Fiche 21/54
Part 2 — Core Principles
Advanced
Reviewed 2026-08-23
Synthesis: Principles Audit Matrix
Principles Compliance & Audit Matrix
⚡ In 30 seconds
This operational audit grid translates the legal standards of Article 5 into concrete verification checkpoints. For every processing pipeline, teams must verify that the required audit question is answered affirmatively and substantiated by contemporaneous documentary evidence.
| Principle | Key Audit Verification Question | Mandatory Evidentiary Proof |
|---|---|---|
| 1. Lawfulness | Is the processing mapped to a valid Article 6 legal ground? | Article 30 register entry; documented consent or LIA test. |
| 2. Purpose Limitation | Are all active uses compatible with the initial notice? | Privacy notices; compatibility assessment record (Art. 6.4). |
| 3. Minimisation | Are all collected fields strictly necessary for the service? | Form schema review; data dictionary; payload logs. |
| 4. Accuracy | Is there an accessible update workflow for individuals? | Account profile dashboard; customer service rectification logs. |
| 5. Storage Limitation | Are retention schedules defined and automated? | Retention policy; automated cron purge scripts; deletion certificates. |
| 6. Security & Integrity | Are data encrypted at rest and in transit with access silos? | Penetration test reports; TLS certificates; IAM access matrices. |