CB Partners Blog

From “We're Compliant” to “We Can Prove It”: A Practical Guide to Demonstrable Privacy

From “We're Compliant” to “We Can Prove It”: A Practical Guide to Demonstrable Privacy

The gap between saying "we're compliant" and being able to show it is where regulatory exposure, lost contracts, and reputational risk accumulate. This guide explains what demonstrable privacy means under the GDPR, what it looks like in daily operations, and how CB Partners helps close that gap.

Most organisations that have invested in GDPR compliance believe they are compliant. They have a privacy policy, a record of processing activities, processor contracts and, in many cases, a DPO or legal adviser who reviewed everything at implementation. When asked whether they comply with the GDPR, the honest answer is: probably yes, in the sense that the right things were done at a point in time.

But there is a second question that is harder to answer: can you prove it? Not that you intended to comply, or that you once set up the right structures, but that you are compliant right now, that you have been continuously compliant, and that you can demonstrate this with actual evidence to a supervisory authority, an enterprise client, or an investor doing due diligence.

These are different questions. And the gap between saying "we're compliant" and being able to show it is where regulatory exposure, lost contracts and reputational risk accumulate. This guide explains what demonstrable privacy means under the GDPR, what it looks like in daily operations, and how CB Partners helps close that gap.

1. The Difference Between Being Compliant and Being Able to Prove It

The GDPR does not simply require organisations to comply. It requires them to be accountable for their compliance, and accountability, in legal and regulatory terms, means evidence. Article 5(2) states that the controller shall be responsible for, and be able to demonstrate compliance with, the data protection principles. This is not a soft obligation; it is a structural requirement that runs through the entire regulation.

In practice, the difference between being compliant and being able to prove it comes down to three things: whether compliance decisions are documented at the time they are made, whether the evidence of ongoing compliance is stored in a retrievable and structured way, and whether the organisation can produce that evidence on request without a lengthy reconstruction exercise.

An organisation that processed a data subject request correctly but did not log the request, the steps taken or the response given cannot demonstrate that it handled the request correctly. An organisation that delivers annual privacy training but keeps no record of attendance cannot demonstrate that its staff are informed. In each of these cases, the compliance may have happened, but it cannot be shown. Under the GDPR, that is a compliance gap.

2. What "Demonstrable" Actually Means Under the GDPR

Demonstrable compliance is the capacity to show, with contemporaneous evidence, that data protection obligations are being met in practice and on an ongoing basis. The word "contemporaneous" matters: evidence created after the fact, reconstructed from memory or assembled under pressure during an inspection, carries far less weight than records generated at the time the relevant activity took place.

European data protection authorities have been clear about what they expect. The AEPD in Spain, the CNIL in France, the ICO in the United Kingdom and the supervisory authorities across the EU consistently ask, in inspections and enforcement proceedings, not just whether a policy exists but whether it is applied, how compliance is monitored, and what evidence exists of the decisions made. Fines have been issued not because organisations lacked policies, but because they could not demonstrate that those policies were being followed.

Demonstrable compliance has three layers: the first is structural (having the right policies, legal bases, contracts and assessments in place); the second is operational (those structures being actively used, assessments being conducted, requests being handled, vendors being reviewed); the third is evidential (records of all of the above being stored, organised and accessible). Most organisations have the first layer. Fewer have the second. Fewer still have the third in a form that holds up under scrutiny.

3. Why Statements Are Not Evidence

A privacy policy is a statement of how an organisation intends to handle personal data. A record of processing activities is a statement of what processing the organisation carries out. A Data Processing Agreement is a statement of the obligations between controller and processor. These documents are necessary; without them, there is no framework for compliance. But they are not, by themselves, evidence that compliance is happening.

The distinction is the difference between a commitment and a record. A commitment describes what will be done. A record shows what was done, when, by whom, and with what outcome. When a supervisory authority investigates a complaint or conducts a routine inspection, it is records they examine, not the policies that describe what the organisation planned to do.

Consider a company that receives a request for erasure under Article 17. Its privacy policy states that erasure requests are handled within one month. If the company has no log of when the request was received, no record of the steps taken to action it, and no documentation of the response sent, it cannot demonstrate that the obligation was met, even if it was.

4. What Demonstrable Compliance Looks Like in Day-to-Day Operations

Demonstrable compliance is not an audit-preparation exercise. It is a way of operating that generates evidence continuously, as a byproduct of well-designed processes. In practice, it has to be visible in five specific areas of daily operations.

Processing decisions are made with documented rationale

Every time a new processing activity is initiated, a new product feature, a new marketing tool, a new data sharing arrangement, the decision about legal basis, purpose limitation and retention should be made explicitly and recorded, not in a lengthy report, but in a structured record showing what was decided, on what basis, who made the decision, and when. This is what makes the RoPA a living document rather than a historical one.

CB Partners works with organisations to define governance triggers, the categories of decision that require a formal privacy review, and to establish the documentation that review should produce. The result is that processing decisions accumulate a traceable rationale over time, rather than being made informally and then forgotten.

Assessments are conducted, approved and linked to processing

A DPIA is not evidence of compliance on its own. It is evidence of compliance when it is completed before the relevant processing begins, when it reflects a genuine analysis of risk and mitigation, when it has been reviewed and approved by the appropriate person, and when it remains connected to the processing activity it covers so that both can be examined together.

