Data protection and processing register
Processing activities
Data protection / processing register documents processing activities under GDPR Article 30. Record purpose, categories of data subjects and personal data, recipients, third-country transfer, retention, legal bases, responsible persons and processors. Link assets, vendors and technical and organisational measures.

An active activity requiring a data protection impact assessment needs a completed assessment and justification. Changes are versioned. Use versions as the referenced state in audits and exports.
TOMs
TOM management is in the same area. Catalogue entries describe a measure while the implementation status is maintained per processing activity. This makes the actual application of a measure traceable.
Export and maintenance
Before a processing-register export, complete controller, joint-controller, representative and data-protection-officer details in Settings. Review activities after new vendors, systems or transfers.