# Audit Logs — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/audit-logs
> Sources are cited per item. Verify against the official texts before relying on them.

Logging and auditing of processing activities

## Overview

## Legal Framework
Audit logs serve as a critical mechanism for demonstrating compliance with the accountability principle under Article 5(2) GDPR. While the GDPR does not explicitly mandate "audit logs" by that name, the requirement to maintain records of processing activities under Article 30, and to implement appropriate technical and organizational measures under Article 32, necessitates robust logging systems. Specifically, Article 32 requires controllers to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems, which includes the ability to restore access in the event of an incident. Because audit logs inherently process personal data by recording user actions, their creation and retention must be anchored in a lawful basis under Article 6, typically Article 6(1)(c) for compliance with a legal obligation or Article 6(1)(f) for legitimate interests in system security.

## Key Developments
The CJEU decision in Worten established that the collection and processing of personal data within records to ensure compliance with legal obligations is lawful if strictly necessary. The court emphasized that access to such records should be limited to authorities with monitoring powers, reinforcing the principle of data minimization even within internal logging systems. Enforcement actions, such as the Finnish DPA’s €1.1 million fine against Yliopiston Apteekin, demonstrate that inadequate monitoring and logging of web analytics and tracking tools constitute severe security and accountability failures. The EDPB Guidelines on the interplay between PSD2 and GDPR further clarify that logging access to payment systems is essential for fraud prevention and regulatory compliance, setting a high standard for the granularity and security of financial processing logs.

## Practical Guidance
- Restrict access to audit logs exclusively to authorized security and compliance personnel, aligning with the necessity and proportionality standards established in Worten.
- Configure logging systems to capture metadata essential for security and accountability—such as user IDs, timestamps, and accessed datasets—without recording the content of the personal data itself, ensuring compliance with Article 5(1)(c) data minimization.
- Implement automated alerts for anomalous access patterns within audit logs to satisfy the Article 32 requirement for ongoing resilience and prompt incident detection.
- Establish strict retention periods for audit logs based on the specific legal obligation or security need, permanently deleting logs once that purpose expires to avoid indefinite storage.
- Regularly test audit log integrity and restoration capabilities to ensure they can effectively support breach investigations and demonstrate accountability to supervisory authorities under Article 5(2).

## Case law

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### Privacy International v Secretary of State

*Source: CJEU, C-623/17, 2020-10-06 — https://overview.legal/posts/51481 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0623*

General and indiscriminate transmission of traffic data to security agencies incompatible with EU law.

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

*Source: CJEU, C-311/18, 2020-07-16 — https://overview.legal/posts/51470 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=51470*

Invalidated Privacy Shield adequacy decision and upheld validity of Standard Contractual Clauses with additional safeguards required.

### GC and Others v CNIL

*Source: CJEU, C-136/17, 2019-09-24 — https://overview.legal/posts/51475 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0136*

Conditions for delisting sensitive data from search results.

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein

*Source: CJEU, C-210/16, 2018-06-05 — https://overview.legal/posts/51477 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=51477*

Facebook fan page administrators are joint controllers with Facebook.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### Google Spain SL and Google Inc. v AEPD and Mario Costeja González

*Source: CJEU, C-131/12, 2014-05-13 — https://overview.legal/posts/51472 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0131&ref=51472*

Established the right to be forgotten (delisting). Search engines are data controllers.

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/6180 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6180*

Purpose for processing: The legislation at issue does base the processing on consent. Rather, it provides that they are to be informed. Thus, processing is not based on their consent. (¶ 54)

### CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is

*Source: CJEU, 2010-06-29 — https://overview.legal/posts/6182 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62008CJ0028&ref=6182*

Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69)

## Guidance

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 07/2022 on certification as a tool for transfers

*Source: EDPB, edpb-guidelines-on-certification-as-a-tool-for-transfers, 2023-02-24 — https://overview.legal/posts/38131 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072022-on-certification-as-a-tool-for-transfers_en*

The GDPR requires in its Article 46 that data exporters shall put in place appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by data exporters under Article 46 for framing transfers to third countries by introducing, amongst others, certification as a new transfer mechanism (Articles 42 (2) and 46 (2) (f) GDPR). These guidelines provide guidance as to the applicati...

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

## Enforcement decisions

### Brussels Airport Charleroi: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2022-04-04 — https://overview.legal/posts/47232 — original: https://www.enforcementtracker.com/ETid-1117*

The Belgian DPA has fined Brussels Airport Charleroi EUR 100,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of persons at the airport. Due to the Covid-19 pandemic the airport used thermal imaging cameras to filter out people with body temperatures above 38 degrees. Those filtered out were then required to answer questions about possible coronavirus symptoms. The DPA particularly noted that the airport did not have a valid lega

### Bocconi University: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2021-09-16 — https://overview.legal/posts/46991 — original: https://www.enforcementtracker.com/ETid-876*

The Italian DPA (Garante) has imposed a fine of EUR 200,000 on Bocconi University. A student had filed a complaint with the DPA about possible GDPR violations related to the use of a monitoring system during written exams. In the context of the emergency situation triggered by the Covid-19 pandemic, the university had equipped itself with the remote monitoring software Respondus provided by the American company Respondus Inc. to ensure the normal running of the exams, since it was not possible t

### Brussels Airport Zaventem: Insufficient legal basis for data processing

*Source: Belgian Data Protection Authority (APD), 2022-04-04 — https://overview.legal/posts/47231 — original: https://www.enforcementtracker.com/ETid-1116*

