This clause requires a company to keep detailed written records of what they do with personal data—what data they collect, who they share it with, how long they keep it, and what security measures they use. These records are like an audit trail that proves the company is following data protection law. If regulators investigate a data breach or complaint, they'll ask to see these records. Without this clause, the company could claim they don't know what happened to your data, and you'd have no way to prove otherwise.

💡
Key Recommendation

Ask the other party to commit to keeping records for at least as long as they hold your data, plus a reasonable period afterward (typically 3-5 years). Request that they agree to show you these records if you ask, or at minimum confirm they'll provide them to regulators if there's an investigation. If they refuse to keep records or won't let you verify them, that's a serious warning sign—consider whether you really want to do business with them.

Frequently Asked Questions

What does this clause mean in simple terms?

This clause requires a company to keep detailed written records of what they do with personal data—what data they collect, who they share it with, how long they keep it, and what security measures they use.

Why should I care about this clause?

These records are like an audit trail that proves the company is following data protection law.

What are my options?

If regulators investigate a data breach or complaint, they'll ask to see these records.

How does this affect small businesses?

Without this clause, the company could claim they don't know what happened to your data, and you'd have no way to prove otherwise.

✅ Action Checklist