GDPR and ENS in the Age of AI: How to Demonstrate Accountability with V-PROOF Cryptographic Evidence

GDPR and ENS in the Age of AI: How to Demonstrate Accountability with Cryptographic Evidence, V-PROOF Journal
Regulations · Data Protection

GDPR and ENS in the Age of AI: Accountability Is No Longer Just a Statement—It’s Technical Evidence

The GDPR’s principle of accountability requires organizations to demonstrate compliance, not merely to declare it. With AI systems in the processing workflow, Articles 5, 25, 30, and 32 require a level of traceability that no policy document can provide on its own.

Published: July 2026
Regulatory coverage: GDPR · Articles 5, 25, 30, 32, 33 · ENS RD 311/2022
Category: Regulation
GDPR · EU 2016/679 ENS · RD 311/2022 European supplier

Key Points

  • Article 5(2) of the GDPR establishes the principle of accountability: the data controller must be able to actively demonstrate compliance; simply stating it in a privacy policy is not sufficient.
  • With AI systems in the processing workflow, Article 25 (privacy by design) requires evidence that privacy controls were implemented during the system's design phase, not as an after-the-fact fix.
  • Article 30 requires an accurate and up-to-date Record of Processing Activities (RAT); V-PROOF turns it into a record with cryptographic evidence that can be verified by the AEPD.
  • Article 33 establishes a 72-hour deadline for reporting personal data breaches to the AEPD. To demonstrate compliance with this deadline, the entity must maintain an tamper-proof technical record of the time the breach was discovered.
  • The ENS (Royal Decree 311/2022) is mandatory for Spanish public administrations and their IT suppliers: the Medium and High categories require auditable security measures with technical traceability.
  • The convergence of the GDPR and the EU AI Act creates a dual obligation for AI systems that process personal data: Article 22 of the GDPR (automated decision-making) and Article 14 of the EU AI Act (human oversight) both require the same verifiable record of human intervention.

Accountability: The Obligation That Most Organizations Still Fail to Meet

Since 2018, Article 5(2) of the GDPR has established what data protection experts call the principle of accountability or proactive responsibility: “The controller shall be responsible for compliance with the provisions of paragraph 1 and shall be able to demonstrate such compliance.” The italics are ours, and therein lies the problem that most organizations overlook.

The GDPR does not say, “Have a privacy policy.” It says, “Be able to demonstrate it.” That demonstration—whether during an inspection by the AEPD or before a court—requires technical evidence, records, logs, and verifiable proof that data protection controls existed, were functioning, and were correctly applied to the specific data processing operation being audited.

Accountability in Practice: What the AEPD Is Asking

During an AEPD inspection or disciplinary proceeding, the question is not “Do you have a privacy policy?” but rather “Can you demonstrate that the specific processing of personal data complied with the principles of Article 5 on the specific date of the incident?” A documented policy answers the first question. Only verifiable technical evidence answers the second.

This problem escalates exponentially when AI systems are integrated into the processing workflow. A machine learning model that processes personal data to generate recommendations, classify applicants, or detect behavioral anomalies introduces opacity into the processing: How does the organization demonstrate that automated processing complied with the principle of data minimization? That there was human oversight of decisions with significant impact? That the model did not introduce biases that violate Article 5(1)(a) regarding the lawfulness of processing? Without verifiable technical traceability, the answer to these questions is always the same: it cannot.

GDPR and ENS: Two Overlapping Frameworks in Key Sectors

For Spanish public sector organizations and their technology providers, the GDPR is not the only framework governing data protection and security. The National Security Framework (ENS, Royal Decree 311/2022) establishes the security principles and requirements for public administration information systems, and it also applies to private providers that offer services to public administrations.

GDPR · EU Regulation 2016/679
Accountability of the Data Controller
Applicable to any organization that processes personal data of EU residents. Principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. All of these must be demonstrable, Art. 5(2).
ENS · Royal Decree 311/2022
Security of Public Information Systems
Mandatory for Spanish public administrations and their IT service providers. Three categories: Basic, Medium, and High, based on the impact of a security incident. The Medium and High categories require auditable security measures with technical traceability that can be verified by CCN-CERT.

The connection is clear: an ICT provider serving a Spanish public administration processes personal data under the GDPR and must comply with the ENS. The technical evidence generated by V-PROOF covers both frameworks simultaneously: the cryptographic log of implemented controls serves both to demonstrate accountability under the GDPR to the AEPD and to prove the implementation of ENS measures to the CCN-CERT.

