
Traceability
The GDPR requires that organisations should maintain records of data processing. According to Article 30, these records should include information, such as the categories of data subjects and categories of personal data, the purpose of data processing, time limits for erasure, details of data transfers to a third country and a general description of the technical and organisational security measures.