Each controller (and its representative) must keep written and electronic records of processing: its name and contact details and those of any joint controller, representative and DPO; purposes; categories of data subjects and data; categories of recipients including abroad; transfers to third countries or international organisations with their identification and, for authorised clause transfers, documentation of safeguards; where possible, erasure time limits; and a general description of the security measures. Each processor (and representative) must keep records of the processing done for each controller: its and each controller's details and DPO, the officers engaged for specific tasks, the categories of processing, transfers with their legal basis under Articles 40 to 42, and the security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to create a risk, is not occasional, or includes sensitive data or criminal records. The Law replaces the former duty to notify processing to the Commissioner with this record.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.