Skip to main content
DG-011HighProvider & DeployerPreventive

Data Processing Records (Article 30 GDPR)

Where training or inference involves personal data, providers must maintain records of processing activities as required by GDPR Article 30, describing the categories of data, purposes of processing, and technical safeguards in place.

Articles:Article 10(5)Article 10(6)

Evidence Examples

  • GDPR Article 30 record of processing
  • Data processing impact assessment
  • Data flow diagram

Standards

ISO/IEC 27701:2019ISO 42001:2023 §8.2

Upgrade when it needs to be

The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.

Start free risk preview
Data Processing Records (Article 30 GDPR) (DG-011) | AZComply Controls