Block 1 · That you had measures, and which ones
☐ 1. Dated inventory of the security measures
A list of which measures protect each set of data, with the date on which they were put in place and who approved them. Measures are assessed specifically, case by case: what has to be proved is not that your company was impregnable, but what specific protection the affected data had and since when. (Rule A · SAP Madrid 371/2023, of 28 July)
☐ 2. Proof of the specific protection of the files containing personal data
A record showing that the files containing personal data are protected and that access to them is restricted to identified individuals. Measures as modest as a file protected by a password known to two people have been found adequate: what was decisive is that it was proven. (Rule A · SAP Madrid 371/2023, of 28 July)
[...] the data [...] was handed over by means of an Excel file encoded with a password known only to the Chair and the Secretary of the Committee [translation]
☐ 3. Register of access and of data disclosures
Who can access what, who authorised it and when that access was withdrawn; and, when data is handed to someone, to whom, for what purpose and on what date. Without this register you cannot maintain that access was restricted, however restricted it in fact was. (Rule A · SAP Madrid 371/2023, of 28 July)
Block 2 · Who answers for what
☐ 4. Map of processing operations with the roles defined
A document that says, processing operation by processing operation, whether your company acts as controller or as processor, and who occupies the other position. Security obligations are imposed only on the controller or the processor: half the defence consists in proving which position you were in. (Rule B · SAP Madrid 371/2023, of 28 July)
[...] since it cannot be held proven that the defendant is the controller or the processor of the data, which is the party on whom the obligations that the claimant considers infringed are imposed [translation]
☐ 5. Data processing agreements under Article 28 GDPR, signed and in force
One for each supplier that processes data on your company's behalf, signed, dated and up to date, with the obligations of assistance and of notice in the event of an incident. It is the document that allocates liability when the failure happens at someone else's premises. (Rule B · SAP Madrid 371/2023, of 28 July)
☐ 6. Correspondence with suppliers during an incident
What you demanded of them, when, and what they replied. In writing, even if the conversation took place by telephone. A call you cannot prove is the same as having demanded nothing. (Rule B · SAP Madrid 371/2023, of 28 July)
Block 3 · That the organisation decides and does not improvise
☐ 7. Written breach response protocol, approved and dated
With its version history and a record of who approved it. The protocol is the proof that the response was not improvised but the execution of something already planned. The step-by-step detail is in the first 72 hours protocol. (Rule A · SAP Madrid 371/2023, of 28 July)
☐ 8. Register of decisions: who decided what and when
Brief minutes with the time, the options considered, the decision taken, the reason and a signature. Including the decision not to do something: not notifying may be correct, but only if it is recorded with reasons and a date. Accountability requires you to demonstrate compliance, not merely to comply. (Rule D · SAP Asturias 412/2024, of 3 October)
☐ 9. Documented staff training
The content delivered, the date, the attendees and a record of their attendance. Training with no attendance list is, for evidential purposes, training that never took place. (Rule D · SAP Asturias 412/2024, of 3 October)
☐ 10. Minutes of the internal compliance reviews
The dated record showing that someone periodically checks whether what is written down is being followed, what they found and what was corrected afterwards. A review with findings that were corrected proves diligence better than an immaculate report with no trace of follow-up. (Rule D · SAP Asturias 412/2024, of 3 October)
Block 4 · That the data is accurate and not kept longer than it should be
☐ 11. Register of rectifications and erasures, with dates
What was rectified or erased, at whose request, on what date and who carried it out. The accuracy principle requires inaccurate data to be erased or rectified without delay; here the date is the main evidence. (Rule E · SAP Asturias 412/2024, of 3 October)
Under Article 5.1(d) GDPR, data shall be accurate and, where necessary, kept up to date, which obliges controllers to take every reasonable step to ensure that inaccurate data is erased or rectified without delay [translation]
☐ 12. Retention rules and proof that they are applied
How long each type of data is kept and evidence of the purges actually carried out. Processing that was lawful at the outset may cease to be so through the mere passage of time, and a breach usually exposes precisely what should no longer have been there. (Rule E · SAP Alicante 33/2024)
...even processing of accurate data that was lawful at the outset may become, over time, incompatible with that Directive [now the GDPR] where the data is no longer necessary in relation to the purposes for which it was collected or processed. [translation]
Block 5 · That you handle people's rights
☐ 13. Procedure for exercising rights, simple and free of charge
Published and accessible, without requiring paid forms, prior registration or off-putting formalities. The obligation to provide a simple and free procedure falls on the controller, not on the person making the request. (Rule F · SAP Barcelona 307/2023)
The controller is obliged to give the data subject a simple and free procedure for dealing with the exercise of these rights. [translation]
☐ 14. Register of erasure requests and of other rights requests
With the date of receipt, the due date, the date of reply and the status. The deadline is one month, extendable by a further two months only on grounds of complexity and provided the extension is communicated within the first month: without a register of dates you cannot prove that you complied. (Rule F · SAP Barcelona 307/2023)
☐ 15. Copy of every express reply and of the extensions communicated
You must decide expressly even where you hold no data on the applicant. Keep the text sent and the acknowledgement of receipt. Silence cannot be defended. (Rule F · SAP Barcelona 307/2023 · SAP Alicante 33/2024)
Block 6 · That you were not taken in
☐ 16. Register of the identity checks
What check was made before handing over data, changing an account or dealing with a request, using what document and who carried it out. The controller's fault is presumed: to be exonerated you must prove the diligence measures adopted, including those aimed at preventing identity impersonation. (Rule C · SAP Madrid 273/2024)
Block 7 · That every use of the data has an explanation
☐ 17. Documented justification for every purpose other than the original one
If data collected for one thing is used for another, it is for the controller to determine and demonstrate that the further purpose is compatible with the original one. That reasoning must exist in writing and bear a date earlier than the use, not be manufactured when the claim arrives. (Rule D · SAP Madrid 123/2026)
Block 8 · The file itself
☐ 18. Index of the file, person responsible for custody and review schedule
A living index that says which documents make it up, where each of them is, who holds them and when they fall due for review. It is what turns an accumulation of folders into a means of evidence that can be handed over. (Rule D · SAP Asturias 412/2024, of 3 October)
How to use this list
- Mark each point with three states, not two: I have it and can produce it, it exists but I would not know where to find it, and it does not exist. The middle state is the one that loses the most cases.
- Put a date and a name on every document. A document with no date proves nothing about when it was made, and the when is almost always what is in dispute.
- Assign each point to a named person responsible for keeping it up to date, not to a department.
- Review the list once a year, whenever a supplier changes and after any incident, leaving a dated record of the review.
- Keep it in a way that remains accessible even when your systems are not.
Indicative model. It does not replace legal advice. Read the no-advice disclaimer. © ILP Abogados — www.ilpabogados.com
How many of these 18 documents could you hand over tomorrow?
ILP Abogados builds the diligence file with your company, document by document, and leaves it dated, ordered and ready to be produced the day it is needed.
See the Demonstrable Diligence File