The documents that demonstrate compliance fall into two sets. External documents are published and are intended for data subjects outside the organisation. Internal documents govern procedures within the organisation; employees must be made familiar with them, and evidence that they have been must be kept.
The package is not what comes first. What comes first is an audit, which takes an inventory of all the data processed and establishes which GDPR obligations actually apply to the organisation. The reason is practical, and it is worth saying openly: documents prepared without an audit describe the wrong organisation. They look tidy, nobody applies them, and the first enquiry shows it at once.
External documents
These are the texts read by clients, visitors, applicants and other people outside the organisation:
- a privacy policy — the main information document under Article 13 GDPR;
- terms of service, insofar as they relate to data;
- cookie information on the website.
The most common mistake here is not a badly written text. It is a text that describes the wrong processes: a privacy policy that mentions a client database that does not exist, and says nothing about video surveillance that is in operation.
Internal documents
This set is larger, and it cannot be seen from the website. It usually includes records of processing activities (Article 30 GDPR), a procedure for handling data subject requests (Article 12 GDPR), a description of security measures (Article 32 GDPR), a breach management procedure (Article 33 GDPR), access rights rules and a retention period schedule.
All of this rests on Article 24(1) GDPR, which requires appropriate technical and organisational measures to be implemented and the ability to demonstrate that processing is carried out in accordance with the Regulation. Article 5(2) GDPR — the accountability principle — lays down the same duty to demonstrate.
And here is the part that is done least often in practice. Employees must be made familiar with the internal documents and evidence of this must be kept, and new hires must be made familiar with them as well. The GDPR does not name this obligation directly. It follows from two provisions: Article 32(4) GDPR requires steps to be taken to ensure that employees who have access to personal data process them only on the controller’s instructions, and Article 5(2) GDPR requires the ability to demonstrate this. This is exactly what is asked about during an inspection. A procedure that nobody has seen does not demonstrate compliance; it demonstrates that a document was prepared.
In one case an organisation came back after several years
An organisation for which documents had been prepared immediately after the GDPR took effect was left without a provider several years later. It had a package, the package looked complete, and the natural request was “update whatever is missing”.
The proposal was to begin not with the documents but with an audit: to find out whether the processes had changed, and only then to update the existing documents and prepare the missing ones. Over several years almost everything changes — systems, providers, staff, services. An old package is often an accurate description of an organisation that no longer exists.
This is a typical case, not an exceptional one. Most of our work in this area starts exactly this way.
What is most often missing
Data processing agreements with providers (Article 28 GDPR). The question “we have an IT service provider who could theoretically access our data — do we need a separate agreement?” reaches us more often than any other.
The answer is yes. And an ordinary service agreement does not meet this requirement: it contains neither the subject-matter and duration of the processing, nor the controller’s instructions, nor a confidentiality undertaking, nor assistance with data subjects’ rights, nor a duty to report a breach, nor rules on sub-processors, nor a decision on what happens to the data when the agreement ends.
The word “theoretically” in the question changes less than it seems. Article 4(2) GDPR treats as processing any operation performed on data, including storage and consultation. So a provider whose servers or systems hold your data is processing that data, even if it never looks at it. This is most often the case with accounting, server hosting, cloud, archiving and security service providers. If the provider does not store the data but does have access, the agreement sets out when and how it may use that access.
A breach register. Article 33(5) GDPR requires all personal data breaches to be documented, including those that do not have to be notified to the supervisory authority. A decision not to notify is lawful; a decision not to record is not.
An awkward detail follows from this: a register without a single entry is not a good sign during an inspection. An organisation that is actually operating has minor incidents — an email to the wrong recipient, a lost document, access left open for too long. An empty register usually means not that nothing happened, but that nothing is being recorded.
How we work
- Audit. We take an inventory of the data processed and establish which obligations actually apply. The result is a prioritised list of what is missing.
- External documents. Privacy policy, cookies, terms.
- Internal documents. Records of processing activities, procedures, registers, access.
- Agreements with providers under Article 28 GDPR.
- Familiarisation of employees with the internal documents, and keeping the evidence.
The fifth step is the one that is easiest to put off and the one that is asked about first.
What it costs
The external documents, and the audit together with the internal document package, are paid for separately, each at a fixed price.
The price depends on two things: how many processes are carried out and how many providers have access to the data. We tell you the exact amount after the first conversation, before work begins, and it does not change as the work progresses. A fixed price here is not marketing but a necessity — the scope of the audit becomes clear in the first week, and the client should not have to pay for it becoming clear.
How to start
Tell us what your organisation does, how many employees you have and whether you already have any documents. If you do, send them to us — we will tell you which of them can still be used and what will need to be prepared from scratch. The first answer and the price quote are free — email info@linden.lt.
A practical step-by-step guide is on Privacio, a site built by Linden: Records of processing activities: Article 30 fields in plain terms. You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).
More about this service: GDPR audit, compliance documents and advice.