The Belgian DPA has fined Brussels Airport Zaventem EUR 200,000. The DPA had launched an investigation against the airport following media reports about temperature monitoring of persons at the airport. Due to the Covid-19 pandemic the airport used thermal imaging cameras to filter out people with body temperatures above 38 degrees. Those filtered out were then required to answer questions about possible coronavirus symptoms. The DPA particularly noted that the airport did not have a valid legal

### Amiu S.p.A.: Insufficient legal basis for data processing

*Source: Italian Data Protection Authority (Garante), 2022-04-28 — https://overview.legal/posts/47782 — original: https://www.enforcementtracker.com/ETid-1667*

The Italian DPA has imposed a fine of EUR 200,000 on Amiu S.p.A.. The company operates the waste collection service for the city of Taranto and acted as a processor for this service. The company had installed several video surveillance cameras for the purpose of monitoring illegal waste disposal. The DPA found that Amiu had posted some images from the cameras on Facebook, showing individuals sufficiently visible making it possible to identify them. During its investigation, the DPA found that Am

### Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles

*Source: Data Protection Authority of Sweden (Integritetsskyddsmyndigheten), 2021-06-09 — https://overview.legal/posts/46837 — original: https://www.enforcementtracker.com/ETid-722*

The Swedish DPA has imposed a fine of EUR 34,800 on the directorate of the Östra Skaraborg Rescue Service. The DPA had received information that several fire stations in Östra Skaraborg operated surveillance cameras that filmed areas where firefighters were changing during an emergency, whereupon it initiated a review of the camera surveillance. The video surveillance was taking place around the clock, although the controller itself stated that video surveillance was only required in case of eme

### Private Individual: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2021-04-15 — https://overview.legal/posts/46750 — original: https://www.enforcementtracker.com/ETid-635*

The Spanish DPA (AEPD) has imposed a fine of EUR 3,000 on a private individual. The controller resides on the 1st floor of an apartment building, where he is the owner of apartments on the 2nd and 3rd floors. He regularly rents out these apartments to tourists. The controller had installed four video cameras on the three floors and in the entrance area of the building. He justified their operation with security concerns related to the rental to tourists. The owners' association had not granted p

### Laboratorio Octogón, S.L.: Non-compliance with general data processing principles

*Source: Spanish Data Protection Authority (aepd), 2021-03-23 — https://overview.legal/posts/46722 — original: https://www.enforcementtracker.com/ETid-607*

Usage of CCTV camera systems that were also monitoring public space (breach of principle of data minimization).

### Company: Insufficient legal basis for data processing

*Source: Croatian Data Protection Authority (azop), 2025-03-24 — https://overview.legal/posts/48718 — original: https://www.enforcementtracker.com/ETid-2603*

The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it accessed personal data – in particular license plate numbers and owner information – from the Croatian Ministry of the Interior's (MUP) vehicle registry without a valid legal basis. Access was gained via a web service that the company had secured the right to use in certain areas on the basis of a concession. However, t

## Recent developments

### Greek SA fines Clearview AI for EUR 20M

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/6252 — original: https://iapp.org/news/a/greek-dpa-imposes-20m-euro-fine-on-clearview-ai-for-unlawful-processing-of-personal-data#entry-1098*

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd.

*Source: IAPP, 2022-10-20 — https://overview.legal/posts/51829*

Een overzicht van de boete die aan IAPP is opgelegd: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

### ICO Publishes Draft Employee Monitoring Guidance for Consultation

*Source: Hunton Andrews Kurth, 2022-10-18 — https://overview.legal/posts/6255 — original: https://www.huntonprivacyblog.com/2022/10/18/uk-ico-publishes-draft-employee-monitoring-guidance-for-consultation/#entry-1081*

> On October 14, 2022, the Federal Trade Commission announced it is extending the deadline by one month to submit comments on its Advanced Notice of Proposed Rulemaking on commercial surveillance and lax data security practices.

### AEPD publishes GDPR Risk Assessment

*Source: AEPD, 2022-10-11 — https://overview.legal/posts/6259 — original: https://evalua-riesgo.aepd.es/index_en.html#entry-1032*

> GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the processing, to make an initial assessment of the intrinsic risk, including the need to perform a DPIA, and to estimate the residual risk if measures and safeguards are used to mitigate the specific risk factors.

### DeFine is a calculator for GDPR fines based on method of the EDPB

*Source: Kromann Reumert, 2022-02-01 — https://overview.legal/posts/6310 — original: https://www.khlaw.com/define#entry-14*

> DeFine is a translation into a calculator of part of the methodology proposed by the European Data Protection Board to calculate GDPR fines (see EDPB, Guidelines 04/2022 on the calculation of administrative fines under the GDPR, 12 May 2022, available online; it was subject to a public consultation until 27 June 2022).

## Literature

### Event-Driven Compliance: Reconciling Privacy Regulation with Real-Time Advertising Infrastructure

*Source: Journal of Computer Science and Technology Studies, 2025-11-26 — https://overview.legal/posts/53852 — original: https://doi.org/10.32996/jcsts.2025.7.12.20*

Programmatic advertising ecosystem functions based on distributed, event-driven frameworks that handle user data across enterprise limits in milliseconds, with basic contradictions with the present-day privacy laws such as GDPR, ePrivacy Directive, and CCPA/CPRA. The system of real-time bidding projects the identifiers of users and the cues of their behavior to many prospective advertisers, creating compliance risks that are multiplicative beyond jurisdictional lines. This manuscript formalizes

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/audit-logs · 2026-08-22
