The Strange Afterlife of a Regulation
Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.
