never recorded, so there is no evidence of what was recommended when a decision is later questioned
- Monitoring reduced to a policy review cycle, with no testing of whether the processing actually follows the policy
- No record kept of advice that was overridden, which is the evidence that most protects both the officer and the organisation
Chapter V - Transfers of Personal Data
Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
- A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on
- The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism
- Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data
- The reasoning that the level of protection is not undermined by the arrangement as a whole, not only by the chosen instrument
- Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
- The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from
- Onward transfers by the recipient left uncovered, so the chain breaks one step beyond the direct relationship
- A mechanism recorded per vendor rather than per transfer, so several distinct transfers share one unexamined justification
Personal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.
- Per transfer, the adequacy decision relied on identified by instrument, with confirmation the recipient and the data fall inside its territorial and sectoral scope
- A monitoring process for changes to adequacy decisions, with a named owner and evidence it has actually been run
- The fallback plan for each adequacy based transfer should the decision be suspended or repealed, tested against the Article 46 and 49 options
- Where a decision covers only certified or listed recipients, evidence the recipient's current status was verified
- Adequacy assumed for a whole country where the decision covers only a sector or only listed recipients, with the recipient's listing never verified
- No monitoring for suspension or invalidation, so a transfer continues on a decision that has since been struck down
- Adequacy relied on for the direct transfer with no consideration of onward transfers out of the adequate country
- The decision recorded at contract signature and never rechecked at the periodic review point
In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, s
- The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank
- The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there
- The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place
- Supervisory authority authorisation where ad hoc contractual clauses or administrative arrangements are relied on
- Evidence that data subjects can in practice exercise the rights the instrument confers, such as an operable third party beneficiary route
- Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
- No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable
- Supplementary measures identified in the assessment and never implemented, leaving open the gap the assessment found
- The instrument signed with the contracting entity while group companies that actually access the data are never brought inside it
Binding corporate rules must be approved by the competent supervisory authority under the consistency mechanism, must be legally binding on and enforced by every member of the group including its employees, and must expressly confer enforceable rights on data subjects. They must specify at least the structure and contact details of the group and each member, the transfers and data covered, their legally binding nature internally and externally, the application of the general data protection principles, the rights of data subjects and the means to exercise them, the acceptance by the Union established member of liability for breaches by members outside the Union, how information about the rules is provided to data subjects, the tasks of the data protection officer or other monitoring role, the complaint procedures, the verification mechanisms including data protection audits and correctiv
- The approval decision from the competent supervisory authority and the approved text as it currently stands
- The internal instrument making the rules binding on each group member and on employees, such as an intra-group agreement and employment terms
- The audit programme the rules commit to, with completed audits, findings and corrective actions closed
- The change log for the rules and for group membership, and evidence changes were reported to the supervisory authority as the rules require
- Training records for personnel with permanent or regular access, and the complaint handling records operated under the rules
- Rules approved years ago while the group has since acquired entities never brought inside the binding instrument
- The verification and audit mechanism written into the rules and never operated, which is the commitment authorities test first
- Changes to the rules or to the group made without the reporting to the supervisory authority the rules commit to
- Binding corporate rules treated as covering every transfer, including to third parties outside the group, which they cannot
A judgment of a court or tribunal, or a decision of an administrative authority, of a third country requiring a controller or processor to transfer or disclose personal data may be recognised or enforceable only if it is based on an international agreement in force between the requesting third country and the Union or a Member State, such as a mutual legal assistance treaty, without prejudice to the other grounds for transfer in Chapter V. In practice the controller or processor must not treat a foreign order as being by itself a lawful ground to hand over personal data, and must route such demands through the applicable mutual legal assistance route or another Chapter V ground before disclosing.
- A documented procedure for receiving and handling third country law enforcement, regulatory and court demands for personal data, requiring legal review before any disclosure
- The register of such demands received, showing the requesting authority, what was sought, the legal basis assessed, and what was disclosed or refused
- Evidence that each disclosure was traced to an international agreement in force or to another Chapter V ground, and not to the foreign order alone
- Processor contract terms requiring notification to the controller of any third country demand and requiring the processor to challenge or defer it where lawful
- A transparency report or equivalent record of demands received and responses given, where publication is permitted
- Group companies or processors outside the Union complying with local subpoenas directly, with the controller in the Union never told that its data left
- A foreign order treated as a legal obligation under Article 6(1)(c), which the Regulation does not accept as a ground for a third country disclosure
- No procedure at all, so a demand is answered by whoever receives it, under time pressure and without legal review
- Processor terms silent on foreign demands, so notification depends on goodwill and the controller learns of the disclosure only if it is later reported
In the absence of an adequacy decision and of appropriate safeguards, a transfer to a third country or an international organisation may take place only on one of the Article 49(1) conditions: the data subject's explicit consent after being informed of the possible risks arising from the absence of adequacy and safeguards; necessity for the performance of a contract with the data subject or pre-contractual measures at their request; necessity for a contract concluded in the data subject's interest between the controller and another person; important reasons of public interest recognised in Union or Member State law; the establishment, exercise or defence of legal claims; protection of the vital interests of a person incapable of giving consent; or a transfer from a register which by law is intended to provide information to the public, limited to the conditions for consultation. Where no
- A register of transfers relying on Article 49, with the specific condition cited and the reasoning recorded per transfer
- Where explicit consent is used, the record showing the data subject was informed of the specific risks arising from the absence of adequacy and safeguards
- Where the compelling legitimate interests route is used, the documented assessment, the suitable safeguards, the notification to the supervisory authority and the information given to the data subject
- The Article 30 record entries documenting that assessment and those safeguards, as Article 49(6) requires
- Evidence that reliance on Article 49 is occasional and non-repetitive rather than the standing basis for a routine transfer
- A derogation used as the permanent basis for routine systematic transfers, when derogations are for specific situations and must remain exceptional
- Necessity for a contract stretched to cover transfers that merely make the service cheaper or more convenient to operate
- Explicit consent obtained without informing the data subject of the risks, which is the specific condition Article 49(1)(a) attaches to it
- The compelling legitimate interests route used without the supervisory authority notification and the data subject information, both of which are mandatory conditions
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GDPR framework page.