Gdpr Retention & Legal Audit · How-to guide

Execute GDPR retention actions

Follow this guide to run approved anonymisation or deletion actions after reviewing the dry-run results. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Compliance administrators and authorised property staffPermission: Administrator or Compliance Monitor Edit/DeleteModule v1.0.0
Jump to steps
Where to goGDPR Retention → Execute
Before you startRetention execution can be irreversible. Confirm governance approval, backups and legal holds before proceeding.

What you’ll accomplish

Run approved anonymisation or deletion actions after reviewing the dry-run results. The supplied Compliance Monitor module keeps live operational records, source documents, generated evidence and audit history connected through shared section keys, compliance types and linked-entity references.

How the workflow fits together

This feature sits inside the Compliance Monitor lifecycle. Source evidence is attached to a linked entity, reviewed by authorised staff and converted into an approved record only when the required fields and evidence are complete.

Follow these steps

  1. Verify the policy, dry-run output and legal holds.
  2. Select the table or all supported tables as intended.
  3. Set a controlled execution limit.
  4. Run Execute.
  5. Check processed, anonymised, deleted, skipped and error counts.

Fields and decisions to review

Linked recordVerify the exact property, tenant, supplier or governance entity.
StatusUse the lifecycle state shown by the module.
Dates and referencesVerify dates and identifiers against source evidence.
Audit evidenceCheck uploaded files, generated PDFs, notification logs and audit events.

Record, audit and evidence checks

Reopen the relevant workspace after saving. Confirm the intake ID or record reference, linked entity, status, dates, evidence list, generated PDF and any notification or audit entry. Where the module offers separate source evidence and system PDF buttons, review both rather than assuming they contain the same information.

How to confirm it worked

The resulting status, evidence, PDF, notification or audit event remains available through the relevant Compliance Monitor register. A successful browser message confirms that the request was handled; the register and audit history confirm what was actually retained.

Controls, checks and common mistakes

  • Verify the linked property, tenant, company or record ID before uploading, approving, sending, exporting or deleting.
  • Do not treat OCR, parsing, confidence or a success alert as a substitute for human evidence review.
  • Verify the saved record and audit history after every state-changing action.
  • Keep original uploaded evidence distinct from system-generated PDFs and notification evidence.
  • Use least privilege and avoid administrator-only actions unless the task genuinely requires them.
  • This module supports operational compliance records; it does not replace professional legal, regulatory or safety advice.
Compliance and data safetyUse the module as an operational evidence and workflow tool. Verify legal, safety, tax, licensing, data-protection and regulatory decisions with the organisation’s authorised professional process.
Browse connected topics:gdpr retentionlegal audit