Demonstrating rather than asserting.
WHAT ACCOUNTABILITY REQUIRES
Being able to show what you do and why.
WHAT TO MAINTAIN
A record of processing activities Privacy notices, with version history Lawful basis assessments Legitimate interest assessments Impact assessments Processor agreements The sub-processor list Retention schedule Security measures documentation Training records Breach register Rights request log
WHY A BREACH REGISTER INCLUDING UNNOTIFIED ONES
You may need to show the assessment, not just the notifications.
WHAT MAKES DOCUMENTATION CREDIBLE
Being produced by the process rather than assembled afterwards.
WHAT MAKES IT USELESS
Describing practices nobody follows.
WHY
It becomes evidence against you.
WHAT TO DO
Document what you actually do, then improve it.
WHAT TO REVIEW
Everything, annually, and when things change.
WHO SHOULD OWN IT
A named person.
WHERE TO KEEP IT
Somewhere accessible and version-controlled.
WHAT TO PREPARE FOR A REGULATOR ENQUIRY
The above, current.
WHY IN ADVANCE
Assembling it under enquiry is visible and unconvincing.
WHAT TO BE HONEST ABOUT
Gaps, with a plan to address them.