Evidence
Records of processing: the artefact every privacy obligation leans on
It looks like paperwork and it is infrastructure. Nearly every privacy obligation resolves to a question this record answers.
Facts checked — 2026-09-11
What must a record of processing contain?
What personal data you hold, the purposes it is processed for, the categories of data subject, who it is shared with including sub-processors, any transfers outside the country, retention periods, and a description of the security measures applied.
The work is rarely the document — it is the discovery. Personal data accumulates in support tools, analytics, log files, spreadsheets and backups, and the first honest inventory is usually a surprise. That is exactly why it precedes the notice, the consent mechanics and the rights process, all of which depend on knowing what you actually hold.
The bottom line
Do the mapping first. Every downstream privacy decision depends on it, and every one of them is wrong if it is wrong.
Related services
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.