Skip to content
SecuriFii

Evidence

Records of processing: the artefact every privacy obligation leans on

It looks like paperwork and it is infrastructure. Nearly every privacy obligation resolves to a question this record answers.

Facts checked2026-09-11

What must a record of processing contain?

What personal data you hold, the purposes it is processed for, the categories of data subject, who it is shared with including sub-processors, any transfers outside the country, retention periods, and a description of the security measures applied.

The work is rarely the document — it is the discovery. Personal data accumulates in support tools, analytics, log files, spreadsheets and backups, and the first honest inventory is usually a surprise. That is exactly why it precedes the notice, the consent mechanics and the rights process, all of which depend on knowing what you actually hold.

The bottom line

Do the mapping first. Every downstream privacy decision depends on it, and every one of them is wrong if it is wrong.

Related insights