Contents
In personal data protection audits the database side is usually the hardest to defend. Policies are written, training is delivered and contracts are signed, but when the question becomes who accessed this data, the answer lives in people's memory. This article lists the evidence items an auditor will ask for and where each one comes from.
What the Auditor Looks At
An auditor separates three things: the claim, the control and the evidence. The claim is what the policy says. The control is the mechanism that enforces it. The evidence is the record showing the control worked. Most organizations are good at claims, average at controls and weak at evidence. When preparing, reverse the order and start by asking whether you can produce the evidence at all.
The 12 Evidence Items
1. Inventory of columns holding personal data
It must be written down which column in which table holds personal data. If this inventory stays a one off spreadsheet exercise it goes stale within six months. A catalog kept current inside the system is far stronger evidence.
2. Access records
Who accessed production data, when and with what justification. A technical connection log alone is not enough; the reason and the approval must be there too.
3. Approval evidence
Who approved each access and each change, with a timestamp. Whether the approver and the accessor are the same person must also be visible.
4. Masking evidence
Which columns were masked and why the others were not. The second half is missing in most organizations and it is exactly where auditors push hardest.
5. Unmasked access exceptions
If unmasked data is genuinely required, that is an exception. The count, justification and approver of exceptions must be reportable. A system with no exceptions is unrealistic; a system whose exceptions cannot be counted is not auditable.
6. Permission matrix
Which role can reach what. This matrix is expected to be the real configuration of the system rather than a separate document. When the document and the system disagree, the auditor believes the system.
7. Privilege change records
Records of grants and revocations. Auditors ask in particular when a departing employee's access was closed.
8. Data change records
Updates and deletions applied to personal data. Data fix scripts fall in this scope too and are usually forgotten.
9. Retention and deletion evidence
Records showing that data past its retention period was deleted. The deletion itself is a change and must be recorded.
10. Integrity of the records
Showing that the audit record was not altered afterwards. A record written to a table that can be updated with the same permission is weak as evidence.
11. The rule set over time
The audit looks at the past while the system shows today. An action from six months ago must be judged by the rules of that day. Freezing the rule set at request time closes this gap.
12. Records of control weakening
Turning a control off or relaxing it should appear as a distinct event. A line saying a setting changed is not enough; which control was weakened and who decided must be readable.
Three Things That Do Not Count as Evidence
Screenshots. Who took them and when is unclear, and they are easy to produce. They can support a case but never carry it alone.
The policy document. A policy is a claim. The auditor reads it but looks for the evidence in the system.
A table compiled afterwards. Summary tables assembled by hand during audit season are not accepted when the source cannot be shown. The source record always outweighs the summary.
A Four Week Preparation Plan
Week 1: Build the inventory of tables and columns holding personal data. Include the gaps you already know about, because an unknown gap is worse than a known one in an audit.
Week 2: Write down how production data access happens today. How many different paths exist and which of them are recorded? This step usually produces the most uncomfortable findings.
Week 3: Try the 12 items one by one. For each, answer how many minutes it would take to produce that evidence today.
Week 4: Design controls for the items you could not produce. The control must generate evidence, because a control that produces none is treated as absent.
Frequently Asked Questions
How long does audit preparation take?
If the records already form on their own, preparation takes a few days; the time is spent trying to produce records after the fact. That is why the measure of readiness is not the calendar but whether evidence forms together with the event. If evidence is assembled after the event, even a four week plan may not be enough.
Does a screenshot count as evidence?
Usually not. A screenshot does not show who took it or when, and it can be altered. What an auditor looks for is that the record formed with the event and that its integrity can be verified independently. A screenshot is only useful as an explanatory aid next to a verifiable record.
How long should we keep which records?
The retention period depends on the organisation's own policy and the regulation it is subject to; there is no single correct number. What matters is that the period is deliberately chosen, written down and enforced by the system. Keeping everything forever is not a decision either: a growing audit trail has to be archived at some point, but the archive itself must stay verifiable.
How many of the 12 can you produce today?
We will demonstrate the evidence dossier and the built-in reports on your own scenario.
Book a Demo →