Regulatory register# Regulatory register ## Objective The **Regulatory** menu brings together GDPR, AIPD processing, data breaches, legal/contractual obligations and exemptions. ## Screen and fields Filter by register, type, status and manager. Common information is title, evidence, maturity and expiration; each type imposes its details, for example purpose, legal basis, conservation, risks, measures, source or notification decision. ## Exemptions and approval A waiver documents risk and compensation, has an expiration date, and must be approved by someone separate from the controller. The deletion respects the history and the tenant. ## Best practices Do not replace legal analysis with the registry. Attach the source, schedule reviews, and relate discrepancies to their actions when action is required. ## Types and expected information | Type | Main information | | --- | --- | | GDPR processing | purpose, legal basis, data, people, conservation and measures | | AIPD | context, necessity, risks,