Reuse evidence from GDPR across ISO 27701 and the AI Act

Stop duplicating documents. Map the supporting evidence once and let it fulfil all the requirements that refer to it.

The iComply Team
AI Governance

Reuse Evidence

Privacy teams produce a great deal of evidence: processing records, personal data impact assessments, retention periods, consent records and transfer assessments. The mistake is to file this evidence by framework. When this is done, the same retention policy ends up in the GDPR folder, the ISO 27701 folder and the AI Act folder — three copies, three updating issues.

Evidence belongs to a control, not a framework

Attach the evidence to the control it supports and let the frameworks reference the control. Its retention period is attached once to a ‘retention governance’ control. The GDPR, ISO 27701 and any other framework that requires it inherit the same evidence — with a single version history.

An example of privacy

  • The processing records demonstrate the controls referred to in the GDPR (Article 30) and ISO 27701.
  • A Data Protection Impact Assessment (DPIA) may also form part of a Fundamental Rights Impact Assessment under the AI Act when AI processes personal data.
  • Access controls demonstrate compliance with both the GDPR and ISO 27001.

Why it matters beyond just tidying up

Reuse is not just about convenience — it’s about rigour. A single source of truth means that when a document is updated, it is updated everywhere instantly, so an auditor never sees an out-of-date copy. It also makes expansion cost-effective: adding ISO 27701 to an existing GDPR programme becomes a mapping exercise, rather than a redrafting project.

The principle is simple and applies across all areas: capture it once, reuse it everywhere.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Two interconnected circles representing the relationship between the ISO 42001 standard and the European AI Regulation

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

Seven ascending layers representing the stages involved in building a unified governance programme with iComply

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.