TL;DR
In the processing register: a catalogue of 35 Art. 32 measures to tick and extend, 26 data types under the six legal categories, and a destination country chosen from a list that states its position under Chapter V. None of the three decides for you.
The problem: the same sentence, on every processing activity
Anyone keeping an Art. 30 register for several controllers knows the scene: the security measures field is an empty box, and the same content gets retyped into it every time. Access control, backups, antivirus. Then the next activity, and again from the start. It is not only a matter of time: a measure written in a hurry is written badly, and under review an inconsistent list across activities of the same controller is the first thing that shows.
A catalogue that suggests, and does not close anything
The 35 measures sit in nine groups anchored to the article that names them: access control, encryption and pseudonymisation, backup, continuity, network protection, devices, organisational measures, logging, testing and erasure. You tick them, they become labels on the record, and the text field stays alongside for whatever differs in the specific case. No register already filled in loses a line.
- The suggestions at the top come from the activity itself: special categories bring up encryption at rest, access logging and strong authentication; a non-EU transfer brings up the supplementary measures discussed after Schrems II.
- The list includes periodic testing of effectiveness, required by Art. 32(1)(d) and recorded in almost no register.
- The CSV export merges the selected measures with the free text: whoever opens the file sees what is on screen.
Data categories: the six legal ones stay, the detail sits underneath
The six boxes — ordinary data, special categories, criminal convictions, minors, biometric, genetic — say on what legal footing the data is processed, and they matter for the Art. 6 basis and the Art. 9(2) condition. They do not say which data. Underneath each there are now 26 descriptive types, plus a field for your own. It speeds up filling in, but above all it helps answer a data subject who asks which data concerns them, as Art. 15(1)(b) requires.
«The United States is adequate» is the sentence that does most harm
In the transfer record — and in the processor record — the country is no longer a text box. You choose from a list grouped by status, and what it entails appears below. The case that matters is partial adequacy: the decision on the United States covers only organisations certified under the Data Privacy Framework, for the processing declared in the certification; the one on Canada covers only commercial organisations subject to PIPEDA. Outside that, an Art. 46 tool with a transfer impact assessment is required.
What the platform does not do
It does not establish whether the measures are appropriate: appropriateness depends on risk, state of the art and cost (Art. 32(1)), and that assessment belongs to whoever signs. It does not infer the legal qualification of the data: if you record health data without ticking «special categories», the form flags it and stops there. And it does not replace the Commission's list of adequacy decisions, which remains the source to consult: the moving cases — the United Kingdom and the United States — carry a marker saying so.
All three changes came from feedback received during a free trial. If something slows you down while using the platform, saying so works: that is how things move.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free