For data protection officers and privacy teams
When the authority asks what you knew and when, show your records as they were written.
After a breach, the first questions are when you found out, what you decided and when you notified. Under the GDPR you must be able to demonstrate compliance, and a record that could have been written last week demonstrates little.
- When it is tested
- A data protection authority’s investigation after a breach or a complaint; a data subject’s claim; an audit of your records of processing.
- What you will be asked for
- That you can demonstrate compliance (GDPR, Article 5(2)); your records of processing activities (Article 30); every personal-data breach documented, with its facts, effects and the remedial action taken (Article 33(5)); data protection impact assessments (Article 35).
- What goes wrong today
- Breach registers and impact assessments live in spreadsheets and document tools that anyone with access can quietly update, and their dates are whatever the file says.
- What changes
- Each breach entry, assessment and change of consent is sealed when written. Corrections become new sealed versions beside the original. Nothing personal is sent: only a salted fingerprint.
Sealing shows that a record existed unchanged from a given moment; whether your records are enough is yours to judge. GDPR breach articles, with NIS2 · Sealed security logs
Try it in two minutes
- Choose a real file of your own: a breach register entry or an impact assessment. It is read in your browser and never uploaded.
- Seal it on Seal a file. A free sandbox key is issued on the page; only a salted fingerprint reaches the log.
- Make a copy, change one character in it, and check both against the receipt at Check. The copy fails; the original passes.
From your own systems it is one API call per record. Integrate · Other industries