Guides/GDPR evidence
Step-by-step guide

How to collect GDPR evidence

GDPR compliance is not a policy document — it is a set of evidence-backed practices. This guide explains what evidence you need, how to collect it, and how to keep it organised so that when the ICO asks, you have answers.

01

Map the personal data you hold

You cannot evidence compliance with data you have not mapped. Start by identifying every category of personal data your organisation holds, where it lives, and why.

Customer data

Names, contact details, purchase history, preferences, loyalty data, payment records.

Employee data

HR records, payroll, contracts, performance data, health information, disciplinary records.

Supplier and partner data

Contacts at suppliers, contractors, and partners — especially where held in shared systems.

Prospect and marketing data

Email lists, CRM records, event attendees, downloaded content — with consent status for each.

What they look for

If the ICO investigates, the first question is: 'What personal data do you hold and why?' If you cannot answer from a document, you have no GDPR evidence. Your data map — even a simple one — is the foundation everything else references.

02

Build your Records of Processing Activities (ROPA)

Article 30 of the UK GDPR requires organisations to maintain a record of all processing activities. This is the backbone of your GDPR evidence — and the first thing the ICO will ask for if they investigate.

What to record per activity

Purpose of processing, categories of data, data subjects, recipients (especially third parties), transfers outside the UK, retention periods, and security measures.

What counts as a "processing activity"

Sending marketing emails, running payroll, storing customer orders, logging support tickets, using analytics tools — each is a separate activity.

Who is responsible

Assign an owner for each processing activity. They are accountable for keeping the record accurate and the processing lawful.

What they look for

The ICO does not prescribe a ROPA format, but it must contain: controller identity, purposes of processing, categories of data subjects and personal data, recipients, international transfers, retention periods, and security measures. A spreadsheet with these columns is sufficient — completeness matters more than format.

03

Document your lawful basis for each activity

Every processing activity must have a documented lawful basis under Article 6 (and Article 9 for special category data). Picking the right basis matters — you cannot switch later without telling people.

Legitimate interests

Most common for B2B processing, fraud prevention, and analytics. Requires a Legitimate Interests Assessment (LIA) document.

Contract

Processing necessary to perform a contract with the data subject — typical for customer orders and employee payroll.

Consent

For marketing to individuals. Must be freely given, specific, informed, and documented. Cannot be bundled with other terms.

Legal obligation

Processing required by law — HMRC reporting, companies house filings, health and safety records.

What they look for

The ICO asks for the documented lawful basis as it existed at the time of processing. If you relied on consent, you need the consent record: date, mechanism, and exact wording shown to the individual. If you relied on legitimate interests, you need a completed Legitimate Interests Assessment document — not just a note that you chose this basis.

04

Review third-party data sharing

Every time you share personal data with a third party — a cloud provider, a payroll bureau, a marketing platform — you need a Data Processing Agreement (DPA) in place and a record of the sharing arrangement.

Identify your data processors

Any third party that processes data on your behalf: your CRM, email platform, cloud storage, payroll provider, IT support company.

Check for DPAs

Most major platforms (Google, Microsoft, Mailchimp, HubSpot) provide DPAs — but you need to have accepted them and have a record of it.

Check for international transfers

Data sent outside the UK/EEA requires an adequacy decision, SCCs, or other transfer mechanism. Identify which of your tools process data in the US or elsewhere.

What they look for

Your processor list and the DPAs against each one. For major SaaS tools (Google, Microsoft, Mailchimp, HubSpot), the DPA is a click-through in admin settings — but you need to have accepted it and have a record. Processors without DPAs are one of the most common ICO findings in SME investigations.

05

Audit your consent records and privacy notices

If you rely on consent for any processing, you must be able to prove someone gave it — when, on what basis, and for what purpose.

Consent records

Timestamp, source (which form or channel), what they consented to, and how they can withdraw. Most email platforms store this — verify it is actually captured.

Privacy notices

Must be up to date, accurate, and written in plain English. Check that what the notice says matches what you actually do — especially after introducing new tools or services.

Withdrawal mechanism

An unsubscribe link is not enough for all consent. Make sure your suppression lists are applied across all systems — not just the tool that received the opt-out.

What they look for

Consent records must show: timestamp, source (which form or channel), the exact wording of the consent request, and how withdrawal can be exercised. Most email platforms export this. Check that your suppression list is applied across all marketing systems — not just the one that received the opt-out.

06

Set up a process for subject access and erasure requests

You have one month to respond to subject access requests (SARs) and erasure requests. Without a documented process, one request can consume days of staff time. With a process in place, it is a known procedure.

Log every request

Date received, requestor identity, type of request (SAR, erasure, rectification), due date. The ICO expects you to demonstrate you responded within the deadline.

Know where to find the data

A SAR means checking every system that might hold data about that person — CRM, email, accounting, support desk, cloud storage. Your ROPA tells you where to look.

Erasure considerations

Some data cannot be erased despite a request — legal obligations, contractual necessity, legitimate interests. Document the reason when you decline a request.

What they look for

The ICO expects you to demonstrate you responded to SARs and erasure requests within the legal deadline (one calendar month). Keep a log with the date received, type of request, and date responded. If you missed a deadline, document why and what you did to address it — an honest explanation is better than no record.

Where people go wrong

Common GDPR compliance mistakes

✕

Relying on consent when legitimate interests is more appropriate — then losing the consent records

Consent requires ongoing maintenance: records of who consented, when, and to what. Many businesses choose consent, fail to maintain records, and then cannot evidence compliance. For B2B processing, legitimate interests is often more appropriate and more sustainable.

✕

Not maintaining DPAs with cloud and SaaS providers

Every cloud tool that processes personal data on your behalf is a data processor. You need a DPA with each one. Most provide them in admin settings but require active acceptance — checking a box, not just using the service.

✕

Privacy notice that does not reflect actual practice

Privacy notices are reviewed against what you actually do. If your notice says you use data for one purpose and you use it for another, that is a breach regardless of whether the notice exists. Review your notice whenever you introduce a new tool or change how you use data.

✕

No documented process for SARs — resulting in missed deadlines

Subject access requests have a hard one-month deadline. Without a documented process, a SAR arriving during a staff absence or busy period can be missed easily. One missed deadline can trigger an ICO complaint.

Common questions about GDPR evidence

What evidence does the ICO actually look for?

In an investigation, the ICO typically asks for: your ROPA, privacy notices, consent records, DPAs with processors, evidence of security measures, and records of any data breaches. Having these organised and accurate is the difference between a formal warning and a fine.

Do small businesses need to maintain a ROPA?

Technically, businesses with fewer than 250 employees are exempt unless processing is high-risk, not occasional, or includes special category data. In practice, maintaining a ROPA is good practice regardless — it forces you to understand what you hold and why.

How often should we review our GDPR evidence?

Annual review as a minimum, plus triggered reviews when you introduce new tools, services, or suppliers; change how you use existing data; suffer a data breach; or receive a SAR that reveals gaps in your records.

What is the biggest GDPR mistake small businesses make?

Relying on consent when legitimate interests would be more appropriate — and then not being able to produce consent records when asked. The second most common: not maintaining DPAs with cloud and SaaS providers.

Start with a free GDPR readiness assessment

Fortify's free GDPR assessment identifies the gaps in your data protection practices — consent records, ROPA completeness, third-party arrangements — and gives you a prioritised action plan.