All news
Regulation August 24, 2026 6 min

Seventy-seven boxes: what a DPO actually files, and why thirty-one were not enough

The document archive goes from thirty-one to seventy-seven areas, grouped into the six things a controller must be able to demonstrate. And the page that shows them has been rebuilt

In short

Thirty-one document areas become seventy-seven, split into six families: inform, appoint, record, assess, react, demonstrate. The archive page has been redesigned: above each family sits a mosaic that is the portrait of that client, and the family in the worst shape promotes itself to the top.

Where this comes from

A document archive with thirty-one boxes looks complete until you try it on a real case. Then you notice that collected consents end up in "Other documents", that the union agreement on CCTV has no home of its own, and that the transfer impact assessment — the one that accompanies every standard contractual clause after Schrems II — is nowhere. "Other documents" is the box where everything the designer failed to foresee goes to die.

The four that weighed most

  • Automated decisions and profiling (Art. 22). With scoring, CV filters and anti-fraud systems it is everywhere, and the 825-million fine decided in the Netherlands these days is about exactly this. It had no box.
  • Biometric processing. It calls for its own assessment and used to end up inside "Security measures", where nobody looks for it.
  • Access and log register. It is the first evidence requested when unauthorised access is alleged, and it is also the duty that falls on system administrators.
  • Anonymisation and pseudonymisation. Almost always claimed, almost never documented: it is the point on which authorities have dismantled the most defences in the past two years.

And then the rest

Union agreements and monitoring authorisations — without them CCTV and geolocation are unlawful upstream, before the GDPR even applies. The Article 33(5) breach register, an autonomous obligation that is not exhausted by handling a single incident. The DPO's resources and independence under Article 38, the first question in any review of the role. Collected consents and withdrawals, which are the proof Article 7(1) requires. And further: notices to candidates, to children, to whistleblowers; system administrators; the Union representative; the data flow map; data classification; vulnerability testing; privacy by design in projects; the incident response plan; Article 34 communications to data subjects; cyber insurance; the DPO's periodic report.

Why the page was rebuilt

Seventy-seven tiles in a grid are a wall, not a list. The areas now sit in six families matching the six things a controller must be able to demonstrate, and above each one there is a mosaic: one tile per area, filled when it holds documents. It is not an illustration pulled from a library — it is the portrait of that client, and it changes as you work. A stock photograph would be identical for everyone and would say nothing.

We do not choose the family in the worst shape: the code does, from the coverage, and it rises to the top with its own colour filled in and a button that opens the first empty area directly. The other five stay monochrome on purpose. Six colours for six families were six colours that said nothing; colour is used by one thing per screen, and that is why it registers.

One thing to know before you open it

On a new client the mosaic will be almost entirely empty and all six cards will say "empty". That is honest and it is uncomfortable. Not all seventy-seven areas apply to everyone: a medical practice and an estate agency together use fewer than twenty. Sector templates exist precisely so you start from the areas that concern that client instead of all of them.

Official source:DPO Workspace — document archive

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min