Reuse Evidence
Privacy teams produce a great deal of evidence: processing records, personal data impact assessments, retention periods, consent records and transfer assessments. The mistake is to file this evidence by framework. When this is done, the same retention policy ends up in the GDPR folder, the ISO 27701 folder and the AI Act folder — three copies, three updating issues.
Evidence belongs to a control, not a framework
Attach the evidence to the control it supports and let the frameworks reference the control. Its retention period is attached once to a ‘retention governance’ control. The GDPR, ISO 27701 and any other framework that requires it inherit the same evidence — with a single version history.
An example of privacy
- The processing records demonstrate the controls referred to in the GDPR (Article 30) and ISO 27701.
- A Data Protection Impact Assessment (DPIA) may also form part of a Fundamental Rights Impact Assessment under the AI Act when AI processes personal data.
- Access controls demonstrate compliance with both the GDPR and ISO 27001.
Why it matters beyond just tidying up
Reuse is not just about convenience — it’s about rigour. A single source of truth means that when a document is updated, it is updated everywhere instantly, so an auditor never sees an out-of-date copy. It also makes expansion cost-effective: adding ISO 27701 to an existing GDPR programme becomes a mapping exercise, rather than a redrafting project.
The principle is simple and applies across all areas: capture it once, reuse it everywhere.