Audit Logs
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Logging and auditing of processing activities
Overview
7 sources · Sep 8, 2026Legal Framework
Audit logging obligations under the GDPR arise from several interlocking provisions rather than a single article. Article 5(2) establishes the accountability principle, requiring controllers to demonstrate compliance. Article 24(1) mandates appropriate technical and organisational measures to ensure and demonstrate that compliance. Article 32(1)(b) requires the ability to restore the availability of and access to personal data after a physical or technical incident — a capacity that presupposes systematic logging of processing activities. Article 30 imposes record-keeping obligations that audit logs operationalise technically, while Article 33(1) requires breach notification within 72 hours, rendering timely incident detection through logging a practical legal requirement.
Key Developments
The Finnish DPA's €1.1 million fine against Yliopiston Apteekin illustrates enforcement focus on logging and audit trail deficiencies in web analytics processing, where the Deputy Data Protection Ombudsman scrutinised inadequate accountability measures.
Healthcare-sector litigation before the Rechtbank Den Haag underscores the sensitivity of processing operations where audit logging is most critical:
"Zilveren Kruis c.s. vergoedt zorg vanuit de basisverzekering, waaronder persoonlijke verzorging en verpleging in de eigen omgeving."
— Rechtbank Den Haag, 04-10-2023
The case involves multi-party corporate arrangements in healthcare delivery:
"[gedaagde 3] is minnelijk enig aandeelhouder en bestuurder van [gedaagde 1] , namelijk via [gedaagde 2] , opgericht op 12 februari 2015."
— Rechtbank Den Haag, 04-10-2023
Such arrangements heighten the need for audit logs to trace data flows and delineate responsibility among controllers and processors.
Status of the Debate
The doctrinal status is contested. While Article 32 clearly requires security measures including incident detection capability, the specific scope and granularity of audit logging remain actively litigated. Courts and DPAs diverge on whether comprehensive access logging is mandatory or whether category-based logging suffices. No CJEU ruling has established a minimum threshold for audit logging adequacy. The debate is enforcement-led, with national DPAs setting expectations through fines rather than harmonised guidance. A preliminary ruling clarifying whether Article 32(1)(b) mandates comprehensive access logging would resolve the open question.
Practical Guidance
- Implement audit logging for all access to and modifications of personal data, with heightened granularity for Article 9 special category data where reconstructing processing sequences is essential for Article 33 breach notification compliance.
- Capture accessor identity, timestamp, data elements accessed, and processing operation in each log entry to satisfy the accountability requirement of Article 5(2).
- Retain logs for a period sufficient to detect breaches and meet the 72-hour notification deadline under Article 33(1), with regular testing through simulated incident scenarios.
- Protect audit logs against unauthorised alteration or deletion, treating logs themselves as personal data requiring Article 32 security measures and Article 30 record-keeping.
why this is here
Logs tracing all data flows leaving the company (including outbound email) are available.
The document repeatedly refers to logs as a means to investigate whether data was exfiltrated, which is relevant to auditing but not the main focus.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Logging (cf. Art. 25 LED) is an important safeguard for verification of the lawfulness of the processing...
The document supports audit logging as a safeguard for law enforcement processing.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
technical and organisational measures which are designed to implement the data protection principles
Audit logs could be a technical measure, but the document does not specifically discuss them.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The DPA found that Amiu did not have a valid legal basis to publish the images. It also found that the processing was not sufficiently regulated, contrary to the requirements of Art. 28 GDPR.
Amiu's failure to properly regulate the processing via Article 28 GDPR (controller-processor contract) and to maintain a lawful basis for publication directly implicates audit-logging and accountability duties for documenting processing activities.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 23 Guidance