Guides · 2.1

How records work

Records, references, states, links, gaps and the audit trail. Learn these once and every register reads the same way.

Records and references

A record is one answer set about one thing: one processing activity, one processor, one breach. Prudence assigns the reference, for example PA-00001 for a processing activity or DOC-00004 for a document, and suggests a name from the register and the date. Replace that name with wording your colleagues would use.

Answers are grouped into numbered pages: Details, Context, Accountability, Assessment, Lifecycle and Evidence. A number beside a page name counts the answers still owed on it.

A processing activity. Special category data is asked first, because the categories and the condition follow from it.
A processing activity. Special category data is asked first, because the categories and the condition follow from it.

States and the path through them

Every record moves along one path. A processing activity runs from draft, through legal review and approved, to in use, and then to suspended or retired. The rail at the top of a record shows where it stands now and offers exactly one step forward, plus the ending states.

A record only enters the Article 30 record of processing when it reaches in use. That is the line at which the duties in the regulation begin to bite.

The state rail. The state now is ringed, and the steps available from here are listed beneath it.
The state rail. The state now is ringed, and the steps available from here are listed beneath it.

Taking a step

A step asks for confirmation and states what the step means. Answers that are required for the destination state are listed as required, and answers that are merely expected are listed separately. You can complete them in place, without closing the record.

Confirming a step saves the record and writes the step to the history.

Confirming a step. Required answers are separated from expected ones and can be completed here.
Confirming a step. Required answers are separated from expected ones and can be completed here.

Gaps, severity and remedies

A gap is a statement that the regulation asks for something the records do not yet show. Each gap carries a severity, the article behind it, and a remedy that opens the exact record and highlights the field to complete. Every remedy is a shareable link.

Gaps are computed from the records as you type, so completing an answer clears the gap immediately.

The gaps view, ordered by severity, each with the remedy that closes it.
The gaps view, ordered by severity, each with the remedy that closes it.

The audit trail

Every creation, change and step is written to the history with the date, the identity acting and the detail of what changed. Article 5(2) asks the controller to be able to demonstrate compliance, and this is the demonstration. The trail can be searched.

The audit trail, searchable across date, action, role and detail.
The audit trail, searchable across date, action, role and detail.

Identities and roles

People in your workspace are bound to roles: the Data Protection Officer who advises, the authors who write records, the owners who are accountable for them, and the approvers who sign them off. A record reads differently to each role, and only the approver may confirm the step that puts a record into use.