Skip to content
Topic Contested in court

Audit Logs

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Logging and auditing of processing activities

116 linked items 21 Case Law23 Guidance38 Enforcement33 News1 Literature

Overview

9 sources · Jul 23, 2026

Legal Framework

Audit logs serve as a critical mechanism for demonstrating compliance with the accountability principle under Article 5(2) GDPR. While the GDPR does not explicitly mandate "audit logs" by that name, the requirement to maintain records of processing activities under Article 30, and to implement appropriate technical and organizational measures under Article 32, necessitates robust logging systems. Specifically, Article 32 requires controllers to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems, which includes the ability to restore access in the event of an incident. Because audit logs inherently process personal data by recording user actions, their creation and retention must be anchored in a lawful basis under Article 6, typically Article 6(1)(c) for compliance with a legal obligation or Article 6(1)(f) for legitimate interests in system security.

Key Developments

The CJEU decision in Worten established that the collection and processing of personal data within records to ensure compliance with legal obligations is lawful if strictly necessary. The court emphasized that access to such records should be limited to authorities with monitoring powers, reinforcing the principle of data minimization even within internal logging systems. Enforcement actions, such as the Finnish DPA’s €1.1 million fine against Yliopiston Apteekin, demonstrate that inadequate monitoring and logging of web analytics and tracking tools constitute severe security and accountability failures. The EDPB Guidelines on the interplay between PSD2 and GDPR further clarify that logging access to payment systems is essential for fraud prevention and regulatory compliance, setting a high standard for the granularity and security of financial processing logs.

Practical Guidance

  • Restrict access to audit logs exclusively to authorized security and compliance personnel, aligning with the necessity and proportionality standards established in Worten.
  • Configure logging systems to capture metadata essential for security and accountability—such as user IDs, timestamps, and accessed datasets—without recording the content of the personal data itself, ensuring compliance with Article 5(1)(c) data minimization.
  • Implement automated alerts for anomalous access patterns within audit logs to satisfy the Article 32 requirement for ongoing resilience and prompt incident detection.
  • Establish strict retention periods for audit logs based on the specific legal obligation or security need, permanently deleting logs once that purpose expires to avoid indefinite storage.
  • Regularly test audit log integrity and restoration capabilities to ensure they can effectively support breach investigations and demonstrate accountability to supervisory authorities under Article 5(2).
Everything on this topic, by type links go to the exact provision / paragraph / section
Case Law 21
40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 252/21 Meta Platforms v noyb CJEU Jan 2023 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 CJEU WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”) CJEU May 2013 623/17 Privacy International v Secretary of State CJEU Oct 2020 507/17 Google LLC v CNIL CJEU Sep 2019 807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin CJEU Dec 2023 136/17 GC and Others v CNIL CJEU Sep 2019 601/21 Meta Platforms and Others v Bundeskartellamt CJEU Jul 2023 311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems CJEU Jul 2020 131/12 Google Spain SL and Google Inc. v AEPD and Mario Costeja González CJEU May 2014 CJEU CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is CJEU Jun 2010 CJEU WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”) CJEU May 2013 CJEU SCARLET EXTENDED SA V. SOCIETE BELGE DES AUTEURS, COMPOSITEURS ET EDITEURS SCRL (SABAM), 24.Nov.2011 (“SCARLET”) CJEU Nov 2011 Show 1 more →
Guidance 23
guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 Show 3 more →
Enforcement 38
Deputy Data Protection Ombudsman Universiteitsapotheek: Niet-naleving van algemene principes voor gegevensverwerking. Deputy Data Protection Ombudsman May 2025 NL Croatian Data Protection Authority (azop) Company: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) Mar 2025 Deputy Data Protection Ombudsman Yliopiston Apteekin: Non-compliance with general data processing principles Deputy Data Protection Ombudsman May 2025 Croatian Data Protection Authority (azop) Hospital: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) Mar 2025 French Data Protection Authority (CNIL) Real estate company: Non-compliance with general data processing principles French Data Protection Authority (CNIL) Feb 2025 Italian Data Protection Authority (Garante) Municipality of Modica: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Jul 2023 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Schockholm School borard: Non-compliance with general data processing principles Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Oct 2023 Italian Data Protection Authority (Garante) Ew Business Machines S.p.A.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Jun 2023 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) REGENCY COMPANY SRL: Non-compliance with general data processing principles Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Apr 2023 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Tehnoplus Industry SRL: Non-compliance with general data processing principles Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Mar 2023 Italian Data Protection Authority (Garante) Lazio Region: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Dec 2022 Belgian Data Protection Authority (APD) Brussels Airport Charleroi: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) Apr 2022 Italian Data Protection Authority (Garante) Bocconi University: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Sep 2021 Belgian Data Protection Authority (APD) Brussels Airport Zaventem: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) Apr 2022 Italian Data Protection Authority (Garante) Amiu S.p.A.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Apr 2022 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Jun 2021 Spanish Data Protection Authority (aepd) Private Individual: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Apr 2021 Spanish Data Protection Authority (aepd) Laboratorio Octogón, S.L.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Mar 2021 Spanish Data Protection Authority (aepd) Private Individual: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Apr 2021 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Feb 2021 Show 18 more →
News 33
EDPB Support the EDPB’s work as an expert EDPB Nov 2025 Government The "policy situation" surrounding Transaction Monitoring Netherlands. Government Jan 2026 EU News Kort: EU News Jan 2026 Autoriteit Persoonsgegevens Supervision of the European Data Regulation begins. Autoriteit Persoonsgegevens Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 Electronic Frontier Foundation EFF investigations reveal abuse of surveillance by Flock Safety: a look back at 2025. Electronic Frontier Foundation Dec 2025 Government the 'policy situation' surrounding Transaction Monitoring Netherlands Government Jan 2026 EU News In short: EU News Jan 2026 Electronic Frontier Foundation States Tried to Censor Kids Online. Courts, and EFF, Mostly Stopped Them: 2025 in Review Electronic Frontier Foundation Dec 2025 European Digital Rights From "chat monitoring" to solutions that truly protect children and their privacy. European Digital Rights Dec 2025 Electronic Frontier Foundation States attempted to censor the online activities of children. Courts and the Electronic Frontier Foundation (EFF) largely managed to prevent this: a look back at 2025. Electronic Frontier Foundation Dec 2025 Electronic Frontier Foundation EFF Joins Internet Advocates Calling on the Iranian Government to Restore Full Internet Connectivity Electronic Frontier Foundation Jan 2026 University of Twente University of Twente: Regarding the effectiveness of online proctoring using the Proctorio platform. University of Twente Nov 2025 Government Monitoring of appropriate education in vocational secondary education. Measurement in 2024. Government Apr 2025 Government Partial Report BZK Government Feb 2025 IAPP De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd. IAPP Oct 2022 NL IAPP Greek SA fines Clearview AI for EUR 20M IAPP Oct 2022 Hunton Andrews Kurth ICO Publishes Draft Employee Monitoring Guidance for Consultation Hunton Andrews Kurth Oct 2022 AEPD AEPD publishes GDPR Risk Assessment AEPD Oct 2022 Show 13 more →
Literature 1
Journal of Computer Science and Technology Studies Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure Journal of Computer Science and Technology Studies Nov 2025