Proactive Responsibility · GDPRIt’s not enough to simply comply—you have to be able to prove it
  1. Art. 25Privacy by DesignEvidence that controls were in place prior to processing data
  2. Art. 30Record of ActivitiesThe record of processing activities, with each change dated
  3. Art. 33Data Breach: 72 HoursWhen it was detected and when the AEPD was notified
  4. Art. 5.2Demonstrating ComplianceTo the AEPD, with records that no one has been able to alter

For public systems and their providers, the ENS (RD 311/2022) also requires proof that security measures were actually implemented, not merely declared.

Articles that require technical evidence, and what that entails V-PROOF

Art. 5(2) GDPR, Accountability
The data controller must be able to demonstrate compliance with the principles of data processing
The principle of accountability runs throughout the GDPR: every decision regarding data processing—what data is collected, for what purpose, for how long, and with what security measures—must be demonstrable to the regulator. “You can demonstrate it” means technical evidence, not a statement of intent.
Evidence V-PROOF V-Seal Core cryptographically seals the processing decisions recorded in the workflow: the implementation of a new data category, a change in the purpose of processing, and the application of a security measure. The timestamp blockchain creates a verifiable history of compliance decisions that can be defended before the AEPD in any proceeding.
Art. 25 GDPR, Privacy by Design
Evidence that privacy controls were implemented during the system's design phase
Privacy by design and by default requires that privacy controls not be added as an afterthought, but rather be implemented during the system’s design phase. In the age of AI, this means that the principles of data minimization and purpose limitation must be embedded in the model’s architecture, and this must be demonstrable.
V-PROOF Evidence V-PROOF records which privacy controls were implemented in the processing system, when they were implemented (during design vs. post-launch), and who approved them. For AI systems, the AI Orchestrator module records that the principles of data minimization and purpose limitation were applied during training and deployment.
Art. 30 GDPR, Activity Log
RAT with verifiable cryptographic evidence: the log that the AEPD can audit
The Record of Processing Activities (RPA) is the documentary backbone of GDPR compliance. But an RPA in a Word document or spreadsheet has a fundamental problem: it can be modified retroactively. When the AEPD audits it in the context of an incident, the organization cannot guarantee that the record reflects what was actually happening on the date of the incident.
V-PROOF Evidence V-PROOF turns the RAT into a log with cryptographic chain of custody: each entry in the activity log receives a timestamp on the blockchain. If the AEPD audits a data processing operation that occurred 18 months ago, the entity can demonstrate exactly what the RAT contained on that date and that it has not been modified since then.
Art. 32–33 GDPR, Security and Data Breaches
Verifiable security measures and timestamp for breach detection
Article 32 requires appropriate technical and organizational measures to ensure the security of processing. Article 33 establishes a 72-hour deadline for reporting personal data breaches to the AEPD, starting from the time the controller “becomes aware” of the incident. That phrase, “becomes aware,” is the point of contention in most penalty proceedings involving data breaches.
Evidence V-PROOF V-Seal Core records the implementation of each security measure under Article 32 using timestamp blockchain. In the event of a breach, the verifiable record of the time of discovery (when the team gained technical knowledge of the incident) serves as evidence demonstrating compliance with the 72-hour deadline under Article 33 before the AEPD, or proving that it would have been impossible to have known about it earlier.

ENS Medium and High Categories: From the Declaration of Conformity to Auditable Evidence

Royal Decree 311/2022 updates the ENS to align it with the current cyberthreat landscape and with European cybersecurity frameworks (NIS2, DORA). The Medium and High categories of the ENS require security measures that go beyond self-declaration: the CCN-CERT may require technical evidence of compliance during its audits.

ENS and the Digital Public Sector

Any private company that provides technology services to a Spanish public administration—ranging from a document management SaaS to an electronic processing platform—must comply with the ENS in the category corresponding to the system. With the accelerated digitization of public services and the incorporation of AI into administrative processes and citizen services, the number of affected providers has multiplied. V-PROOF generates the technical audit trail required by CCN-CERT to certify ENS compliance for systems in the Medium and High categories.

