EvidenceSheet

Art.39 Tasks of the data protection officer

The data protection officer must at least inform and advise the controller or processor and the employees who carry out processing of their obligations under the Regulation and other Union or Member State data protection

5
artefacts
1
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Evidence the monitoring effort is weighted by processing risk rather than spread evenly across the organisation · SIEM / log platform

periodic reviewEvidence produced at each review

  • The officer's record of contacts as supervisory authority contact point, and of impact assessment advice given under Article 35(2) · Document repository

governing documentDocuments that govern the control

  • The officer's monitoring plan and its output, such as a review or audit programme with findings and their closure · Policy repository / GRC workspace
  • Advice given, recorded with its date and outcome including where it was not followed and by whose decision · Document repository
  • Training and awareness activity delivered or overseen, with coverage figures for the staff involved in processing operations · HR system / LMS

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

Art.38 Position of the data protection officer · Art.44 General principle for transfers