The record as a report view
A read-only, spreadsheet-like view drawn from your processing activities. You edit the activity, never the record, so the record and its source can never disagree.
The record of processing is a report drawn from your processing activities, not a document you rebuild before an inspection. Correct an activity and the record says so immediately, with red markers on whatever is still missing.
Unlimited users • Free onboarding and support • No commitment
Sofie Bruhn is group DPO at Meridian Nordic, three legal entities and around 1,200 vendors between them. Her record of processing used to be true on the day it was written and slightly less true every week after that, and she found out how much less every time a customer sent an audit questionnaire. Now the record is a report drawn from the processing activities themselves. She edits the activity, the record says so immediately, and the red markers tell her where it has gone thin before anyone else asks.
Ready when asked
The record is a live view over your processing activities, so there is nothing to assemble the week an auditor writes.
One record per entity
The record is drawn per legal entity, because that is the unit the law asks for, and the company's own details follow the export.
Red markers, not a pass mark
Every activity shows how far it has got and marks exactly which fields are missing. Nothing is blocked, and nothing is hidden either.
Every change on record
Every single action on a processing activity is written to a full change log, so several colleagues can work in the same record safely.
Documentation goes out of date quietly. The activity was described correctly, and then payroll moved to a new provider and nobody thought to mention it to the DPO.
This is the part people have to see once before it clicks. The record in .legal is a read-only view, laid out like a spreadsheet, drawn from your processing activities.
Article 30 sets a minimum, and a real audit conversation rarely stops there. So the same view is drawn two ways.
The platform does not tell you that you are compliant. It tells you how much of the record is filled in, and where the holes are.
Processing activity, system and vendor are mapped to each other, so the same fact does not have to be maintained in three places.
Somebody still has to notice that a system changed. What the platform does is make sure the noticing is planned, owned and logged.
A read-only, spreadsheet-like view drawn from your processing activities. You edit the activity, never the record, so the record and its source can never disagree.
One record holds the Article 30 requirements one to one. The other adds further relevant information, the legal basis and the systems in use for example, for the questions that come after the statutory minimum.
Each activity computes how far it is towards meeting the record requirements and marks the fields that are missing, so you chase the gaps instead of re-reading everything.
Every single action on a processing activity is recorded. When someone asks who changed the retention period and when, the answer is in the platform, not in an email thread.
Export the record as Excel with the selected company's details on it, or filter it down to a subset first, one department for instance.
The recurring review work becomes planned tasks with named owners, and when .legal invalidates a legal basis centrally you get a notification listing every affected place.
One record, kept to the requirement it exists for.
GDPR
Article 30 is the obligation this page is about: a record for each legal entity, in the controller role and the processor role, kept current rather than reconstructed.
Document GDPR, keep Article 30 records current and stay audit-ready, with the processing activities, assets, vendors and annual wheel that sit around the record.
Explore GDPRcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
6 use cases
No use cases match that combination yet. Try removing a filter.
A reporting view, laid out like a spreadsheet and read-only. It is drawn from your processing activities and always for one legal entity at a time, because that is the unit the regulation asks for. All editing happens on the processing activity itself, and there is no save button, so a correction is in the record as soon as you make it.
Two are available. One holds the Article 30 requirements one to one, which is what you hand over when someone asks for the statutory record. The other adds further relevant information, for example the legal basis and the systems in use, which is usually what a customer or an auditor asks about next.
Every processing activity carries a progress bar towards the record requirements, with red markers on exactly the fields that are not filled in, and the dashboard carries the same figure for the whole organisation. In a demo environment it stood at 84% documented, which is an illustration of what the platform shows rather than a benchmark. Nothing is blocked while it is incomplete, because being 100% documented at all times is not realistic and we would rather show status than pretend.
Yes. The record exports as Excel, and the details of the company you selected travel out with the file. You can also filter it first and draw it for a subset, one department for instance. The rule behind it is that anything you could be asked to show a third party can be exported in the format that suits its shape, and the record's shape is a list, so the record goes out as Excel.
Who the Danish Data Protection Agency isYes. Every single action on a processing activity is written to a full change log. That is what makes it safe for several colleagues to work in the same record, and it is the answer when an auditor asks how a field came to say what it says.
The Article 6 and Article 9 bases are master data .legal maintains centrally, so when one is invalidated we do it once for every customer. Every place it was used is marked red, the affected activity's completion percentage falls, and you get a notification with the list of affected places. We will not go in and change your documentation on your behalf, and that is deliberate.
You register the sub-processor on the vendor, and the platform offers to apply it everywhere that vendor is already used, then fills those places in once you accept. It is a prompt you approve, never a silent update, which is the way this reader usually wants it.
Run due diligence and supervision of your processorsSeveral, one per legal entity, and reporting on top of them can be consolidated across the group or filtered to a single company. An intra-group sharing is registered once and appears on both sides, on the controller's Article 30(1) record and on the processing company's Article 30(2) record.
No, and we would rather say that plainly. Somebody still has to notice that a system changed. What the platform does is make sure the work is planned, owned and visible: the recurring reviews sit in the annual wheel as tasks with named owners, changes land in the record with no save step, and the red markers show where the record has quietly gone thin.
You can, and we do not push our own template at you. A DPIA has to fit the specific case, so if you already have a document that works, keep using it. That is our own recommendation, not a limitation we are apologising for.
What a data protection impact assessment involves
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.