V-PROOF 's coverage under the GDPR and ENS

Article Obligation Coverage V-PROOF Module
GDPR, Principles, and Accountability
Art. 5(2)Accountability Verifiable technical evidence of compliance with the principles of processing ✓ Complete V-Seal
Art.25 Privacy by Design Record of when and how privacy controls were implemented during the system's design ✓ Complete V-Seal Core AI Orchestrator
Art.30RAT Record of Processing Activities with a cryptographic chain of custody that is verifiable and retroactively verifiable ✓ Complete V-Seal
Art.32 Security of Processing Evidence of the implementation of technical and organizational security measures, verifiable by the AEPD ✓ Complete V-Seal
Art.33 Notification of Security Breaches · 72 Hours A verifiable time stamp indicating when the breach was discovered, confirming compliance with the 72-hour deadline ✓ Complete V-Seal
Art.35 of the DPIA Data Protection Impact Assessment for High-Risk Processing Operations ◐ Midterm V-Seal
ENS, Royal Decree 311/2022
ENS Cat.Media: Safety Measures Technical audit trail of the security measures implemented, verifiable by CCN-CERT ✓ Complete V-Seal
ENS Cat.Advanced Traceability Cryptographic evidence of security controls with full traceability throughout the system's lifecycle ✓ Complete V-Seal Git Integration
GDPR and EU AI Act Compliance for AI Systems That Process Personal Data
GDPR Art. 22+ EU AI Act Art. 14 Verifiable human oversight in AI systems that have a significant impact on individuals ✓ Complete V-Proof AI AI Orchestrator
GDPR Art. 25+ EU AI Act Art. 10 Privacy by Design in the Processing of Training Data for AI Models ✓ Complete AI Orchestrator

◐ Partial = V-PROOF seals the results of the assessment; the design and implementation of the DPIA are the responsibility of the DPO or a specialized legal advisor.

GDPR + EU AI Act: The Dual Obligation Affecting Nearly All AI Systems

Almost any enterprise AI system processes personal data: credit scoring systems, customer behavior analytics platforms, AI-assisted recruitment tools, and intelligent video surveillance systems. All of these are subject to the GDPR and, if they are high-risk, to the General Data Protection Regulation for High-Risk AI ( EU AI Act). This overlap creates obligations that neither framework addresses on its own.

Article 22 of the GDPR establishes that data subjects have the right not to be subject to decisions based solely on automated processing that produce significant legal or similar effects on them. Article 14 of the EU AI Act requires that high-risk AI systems have verifiable human oversight. Both require the same thing from different frameworks: that a person has reviewed, understood, and approved the decision, and that this can be demonstrated.

A single piece of evidence for two frameworks

V-PROOF ’s “ V-Proof ” AI module records the human reviewer’s identity, their role, the AI-to-human ratio of the decision, and the applicable regulatory context for each decision logged in the system. This record simultaneously fulfills the requirement for human oversight under the EU AI Act (Art. 14) and the obligation to demonstrate human intervention under Art. 22 of the GDPR. The DPO and the AI governance team have a single source of evidence for two different regulators.

Data Sovereignty · GDPR / ENS Relevance

Why the Location of the Compliance Provider Matters Under the GDPR

The GDPR (Articles 44–49) restricts the transfer of personal data to third countries without equivalent safeguards. A U.S.-based AI Governance or GRC platform provider that manages a European organization’s GDPR compliance documentation may be transferring compliance data—including records of processing activities and evidence of data breaches—outside the EU without adequate safeguards.

Even more serious: The U.S. CLOUD Act may compel that provider to hand over those records to U.S. authorities—potentially including records of personal data breaches—before the organization has been able to notify the AEPD, which could violate Article 33 of the GDPR by compromising the confidentiality of the notification process.

V-PROOF has its registered office in Spain. GDPR compliance records, the RAT, evidence of accountability, and timestamps for breach detection remain under EU jurisdiction. There is no international data transfer, no CLOUD Act risk, and no incompatibility with Articles 44–49 of the GDPR.