The same applies to Legitimate Interest Assessments and Transfer Impact Assessments. Each is a decision-making record: it shows that the organisation considered the legal and risk dimensions of a processing activity and reached a reasoned conclusion.

Data subject requests are logged from receipt to closure

Under Articles 15 to 22 of the GDPR, individuals have rights that must be responded to within defined deadlines. Demonstrating compliance requires a complete log of every request received: the date and channel of receipt, the type of request, verification steps, the actions taken, the date and content of the response, and the legal basis for any limitation or refusal. This log is the evidence.

Vendor relationships are monitored, not just documented

Signing a Data Processing Agreement is a point-in-time action. Demonstrating ongoing compliance with Article 28 requires showing that the relationship with the processor has been actively managed: that the DPA was in place before data flows began, that sub-processor changes have been monitored, that the vendor's security measures have been assessed, and that the contract has been reviewed at renewal.

Training is delivered, recorded and evidenced

Staff training is required under the GDPR's accountability principle, and authorities ask for evidence of it. The evidence required is a record showing which training was delivered, to whom, on what date, and with what outcome. In regulated sectors or where processing is high-risk, evidence of role-specific training and periodic refreshers is increasingly expected.

5. The Role of Logs, Approvals and Metrics

If day-to-day operations are the body of demonstrable compliance, logs, approvals and metrics are the skeleton. They are the structures that make evidence retrievable, credible and usable in a regulatory or commercial context.

Logs are contemporaneous records of actions taken: data subject requests received, DPIA approvals, training completions, vendor contract reviews. Logs are more credible than reports produced after the fact because they were generated as the activity occurred.

Approvals are the records of decisions made at governance level: when a DPO reviews and approves a DPIA, when a compliance officer signs off on a legal basis assessment. Approvals show that compliance is governed and that decisions are made with appropriate authority.

Metrics are the evidence of systemic performance over time: the percentage of data subject requests closed within the legal deadline, the proportion of processing activities with a current DPIA, the number of staff who have completed training, the number of vendors with a current DPA. These indicators show that compliance is monitored and managed, not assumed.

6. How CB Partners Builds the Compliance You Can Stand Behind

Demonstrable compliance starts with getting the framework right. If the legal bases are incorrect, if the DPIAs are incomplete, if the processor contracts do not meet Article 28 requirements, no amount of operational infrastructure will produce genuine evidence of compliance; it will produce evidence of a flawed framework being consistently applied.

We build the compliance framework from first principles: a maturity assessment that identifies where the organisation actually stands, legal basis review against the GDPR's requirements and the AEPD's guidance, DPIAs and LIAs structured as genuine risk analysis, processor contracts reviewed against Article 28, and a governance model that assigns accountability clearly.

Our external DPO function is not a formality. It is an active, independent function that monitors compliance, advises on new processing decisions, reviews the output of assessments, acts as the contact point for the supervisory authority, and contributes to the training and awareness of staff.

Frequently Asked Questions

What does "demonstrable compliance" mean under the GDPR?

Demonstrable compliance under the GDPR means being able to show, with contemporaneous evidence, that data protection obligations are being met in practice and on an ongoing basis. It flows from Article 5(2), the accountability principle, which requires controllers not just to comply with data protection principles but to be able to demonstrate compliance.

What evidence does a supervisory authority look for in a GDPR inspection?

Supervisory authorities across the EU, including the AEPD in Spain, consistently ask to see the Record of Processing Activities and whether it reflects current processing; the legal basis for each category of processing; completed DPIAs and LIAs where required; logs of data subject requests; staff training records; and vendor management records including DPAs and sub-processor information.

Why is a privacy policy not enough to demonstrate GDPR compliance?

A privacy policy is a statement of intent; it is a necessary part of transparency under Articles 13 and 14 but it is not evidence that data is being handled in the way described. Demonstrable compliance requires records of actual processing activities, documented decisions, completed assessments, logs, training records and vendor management documentation.

How should data subject requests be documented to demonstrate compliance?

Every request should be logged from receipt, with the date and channel, the type of request, identity verification steps, actions taken, the date of the response, and the legal basis for any refusal. Under Article 12 the general response deadline is one month, and any extension must be communicated and documented.

What is the difference between a DPIA and demonstrable compliance?

A DPIA is one component of demonstrable compliance, the evidence that high-risk processing has been assessed before it began. It needs to be linked to the processing activity it covers, approved by the appropriate person, and reviewed when the processing changes. It is one record in a broader evidence base.

How do metrics help demonstrate GDPR compliance?

Metrics show that compliance is monitored and managed systemically, not just asserted: the percentage of requests resolved within deadline, the proportion of processing activities with a current DPIA, training completion rates, and vendor DPA status. They also let the compliance team identify gaps before they become regulatory issues.

Can you demonstrate GDPR compliance without a dedicated compliance platform?

It is possible but increasingly difficult at scale. Without a dedicated platform, evidence tends to accumulate across email threads and shared drives, making it hard to retrieve and vulnerable to loss when team members change. A compliance management platform centralises records and ensures documentation is structured, retrievable and audit-ready.

Ready to talk about your compliance roadmap?

Tell us which frameworks apply to you and we'll scope an engagement within days.