Skip to content
Topic Contested in court

Audit Logs

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Logging and auditing of processing activities

71 linked items 17 Case Law23 Guidance12 Enforcement18 News1 Literature

Overview

7 sources · Sep 8, 2026

Legal Framework

Audit logging obligations under the GDPR arise from several interlocking provisions rather than a single article. Article 5(2) establishes the accountability principle, requiring controllers to demonstrate compliance. Article 24(1) mandates appropriate technical and organisational measures to ensure and demonstrate that compliance. Article 32(1)(b) requires the ability to restore the availability of and access to personal data after a physical or technical incident — a capacity that presupposes systematic logging of processing activities. Article 30 imposes record-keeping obligations that audit logs operationalise technically, while Article 33(1) requires breach notification within 72 hours, rendering timely incident detection through logging a practical legal requirement.

Key Developments

The Finnish DPA's €1.1 million fine against Yliopiston Apteekin illustrates enforcement focus on logging and audit trail deficiencies in web analytics processing, where the Deputy Data Protection Ombudsman scrutinised inadequate accountability measures.

Healthcare-sector litigation before the Rechtbank Den Haag underscores the sensitivity of processing operations where audit logging is most critical:

"Zilveren Kruis c.s. vergoedt zorg vanuit de basisverzekering, waaronder persoonlijke verzorging en verpleging in de eigen omgeving."
— Rechtbank Den Haag, 04-10-2023

The case involves multi-party corporate arrangements in healthcare delivery:

"[gedaagde 3] is minnelijk enig aandeelhouder en bestuurder van [gedaagde 1] , namelijk via [gedaagde 2] , opgericht op 12 februari 2015."
— Rechtbank Den Haag, 04-10-2023

Such arrangements heighten the need for audit logs to trace data flows and delineate responsibility among controllers and processors.

Status of the Debate

The doctrinal status is contested. While Article 32 clearly requires security measures including incident detection capability, the specific scope and granularity of audit logging remain actively litigated. Courts and DPAs diverge on whether comprehensive access logging is mandatory or whether category-based logging suffices. No CJEU ruling has established a minimum threshold for audit logging adequacy. The debate is enforcement-led, with national DPAs setting expectations through fines rather than harmonised guidance. A preliminary ruling clarifying whether Article 32(1)(b) mandates comprehensive access logging would resolve the open question.

Practical Guidance

  • Implement audit logging for all access to and modifications of personal data, with heightened granularity for Article 9 special category data where reconstructing processing sequences is essential for Article 33 breach notification compliance.
  • Capture accessor identity, timestamp, data elements accessed, and processing operation in each log entry to satisfy the accountability requirement of Article 5(2).
  • Retain logs for a period sufficient to detect breaches and meet the 72-hour notification deadline under Article 33(1), with regular testing through simulated incident scenarios.
  • Protect audit logs against unauthorised alteration or deletion, treating logs themselves as personal data requiring Article 32 security measures and Article 30 record-keeping.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Guidance EDPB Jan 2022 logs for breach investigation
why this is here
Logs tracing all data flows leaving the company (including outbound email) are available.

The document repeatedly refers to logs as a means to investigate whether data was exfiltrated, which is relevant to auditing but not the main focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 05/2022 use of facial recognition technology in the area of law enforcement Guidelines ·EDPB Guidance EDPB May 2023 Logging as safeguard
why this is here
Logging (cf. Art. 25 LED) is an important safeguard for verification of the lawfulness of the processing...

The document supports audit logging as a safeguard for law enforcement processing.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Technical measures for logging
why this is here
technical and organisational measures which are designed to implement the data protection principles

Audit logs could be a technical measure, but the document does not specifically discuss them.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

€200,000 Amiu S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 200,000 on Amiu S.p.A.. The company operates the waste collection service for the city of Taranto and acted as a processor for this… ITALY ·Garante ·Art. 5, 6, 28 +1 Enforcement Italian Data Protection Authority (Garante) Apr 2022 accounting
why this is here
The DPA found that Amiu did not have a valid legal basis to publish the images. It also found that the processing was not sufficiently regulated, contrary to the requirements of Art. 28 GDPR.

Amiu's failure to properly regulate the processing via Article 28 GDPR (controller-processor contract) and to maintain a lawful basis for publication directly implicates audit-logging and accountability duties for documenting processing activities.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 23 Guidance