For the public sector under the ENS, this point is particularly relevant: the ENS requires that public administrations’ information systems and their data remain under Spanish sovereignty. An ENS evidence management provider based in the U.S. is incompatible with this requirement.
Strategic Analysis

V-PROOF in light of the GDPR and the ENS

Strengths, Regulatory Use Cases, and Scope Limitations

F
Strengths · What V-PROOF Brings to the GDPR and ENS
  • RAT with cryptographic chain of custody: verifiable, retroactively verifiable by the AEPD—the difference between declaring compliance and being able to demonstrate it Art. 30 GDPR, RAT
  • Timestamp blockchain record of the time a breach was discovered, evidence demonstrating compliance with the 72-hour deadline under Article 33 or proving that compliance was technically impossible Article 33 of the GDPR, Data Breach Notification
  • Evidence of privacy by design: a record of when and how privacy controls were implemented during system development, not as a retroactive fix Art. 25 GDPR, Privacy by Design
  • Verifiable human oversight in AI systems that process personal data: covers Article 22 of the GDPR and Article 14 of the EU AI Act with a single record GDPR Art. 22 + EU AI Act Art. 14
  • ENS Audit Trail: Technical evidence of security measures in the Medium and High categories, verifiable by CCN-CERT ENS Medium/High Category, RD 311/2022
  • Legal headquarters in Spain: GDPR and ENS compliance records under EU jurisdiction, with no risk of the CLOUD Act or incompatibility with Articles 44–49 of the GDPR Articles 44–49 of the GDPR + ENS sovereignty
↗
Where It Applies · Regulatory Use Cases
  • DPOs of organizations with AI systems that process personal data and need technical evidence of accountability for the AEPD Art. 5(2) GDPR, Accountability
  • Companies that have experienced data breaches and need to document the exact time of discovery to demonstrate compliance with the 72-hour deadline Art. 33 GDPR, Data Breaches
  • ICT providers for Spanish public administrations that must certify the ENS compliance of their systems in the Medium or High categories ENS, Royal Decree 311/2022
  • Organizations with automated decision-making platforms (scoring, AI-powered recruitment, citizen services) subject to the dual obligation under GDPR Art. 22 + EU AI Act GDPR and EU AI Act convergence
  • Development teams that implement systems involving personal data and need to demonstrate "privacy by design" during the development cycle, not after the fact Art. 25 GDPR, Privacy by Design
⊘
Out of scope · Client's responsibility
  • The design of the privacy policy and legal texts: V-PROOF provides verifiable evidence that controls exist and have been implemented; it does not draft legal clauses or provide advice on the legal basis for data processing. Privacy Policy
  • The Data Protection Impact Assessment (DPIA, Art. 35): V-PROOF formalizes the results of the DPIA and its approval, but the risk analysis and the design of measures are carried out by the DPO or specialized legal advisors. Art. 35 GDPR, DPIA
  • Formal notification of data breaches to the AEPD (Art. 33) and to data subjects (Art. 34): V-PROOF records the time of discovery; formal notification is the responsibility of the data controller. Articles 33–34 of the GDPR, Notification
  • Legal Analysis of International Data Transfers (Articles 44–49): V-PROOF does not handle standard contractual clauses or assess the adequacy of third countries. Such analysis requires specialized legal counsel. Articles 44–49 of the GDPR, Transfers
GDPR / ENS Assessment

Can your organization demonstrate to the AEPD that its AI-based data processing complies with Article 5 of the GDPR?

V-PROOF offers a 48-hour strategic assessment that maps the GDPR and ENS requirements applicable to your systems, identifies gaps in technical evidence, and defines the integration needed to demonstrate accountability.

Request a Strategic GDPR/ENS Assessment

Sources and Regulatory References

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR) · EUR-Lex CELEX:32016R0679
  2. Royal Decree 311/2022, dated May 3, regulating the National Security Framework, BOE-A-2022-7191
  3. AEPD, Guide to Risk Analysis in the Processing of Personal Data Using AI, 2024, aepd.es
  4. AEPD, Practical Guide to Risk Analysis for the Processing of Personal Data, 2021, aepd.es
  5. CCN-CERT, ENS Implementation Guide (CCN-STIC 800 Series) · ccn-cert.cni.es
  6. EDPB, Guidelines 05/2022 on the Use of Facial Recognition Technology in Law Enforcement, edpb.europa.eu
  7. Regulation (EU) 2024/1689 (EU AI Act) · GDPR Convergence Reference for AI Systems That Process Personal Data, EUR-Lex
Previous
Previous

How V-PROOF Helps with DORA Compliance in the Financial Sector

Next
Next

NIS2 in Spain: What Directive 2022/2555 Requires and How to Demonstrate Compliance with V-PROOF