Skip to main content
FRAMEWORK

A defensible record of accountability — not a policy that says you have one.

The GDPR has applied since 25 May 2018, and its substantive rules are widely mapped. What separates a defensible programme from a policy folder is the accountability principle in Article 5(2): compliance must be demonstrated, not merely achieved — through records of processing, impact assessments and a documented legal basis for each processing activity.

For a controller this is an operating problem, not a documentation problem. A record of processing is only defensible while it matches the processing that actually happens; a DPIA is only real while the risks it assessed are the risks that remain. Accountability asks for a living record, and living records are produced by operations.

Who it applies to

Controllers and processors established in the EU, and organizations outside it that offer goods or services to people in the EU or monitor their behaviour. The obligations differ — controllers answer for the processing they decide, processors for the security of what they handle — but both must be able to show it on request.

What accountability actually asks

The accountability principle is usually reduced to keeping a record of processing. Read as an operating requirement, it asks three standing things: each processing activity carries a documented legal basis; high-risk processing is assessed before it runs, not after; and when a breach occurs, the supervisory authority is notified within 72 hours of awareness — which presumes someone already knows what data was involved and where it went. None of that survives as annual paperwork.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, GDPR accountability reduces to a handful of standing asks — each answerable from a live record, not reconstructed when a request arrives.

GDPR requirements · how TruSecure answers them
What GDPR asksWhere it is answered
Record each processing activity with its legal basis and purposesProcessing register · one activity, one basis, linked to systems and controls
Assess high-risk processing before it runsRisk management · DPIAs with owners, outcomes and review dates
Notify the supervisory authority without undue delay — within the timelines the regulation and national law define, 72 hours where feasibleIncident & resilience workflows · clocked from logging, evidence assembled per stage
Keep records current as processing changesEvidence automation · continuous, provenance-tracked from connected systems
Oversee processors and document transfer routesSupplier risk register · one record per processor, safeguards documented

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an accountability file is made of:

Accountability file · controller excerptSample data
Processing activities
58 · legal basis documented for each
DPIAs
6 current · 1 in consultation
Breach notifications · YTD
2 · both within the regulatory timeline
Transfer routes
mapped · safeguards current
Evidence
sealed · sha256:1e9d…44ac

Where teams usually start

With a demo walked through by TruSecure — the processing register, a DPIA from a live risk workflow, the export a data-protection request or supervisory enquiry will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

Sovereignty

Chapter V governs transfers out of the EEA. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework — under live legal challenge — is not a dependency of ours to begin with. Our own Romania-to-UK flow, between our two entities, rests on the separate EU–UK adequacy decision (EU) 2021/1772. If the US Framework falls, nothing about your arrangement changes.

See the whole chain

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

GDPR's accountability principle (Article 5(2)) requires organizations to demonstrate compliance, not just achieve it — through records of processing, DPIAs, and a documented legal basis for each processing activity. TruSecure links these records directly to the security controls protecting the underlying data.