Documentation — EU recitals
Documentation of the recitals, step by step. Every step has a control point, every claim an article, and the chain carries hashes so the work can be shown afterwards.
Step by step
- 1. Write down the assessment with article, role and date on every row. Can be shown: the list, with date and owner.
- 2. Link every claim to the node it rests on, not to a summary. Can be shown: the role choice with one sentence on why.
- 3. Store hash and reading date together with the text. Can be shown: the article rows with address, hash and reading date.
- 4. Mark what is your assessment and what is the source's wording. Can be shown: the gaps and what was decided about them.
- 5. Put the document where the reviewer finds it without asking. Can be shown: the next check date and who owns it.
Audit chain
- GDPR — 5: Principles relating to processing of personal data — e039f92a054c2009
- GDPR — 7: Conditions for consent — a964590806793e8f
- GDPR — 6: Lawfulness of processing — 193758ef71455742
- GDPR — 13: Information to be provided where personal data are collected from the data subject — 2e9c052bc1efd6d0
- GDPR — 22: Automated individual decision-making, including profiling — a6402833d82daea2
- GDPR — 32: Security of processing — 00970deabf8e51d9
- GDPR — 33: Notification of a personal data breach to the supervisory authority — 743b4711108e27e2
- GDPR — 35: Data protection impact assessment — e3f5d603a6997830
What forces a redo
- The node hash changes — the text behind the row is no longer the same.
- The reading date moves forward — the row has been re-read against the source.
- A timeline passes — the requirement starts to apply or tightens.
As data
- The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.
Roles
Articles
- GDPR — 5: Principles relating to processing of personal data
- GDPR — 7: Conditions for consent
- GDPR — 6: Lawfulness of processing
- GDPR — 13: Information to be provided where personal data are collected from the data subject
- GDPR — 22: Automated individual decision-making, including profiling
- GDPR — 32: Security of processing
- GDPR — 33: Notification of a personal data breach to the supervisory authority
- GDPR — 35: Data protection impact assessment
- GDPR — 46: Transfers subject to appropriate safeguards
- GDPR — 83: General conditions for imposing administrative fines
- AI Act — 6: Classification rules for high-risk AI systems
- AI Act — 5: Prohibited AI practices
- AI Act — 9: Risk management system
- AI Act — 17: Quality management system
- AI Act — 43: Conformity assessment
- AI Act — 49: Registration
- AI Act — 50: Transparency obligations for providers and deployers of certain AI systems
- AI Act — 71: EU database for high-risk AI systems listed in Annex III
- AI Act — 99: Penalties
- DORA — 17: ICT-related incident management process
- DORA — 28: General principles
Relations
Metadata
- Acts
- GDPR, AI Act, DORA
- Articles
- 21
- Reading date
- 2026-08-31
- Freshness
- 74/100
- Hash
- cde54fa45f61d87a
- Corpus version
- legal-2026-08-25
- Next check
- —
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.