Requirement
Controllers and processors shall maintain a record of processing activities including purposes, categories of data subjects and data, recipients, third-country transfers, retention periods and security measures.
UK GDPR: Under UK GDPR the same record is required; the ICO publishes a template.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| PCI DSS 4.0.1 | 12.5.2 | PCI DSS scope documented and confirmed annually | inventory records |
| CCPA/CPRA | Regs 7101 | Records of consumer requests kept for 24 months | records |
| SOC 2 | CC2.1 | Quality information for internal control | records |
| ISO 27001 | A.5.9 | Inventory of information and other associated assets | inventory |
| ISO 27001 | A.5.31 | Legal, statutory, regulatory and contractual requirements | records |
| GLBA | 314.4(c)(2) | Inventory of data, personnel, devices and systems | inventory |
| NIST CSF 2.0 | ID.AM-01 | Inventories of hardware are maintained | inventory |
| NDPA 2023 | s.44 | Registration as a data controller or processor of major importance | records |