Record of processing
What data you hold, why, where it lives, how long you keep it and who accesses it. Mandatory above 250 staff, and indispensable in any case in order to reason.
Dizzus GmbH · Zug, Switzerland
Infrastructure we operate ourselves, data in Switzerland
Compliance is not proven by intentions but by dated documents. We build the file, and we keep it current.
An inspection, a client auditing you, an insurer after a loss: in all three cases the question is the same. What can you produce, and when was it established? An excellent technical setup that is undocumented is worth nothing in that conversation.
What data you hold, why, where it lives, how long you keep it and who accesses it. Mandatory above 250 staff, and indispensable in any case in order to reason.
A written contract with every third party that touches your data, with the list of its own subprocessors and the real location of the data.
What is backed up, how often, where, for how long, and the record of restore tests.
Who decides, who is told, in what order and within what deadline, with named people and their deputies.
Logs, monthly records, test reports. This is the material that turns a policy into an established fact.
A dated re-reading of the setup. Without it, your documentation becomes false in silence, which is worse than having none.
A thirty-minute review. You leave with a dated document listing your gaps in order of severity. No commitment, and it is yours.