← NDPA 2023 · Accountability

GAID Art.10 — Compliance audit returns and records of processing (GAID 2025)

high recordsaudit

Requirement

The Act does not itself impose a general duty to keep records of processing, but the NDPC's GAID 2025 requires data controllers and processors of major importance to file annual Compliance Audit Returns with the Commission (by 31 March for established organisations; Art. 10) and requires the DPO's semi-annual data protection reports to form part of a Record of Processing Activities (Art. 13).

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
record of processingrecordsauditcompliance audit returnropaauditorcompliance audit returns
Required element 2 — any one of
annualdemonstrate compliancefiledmaintain
Supporting terms — specificity signals
gaidcompliance auditndpclicenseddpcoregisterreview31 marcharticle 10article 13semi-annual
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no records of processing no compliance audit

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.5(2) Accountability records
GDPR Art.30 Records of processing activities records
CCPA/CPRA Regs 7101 Records of consumer requests kept for 24 months records
CCPA/CPRA Regs (cybersecurity audits) Annual independent cybersecurity audit audit
SOC 2 CC2.1 Quality information for internal control records
SOC 2 CC4.1 Ongoing and separate evaluations audit
SOC 2 CC4.2 Communication of deficiencies audit
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements records