Start with the specific processing operation
The example assumes a fictional service subject to GDPR that reconciles investor entries. The business entity decides purpose, necessary data and recipients; the cloud supplier performs storage under documented instructions. Controller and processor analysis depends on actual decisions about purposes and means rather than only the contract’s commercial title. The inspected EDPB Guidelines 07/2020 are version 2.1. An organization may have different roles in different operations. If the supplier starts using data for its own purpose, that activity needs fresh analysis; always calling it a processor does not resolve the change. The PM gathers facts and coordinates privacy and legal owners without turning the technical diagram into an automatic legal conclusion.
Connect purpose to data, access and retention
In the worksheet, reconciling entries needs transaction identifier, amount, currency and time; no need has been demonstrated to store a full name in every debug log. Removing an unnecessary field reduces exposure but does not replace analysis of lawful basis or other applicable requirements. Encrypting data does not itself create a legitimate purpose either. Define who may view identifiable data, which versions reach testing, retention periods and handling of requests and mandatory preservation. An identifier replaced by a token may remain personal data when it can be linked back to a person; do not declare anonymization merely by changing the visible field. Record decisions per flow, including logs, exports and support, rather than limiting inventory to the primary database.
Make the contract usable by operations
Article 28 requires processor activity to be governed by a contract or other legal act with applicable contents. For the project, turn that into a matrix covering instructions, scope, security, rights assistance, incidents, audits and service termination. Engaging another processor needs prior specific or general written authorization; under general authorization, relevant changes must be communicated to permit objection. A commercial email saying the supplier uses partners does not replace that process. Check who can provide evidence and within what operational timeframe. The contract must also match the service actually used, including support and exports. Do not present a signature as proof that controls were configured or tested.
Assess recipients and access beyond the region
Selecting a European region informs storage location but does not alone resolve access by entities in other jurisdictions. EDPB Guidelines 05/2021 version 2.0 use three cumulative criteria: an exporter subject to GDPR for the processing, disclosure to another controller or processor, and an importer in a third country or international organization. In the worksheet, support is a separate entity in a third country with access to personal data; Chapter V therefore needs assessment. Do not conclude a transfer is permitted merely because traffic is encrypted or a generic contract is signed. By contrast, an employee of the same entity traveling abroad is not automatically another importing entity; security obligations and risks remain. Map the facts before selecting a mechanism or accepting the flow.
Prepare incidents and acceptance with clear responsibilities
A processor must notify the controller without undue delay upon awareness of a personal-data breach. For the controller, Article 33 provides for authority notification without undue delay and, where feasible, within 72 hours of awareness, subject to the article’s unlikely-risk exception. This is neither permission to wait 72 hours nor a universal deadline for every communication. Information may be supplied in phases when the article’s conditions are met, and assessment must be documented. The worksheet simulates no actual notification and decides no organization’s actual case. At acceptance, hand over flows, roles, tested controls, contacts, outstanding work and specialist decisions. Summary: region, encryption and contract contribute to analysis; responsibility depends on actual processing and evidence the project can present.
FICTIONAL WORKSHEET, NOT A LEGAL DECISION FOR AN ACTUAL SERVICE
Purpose: entry reconciliation
Assumed necessary data: transaction, amount, currency, time
Full name in debug: need not demonstrated
Entity A: determines purpose and essential means
Supplier B: storage under instructions
Support C: separate third-country entity with access
Confirm subprocessing authorization and Chapter V assessment
A employee traveling: distinguish from entity C
Incident: contact and escalation without undue delay
Contract and region do not demonstrate executed controls.An EU-hosted service may make data available to support staff of a separate third-country entity; the flow map needs to include that access.
Common pitfalls
Region as compliance; role defined only by title; token as anonymization; encryption as lawful basis; waiting72 hours before escalation.
Related topics: Change, inventory and operational evidence · Data, suppliers and responsibilities
Translate personal-data flows into responsibilities and project decisions without equating cloud region with compliance.
Reference: Guidelines07/2020 controller and processor · CCSP examination outline effective 2026-08-01; January2026 V2 PDF