Know what you process
- Maintain records of processing activities under Article 30.
- Record the lawful basis for each processing activity.
- Record retention periods and deletion behaviour per data category.
- Identify international transfers and the mechanism relied on.
Respect individual rights
- Provide a route for access, rectification, erasure, portability and objection requests.
- Track requests with owners and deadlines; the default response window is one month.
- Be able to show how a request was handled after the fact.
Manage processors
- Keep an inventory of processors and sub-processors.
- Hold data processing terms with each processor.
- Review processors on a defined cycle rather than only at onboarding.
Secure and prove
- Implement and document Article 32 technical and organisational measures.
- Run DPIAs where processing is likely to be high risk.
- Be able to detect, assess and report a personal data breach within 72 hours where required.
Most of these obligations are ongoing records, not one-off documents. Keeping them in a system rather than a folder is what makes them defensible.
See this in the product
Compliancy holds the controls, evidence and records described above in one platform.