Skip to main content

Conduct an information audit — Conduct an information audit to determine what information you process and who has access to it

Organizations that have at least 250 employees or conduct higher-risk data processing are required to keep an up-to-date and detailed list of their processing activities (article 30) and be prepared to show that list to regulators upon request. The best way to demonstrate GDPR compliance is using a data protection impact assessment (article 35). Organizations with fewer than 250 employees should also conduct an assessment because it will make complying with the GDPR's other requirements easier. In your list, you should include: the purposes of the processing, what kind of data you process, who has access to it in your organization, any third parties (and where they are located) that have access, what you're doing to protect the data (e.g. encryption), and when you plan to erase it (if possible).

PropertyValue
SectionLawful basis and transparency
Ownerplatform

Mapped Controls

ControlTitle
SID-AUDIT-01Structured Security Event Logging

Source: GDPR Checklist for Data Controllers