Compliance with the European data protection framework is often run as a project: a few weeks of effort, a set of documents, a shared folder, and the subject is considered closed. Months later, the record of processing no longer reflects the organisation, nobody knows who handles an access request, and the retention policy has never deleted a single record. Yet the regulation does not ask for a folder. It asks the controller to be able to demonstrate compliance at any time. That is a difference in nature, not in degree.
Paper compliance and lived compliance
Compliance on paper shows the same symptoms from one audit to the next:
- the record of processing was completed once, during the initial remediation, and never moved again;
- privacy notices are legally accurate but unreadable for the people they address;
- the retention policy sets durations that nothing technically enforces;
- nobody knows where an erasure request lands, or who is expected to answer it;
- processor contracts were signed without anyone checking what they actually permit.
None of these is a dramatic failure. Together they describe an organisation that produced documentation without changing its practices. The accountability principle points the other way: it places the burden of proof on what you do, not on what you wrote.
The record of processing as a steering tool
The record of processing activities is the most underused document of the whole framework. Treated as a formality, it becomes a table of vague purposes. Treated as a steering tool, it becomes the map of how data lives in the organisation: which purposes, which categories of people and data, which lawful bases, which recipients, which retention periods, which processors, which transfers.
A current record surfaces what no other document shows: duplicate collection across teams, orphaned processing whose owner has left, tools deployed without legal ever hearing about them. Above all, it lets you answer a rights request in minutes rather than weeks.
One habit changes everything: the record is updated when the decision is made — new tool, new supplier, new form — not during an annual review that reconstructs the past from memory.
Qualify, minimise, purge: the structural decisions
Breaking the consent reflex
The regulation offers several possible grounds: consent, performance of a contract, a legal obligation, vital interests, a public interest task and legitimate interests. Consent is only one of them, and it is the one organisations invoke wrongly most often. Valid consent must be freely given, specific, informed and unambiguous, and as easy to withdraw as it was to give — so using it for processing that the service cannot function without promises a reversibility you cannot honour.
In practice, running a customer account usually rests on performance of the contract, invoicing on a legal obligation, and system security or fraud prevention on legitimate interests — provided you genuinely balanced that interest against people's rights and kept a record of the reasoning. The choice of basis is not a stylistic one: it determines which rights apply. Portability does not cover every processing activity, and a badly qualified basis weakens everything built on top of it.
A retention policy that actually runs
Minimisation is the cheapest security control available: data you never collect cannot leak. Every field on a form should be justified by a precise purpose; otherwise it should go.
Storage limitation follows the same logic but nearly always fails in the same place. A retention policy is real only when it combines three things: a justified duration for each purpose, a technical mechanism that enforces it automatically, and evidence that the purge actually ran. Without the last two, the duration is merely an intention. The blind spots are always the same: backups, exports, test environments fed with production data, mailboxes.
Inform clearly, make rights workable
Information people can actually read
Transparency is not satisfied by an exhaustive text nobody reads: it calls for information that is concise, intelligible and easily accessible. A useful notice answers, in a few lines, the questions people actually have — who processes my data, for what purpose, on what basis, who receives it, for how long, and how do I exercise my rights.
Organising responses to requests
People hold rights of access, rectification, erasure, restriction, objection and portability. The difficulty is not legal but organisational: the response must come within the prescribed time — one month, extendable by two further months where requests are complex or numerous, provided the person is told within the first month. Meeting that deadline means knowing in advance who receives the request, who qualifies it, how identity is verified, and in which systems the data sits.
Impact assessments, processors and transfers
A data protection impact assessment (DPIA) is required where processing is likely to result in a high risk to people's rights and freedoms. The regulation explicitly targets systematic evaluation of personal aspects based on automated processing with significant effects, large-scale processing of special categories of data, and large-scale systematic monitoring of a publicly accessible area; supervisory authorities also publish their own lists. Carried out early, a DPIA shapes the design; carried out at the end, it merely records it.
Using a processor must be framed by a contract meeting the requirements of Article 28: documented instructions, confidentiality, security measures, control over sub-processors, assistance to the controller, the fate of the data at the end of the contract, and the information needed for audits. Two points deserve particular attention: the real list of sub-processors, and where the data — and the support teams — are located. Any transfer outside the Union must rest on a valid mechanism: an adequacy decision, standard contractual clauses or binding corporate rules.
Security, breaches and the human factor
Security is an obligation to apply measures appropriate to the risk, judged against the state of the art and the nature of the data: encryption in transit and at rest, segregated environments, least-privilege access management with periodic reviews, usable logging, tested backups. These are not a separate chapter of compliance; they are its technical expression.
When a breach occurs, the decisive reflex is fast qualification. Every breach must be documented internally; those likely to result in a risk to people must be notified to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of them; where the risk is high, the individuals concerned must be informed as well. The clock starts on awareness, which means the alert has to travel — everyone needs to know what to report and to whom.
Compliance is not measured by the volume of documents produced, but by how long it takes to answer a simple question: where is this data, why do we hold it, and until when?
This is where the data protection officer matters, less for formal expertise than for positioning: involved in good time in data-related questions, performing the role without instructions on how to carry it out, free of conflicts of interest, and able to reach the highest level of management. A DPO consulted after the decisions is not a DPO. And because most incidents begin with an ordinary gesture — an attachment, an over-broad share — regular awareness work remains the first line of defence.
The next step
If you do one thing this quarter, do this: open your record of processing, pick your five most sensitive activities and check four points for each — is the lawful basis the right one, is the retention period enforced by a technical mechanism, is the information readable, and does the processor contract cover what the supplier actually does. The gaps you find become your action plan.
This article sets out general principles and does not constitute legal advice: each processing activity must be qualified against its own purpose and context, with your data protection officer or your legal counsel.



