A defensible record of accountability — not a policy that says you have one.
The GDPR has applied since 25 May 2018, and its substantive rules are widely mapped. What separates a defensible programme from a policy folder is the accountability principle in Article 5(2): compliance must be demonstrated, not merely achieved — through records of processing, impact assessments and a documented legal basis for each processing activity.
For a controller this is an operating problem, not a documentation problem. A record of processing is only defensible while it matches the processing that actually happens; a DPIA is only real while the risks it assessed are the risks that remain. Accountability asks for a living record, and living records are produced by operations.
Who it applies to
Controllers and processors established in the EU, and organizations outside it that offer goods or services to people in the EU or monitor their behaviour. The obligations differ — controllers answer for the processing they decide, processors for the security of what they handle — but both must be able to show it on request.
What accountability actually asks
The accountability principle is usually reduced to keeping a record of processing. Read as an operating requirement, it asks three standing things: each processing activity carries a documented legal basis; high-risk processing is assessed before it runs, not after; and when a breach occurs, the supervisory authority is notified within 72 hours of awareness — which presumes someone already knows what data was involved and where it went. None of that survives as annual paperwork.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, GDPR accountability reduces to a handful of standing asks — each answerable from a live record, not reconstructed when a request arrives.
| What GDPR asks | Where it is answered |
|---|---|
| Record each processing activity with its legal basis and purposes | Processing register · one activity, one basis, linked to systems and controls |
| Assess high-risk processing before it runs | Risk management · DPIAs with owners, outcomes and review dates |
| Notify the supervisory authority without undue delay — within the timelines the regulation and national law define, 72 hours where feasible | Incident & resilience workflows · clocked from logging, evidence assembled per stage |
| Keep records current as processing changes | Evidence automation · continuous, provenance-tracked from connected systems |
| Oversee processors and document transfer routes | Supplier risk register · one record per processor, safeguards documented |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an accountability file is made of:
- Processing activities
- 58 · legal basis documented for each
- DPIAs
- 6 current · 1 in consultation
- Breach notifications · YTD
- 2 · both within the regulatory timeline
- Transfer routes
- mapped · safeguards current
- Evidence
- sealed · sha256:1e9d…44ac
Where teams usually start
With a demo walked through by TruSecure — the processing register, a DPIA from a live risk workflow, the export a data-protection request or supervisory enquiry will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Chapter V governs transfers out of the EEA. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework — under live legal challenge — is not a dependency of ours to begin with. Our own Romania-to-UK flow, between our two entities, rests on the separate EU–UK adequacy decision (EU) 2021/1772. If the US Framework falls, nothing about your arrangement changes.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
GDPR's accountability principle (Article 5(2)) requires organizations to demonstrate compliance, not just achieve it — through records of processing, DPIAs, and a documented legal basis for each processing activity. TruSecure links these records directly to the security controls protecting the underlying data.