← Compliance guide

What the organisation must put in place

The records, contracts, security and assessments the organisation is expected to be able to show.

Article 24

Responsibility of the controller

What it asks for

The organisation must put appropriate measures in place and be able to show they exist, reviewing them as the processing changes.

For example

Saying the staff are careful is not evidence. A dated policy, a training record and a review date are.

How Prudence covers it

The measures register holds each control with an owner and a review date, and an overdue review becomes a task rather than a note somebody forgets.

Article 25

Data protection by design and by default

What it asks for

Protection has to be built in when a system or process is designed, and the default settings must collect and share the least data necessary.

For example

A new booking form asks for a date of birth that nobody uses. By default, it should not ask.

How Prudence covers it

Activities in draft cannot progress without the data minimisation and default settings fields completed, so the question is asked before launch rather than after.

Article 26

Joint controllers

What it asks for

Where two organisations decide jointly why and how data is handled, they must agree in writing who does what, especially who answers requests.

For example

Two companies running a shared marketing campaign are joint controllers.

How Prudence covers it

The entity register has a joint controller role that requires an arrangement document to be attached before the relationship can be marked active.

Article 27

Representatives of controllers not established in the Union

What it asks for

An organisation outside the EU that is caught by the regulation must appoint a representative inside the EU in writing.

For example

An Australian online shop selling into France appoints a representative in an EU member state where its customers are.

How Prudence covers it

The representative is an entity role. Prudence raises a gap where the controller is outside the EU and no representative is recorded.

Article 28

Processor

What it asks for

Any supplier handling personal data on the organisation's behalf must be under a written contract containing the eight specific commitments listed in Article 28(3), and must not bring in a sub-processor without permission.

For example

The cloud accounting provider, the email marketing tool and the shredding company all need one.

How Prudence covers it

Every processor requires a linked agreement with an effective date. A processor in use with no agreement is a high severity gap, and the licensed set includes the contract schedule covering all eight commitments.

Article 29

Processing under the authority of the controller

What it asks for

Anyone with access to the data may only use it on the controller's instructions.

For example

A temporary worker may not export the customer list for their own use.

How Prudence covers it

The licensed acceptable use and confidentiality documents cover this, and each is linked to the systems it governs.

Article 30

Records of processing activities

What it asks for

Controllers must keep a written record of what they do with personal data, and processors must keep a record of what they do for each client. The record must be produced to the supervisory authority on request.

For example

An authority writes asking what the company does with personal data. The answer is a document, produced the same week, not a project.

How Prudence covers it

This is the centre of the product. Prudence generates the Article 30(1) controller record and the Article 30(2) processor record from the register, for one business unit or the whole organisation, and keeps a dated copy of every version produced.

Article 31

Cooperation with the supervisory authority

What it asks for

The organisation must cooperate with the authority when asked.

For example

An authority asks for the record and the breach log within ten working days.

How Prudence covers it

Export of the record, the breach log and the request log is available at any time in document and spreadsheet form.

Article 32

Security of processing

What it asks for

Security must match the risk, and the regulation names encryption, resilience, restoration after an incident, and regular testing of the measures.

For example

Having a backup is not enough. Testing that the backup restores is the part Article 32(1)(c) and (d) ask about.

How Prudence covers it

The measures register maps each control to the four categories named in Article 32(1), with a test date. A control never tested is raised as a gap.

Article 33

Notification of a personal data breach to the supervisory authority

What it asks for

A breach must be reported to the authority within seventy two hours of becoming aware of it, unless it is unlikely to pose a risk. A processor must tell its controller without undue delay. Every breach must be logged, including the ones not reported.

For example

A laptop with an unencrypted customer file is stolen on Friday evening. The clock started on Friday.

How Prudence covers it

Prudence runs three clocks: seventy two hours from awareness, the processor notification to the controller, and the communication to individuals. It drafts the authority notification from the breach record and keeps the log of breaches judged not reportable, with the reasoning.

Article 34

Communication of a personal data breach to the data subject

What it asks for

Where a breach is likely to result in a high risk to people, they must be told without undue delay, in clear language.

For example

Passwords are exposed. Users have to be told directly, not by a notice buried on a web page.

How Prudence covers it

The high risk assessment is recorded against the breach, and where the answer is yes a separate clock and a drafted communication are raised.

Article 35

Data Protection Impact Assessment

What it asks for

Where processing is likely to result in a high risk, an assessment must be completed before it starts, describing the processing, its necessity, the risks and the safeguards.

For example

Introducing CCTV with facial recognition across a site needs one before the cameras go in.

How Prudence covers it

Prudence screens each activity against the high risk criteria and requires a linked assessment before an activity meeting them can go live. The assessment template is part of the licensed set.

Article 36

Prior consultation

What it asks for

If an assessment shows a high risk that cannot be reduced, the authority must be consulted before starting.

For example

An assessment concludes the residual risk stays high. The plan pauses until the authority responds.

How Prudence covers it

An assessment with a high residual risk raises a consultation task and blocks the activity from going live.

Article 37

Designation of the Data Protection Officer

What it asks for

A Data Protection Officer is required for public authorities, for large scale regular monitoring, and for large scale special category or criminal data. Their details must be published and given to the authority.

For example

A small accountancy practice usually does not need one. A company running a large loyalty programme with behavioural tracking probably does.

How Prudence covers it

The officer is an entity role with published contact details and the notification date to the authority. Where the register shows large scale special category processing and no officer, Prudence raises the question.

Still yours to decide: The judgement about large scale remains an organisational decision.

Article 38

Position of the Data Protection Officer

What it asks for

The officer must be involved early, given resources, allowed to work without instruction on their tasks, and must not be dismissed for doing the job.

For example

The officer sees a new supplier contract before it is signed, not afterwards.

How Prudence covers it

The officer role has approval rights on assessments and on promoting an activity into the formal record, so involvement is recorded rather than assumed.

Article 39

Tasks of the Data Protection Officer

What it asks for

The officer advises, monitors compliance, advises on assessments and acts as the point of contact for the authority.

For example

The officer reviews the register quarterly and reports what needs attention.

How Prudence covers it

The audit and review register schedules the monitoring work, and the dashboard is the officer's monitoring view.

Also in this part of the regulation

  • Articles 23, 40 to 43: national restrictions, codes of conduct and certification schemes. These matter when an organisation joins a scheme, and Prudence records the certificate as a document rather than administering the scheme.