GDPR Documentation System
The Regulation changes the axe for the legitimacy of the processing of personal data, moving it from the so-called legitimacy requirements1 to the compliance data protection system and the direct attribution of responsibility to the data controller.
 
In summary, the Regulation stipulates that compliance with the obligations of the data controller – for whose satisfaction he is therefore responsible and he is required to demonstrate it – can be expressed as follows:
through a documentation system consisting in the maintenance of the record of processing activities, descriptive of the processing carried out under its own responsibility (Article 30) and further compulsory documentation
the adoption of appropriate policies (Article 24) and compliance assessments with regard to processing and effectiveness assessments concerning the data protection measures implemented
adherence to approved Code of Conducts (Articles 24.3, 28.5, 32.3)
the use of a certification mechanism (Articles 24.3, 25.3, 28.5, 32.3).
Therefore, documentation requirements, assessments and compliance with codes of conduct and data protection certification systems are tools to demonstrate compliance of the company with legal requirements.