Data protection is a duty of accountability — Art. 5(2) GDPR calls this the "accountability principle." You must not only act in compliance with data protection law, you must also be able to prove it. That means complete, up-to-date documentation.
The key documents at a glance
- Records of Processing Activities (RoPA) — Art. 30 GDPR. The RoPA is the centerpiece of data protection documentation. It lists every processing activity, including purpose, legal basis, categories of data subjects, retention periods, and recipients. More on RoPA
- Technical and Organizational Measures (TOMs) — Art. 32 GDPR. The TOM document describes how you protect data: access control, encryption, access authorizations, backups, contingency plans, and more. More on TOMs
- Privacy notice — Art. 13/14 GDPR. Every website needs a complete privacy notice. It informs users about all data processing activities, the services used, and their rights. More on privacy notices
- Data Processing Agreements (DPAs) — Art. 28 GDPR. For every service provider that processes data on your behalf, you need a written DPA. Without this agreement, the processing is unlawful. More on DPAs
- Data Protection Impact Assessment (DPIA) — Art. 35 GDPR. For processing activities that pose a high risk to data subjects, a DPIA is mandatory. It analyses the risk and shows how it can be minimized. More on DPIAs
- Deletion concept — Art. 5(1)(e) GDPR. Personal data may only be stored for as long as the purpose requires. A deletion concept defines retention periods and implements them systematically.
Why documentation often fails
In practice, we repeatedly see the same problems:
- Created once, never updated. A RoPA created three years ago no longer reflects the current software landscape — especially once new tools have been introduced.
- Too generic. Documents designed to fit every company don't really fit any of them. Data protection documentation has to be company-specific.
- Not findable. Even the best documentation is useless if it cannot be produced when it matters. Clear filing structures are part of the system.
- No clear ownership. Who updates the RoPA when new software is introduced? Who reviews the DPA list every year? Without clear responsibilities, documentation decays.
Our approach: documentation that lasts
We don't create documents that gather dust after handover. We build a documentation structure with you that is actually maintainable, and on request we take over ongoing updates as part of our DPO service.
What supervisory authorities ask for during an inspection
When a data protection supervisory authority conducts a review — whether following a complaint or as part of a routine inspection — it typically asks for:
- Records of Processing Activities (Art. 30 GDPR)
- The website's privacy notice
- Data Processing Agreements with service providers
- Appointment of the Data Protection Officer (where required)
- Evidence of employee training
- Documentation of data breaches (even ones not reported internally)
- Data Protection Impact Assessments (for high-risk processing)
Anyone who cannot produce these documents comes under pressure — even if actual practice is sound.