A defensible record of accountability — not a policy that says you have one.
Seventy-two hours. That is the window between learning of a personal-data breach and notifying the supervisory authority — with the analysis, the scope and the reasoning documented inside it. Beyond incidents, the accountability principle expects you to demonstrate compliance, not assert it: records, assessments, decisions, producible on demand.
AI systems raised the stakes. Processing activities now have AI systems using that data, each with its own obligations under the EU AI Act — a layer most registers don't model. TruSecure keeps one linked register — activities, AI systems, controls, evidence — so the answer to "show me" is an export, not a project.
What changes for the register
- Register once, linked
Processing activities and AI systems in one register, related to each other — which activity, which AI system, which data.
- Attach the controls
Each activity links to the controls protecting it and the citations they satisfy — GDPR, EU AI Act, NIS2 where relevant.
- Run the clocks
The incident workflow classifies, starts the 72-hour clock, and records every step and decision taken inside it.
- Produce on demand
The accountability export is generated on request: timestamped, sealed, scoped to exactly what was asked.
What you'd actually look at
One register entry — the export the dashboard produces when a regulatory inquiry asks:
- Legal basis
- Art. 6(1)(f) · documented
- AI system
- deployer · registered
- Controls
- DSP-2 · DSP-4
- Citations
- GDPR Art. 30 · 35 · EU AI Act Art. 26
- Evidence
- 4 records · linked
- Exported
- 2026-08-17 · sealed
The obligations that expect a producible answer
| What it asks of you | Citation | Where the answer lives |
|---|---|---|
| GDPR · demonstrate compliance | Art. 5(2) | Accountability export |
| GDPR · records of processing activities | Art. 30 | Register |
| GDPR · breach notification without undue delay, within the 72-hour timeline the regulation defines | Art. 33 | Incident clocks |
| GDPR · impact assessment for high-risk processing | Art. 35 | AI register · DPIA link |
| EU AI Act · deployer obligations | Art. 26 | AI register |
| NIS2 · incident reporting | Art. 23 | Incident clocks |
No Customer Content is transferred to the United States or to Asia, so there is no EU–US Data Privacy Framework dependency to maintain, no transfer impact assessment to refresh for it, and nothing to re-paper on your side if that Framework falls. That is one fewer standing obligation on your desk.
How DPOs usually start
A demo walked through with your own register structure in view, then a fixed-scope Resilience Sprint that builds the linked register and maps your first regime, then the subscription. No self-serve checkout, no per-seat maths.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
TruSecure links records of processing, AI system inventories, and security controls into one defensible, timestamped accountability record, satisfying GDPR's Article 5(2) accountability principle.