GDPR and ENS in the Age of AI: How to Demonstrate Accountability with V-PROOF Cryptographic Evidence
GDPR and ENS in the Age of AI: Accountability Is No Longer Just a Statement—It’s Technical Evidence
The GDPR’s principle of accountability requires organizations to demonstrate compliance, not merely to declare it. With AI systems in the processing workflow, Articles 5, 25, 30, and 32 require a level of traceability that no policy document can provide on its own.
Key Points
- Article 5(2) of the GDPR establishes the principle of accountability: the data controller must be able to actively demonstrate compliance; simply stating it in a privacy policy is not sufficient.
- With AI systems in the processing workflow, Article 25 (privacy by design) requires evidence that privacy controls were implemented during the system's design phase, not as an after-the-fact fix.
- Article 30 requires an accurate and up-to-date Record of Processing Activities (RAT); V-PROOF turns it into a record with cryptographic evidence that can be verified by the AEPD.
- Article 33 establishes a 72-hour deadline for reporting personal data breaches to the AEPD. To demonstrate compliance with this deadline, the entity must maintain an tamper-proof technical record of the time the breach was discovered.
- The ENS (Royal Decree 311/2022) is mandatory for Spanish public administrations and their IT suppliers: the Medium and High categories require auditable security measures with technical traceability.
- The convergence of the GDPR and the EU AI Act creates a dual obligation for AI systems that process personal data: Article 22 of the GDPR (automated decision-making) and Article 14 of the EU AI Act (human oversight) both require the same verifiable record of human intervention.
Accountability: The Obligation That Most Organizations Still Fail to Meet
Since 2018, Article 5(2) of the GDPR has established what data protection experts call the principle of accountability or proactive responsibility: “The controller shall be responsible for compliance with the provisions of paragraph 1 and shall be able to demonstrate such compliance.” The italics are ours, and therein lies the problem that most organizations overlook.
The GDPR does not say, “Have a privacy policy.” It says, “Be able to demonstrate it.” That demonstration—whether during an inspection by the AEPD or before a court—requires technical evidence, records, logs, and verifiable proof that data protection controls existed, were functioning, and were correctly applied to the specific data processing operation being audited.
Accountability in Practice: What the AEPD Is Asking
During an AEPD inspection or disciplinary proceeding, the question is not “Do you have a privacy policy?” but rather “Can you demonstrate that the specific processing of personal data complied with the principles of Article 5 on the specific date of the incident?” A documented policy answers the first question. Only verifiable technical evidence answers the second.
This problem escalates exponentially when AI systems are integrated into the processing workflow. A machine learning model that processes personal data to generate recommendations, classify applicants, or detect behavioral anomalies introduces opacity into the processing: How does the organization demonstrate that automated processing complied with the principle of data minimization? That there was human oversight of decisions with significant impact? That the model did not introduce biases that violate Article 5(1)(a) regarding the lawfulness of processing? Without verifiable technical traceability, the answer to these questions is always the same: it cannot.
GDPR and ENS: Two Overlapping Frameworks in Key Sectors
For Spanish public sector organizations and their technology providers, the GDPR is not the only framework governing data protection and security. The National Security Framework (ENS, Royal Decree 311/2022) establishes the security principles and requirements for public administration information systems, and it also applies to private providers that offer services to public administrations.
The connection is clear: an ICT provider serving a Spanish public administration processes personal data under the GDPR and must comply with the ENS. The technical evidence generated by V-PROOF covers both frameworks simultaneously: the cryptographic log of implemented controls serves both to demonstrate accountability under the GDPR to the AEPD and to prove the implementation of ENS measures to the CCN-CERT.
- Art. 25Privacy by DesignEvidence that controls were in place prior to processing data
- Art. 30Record of ActivitiesThe record of processing activities, with each change dated
- Art. 33Data Breach: 72 HoursWhen it was detected and when the AEPD was notified
- Art. 5.2Demonstrating ComplianceTo the AEPD, with records that no one has been able to alter
For public systems and their providers, the ENS (RD 311/2022) also requires proof that security measures were actually implemented, not merely declared.
Articles that require technical evidence, and what that entails V-PROOF
ENS Medium and High Categories: From the Declaration of Conformity to Auditable Evidence
Royal Decree 311/2022 updates the ENS to align it with the current cyberthreat landscape and with European cybersecurity frameworks (NIS2, DORA). The Medium and High categories of the ENS require security measures that go beyond self-declaration: the CCN-CERT may require technical evidence of compliance during its audits.
ENS and the Digital Public Sector
Any private company that provides technology services to a Spanish public administration—ranging from a document management SaaS to an electronic processing platform—must comply with the ENS in the category corresponding to the system. With the accelerated digitization of public services and the incorporation of AI into administrative processes and citizen services, the number of affected providers has multiplied. V-PROOF generates the technical audit trail required by CCN-CERT to certify ENS compliance for systems in the Medium and High categories.
V-PROOF 's coverage under the GDPR and ENS
| Article | Obligation | Coverage | V-PROOF Module |
|---|---|---|---|
| GDPR, Principles, and Accountability | |||
| Art. 5(2)Accountability | Verifiable technical evidence of compliance with the principles of processing | ✓ Complete | V-Seal |
| Art.25 Privacy by Design | Record of when and how privacy controls were implemented during the system's design | ✓ Complete | V-Seal Core AI Orchestrator |
| Art.30RAT | Record of Processing Activities with a cryptographic chain of custody that is verifiable and retroactively verifiable | ✓ Complete | V-Seal |
| Art.32 Security of Processing | Evidence of the implementation of technical and organizational security measures, verifiable by the AEPD | ✓ Complete | V-Seal |
| Art.33 Notification of Security Breaches · 72 Hours | A verifiable time stamp indicating when the breach was discovered, confirming compliance with the 72-hour deadline | ✓ Complete | V-Seal |
| Art.35 of the DPIA | Data Protection Impact Assessment for High-Risk Processing Operations | ◐ Midterm | V-Seal |
| ENS, Royal Decree 311/2022 | |||
| ENS Cat.Media: Safety Measures | Technical audit trail of the security measures implemented, verifiable by CCN-CERT | ✓ Complete | V-Seal |
| ENS Cat.Advanced Traceability | Cryptographic evidence of security controls with full traceability throughout the system's lifecycle | ✓ Complete | V-Seal Git Integration |
| GDPR and EU AI Act Compliance for AI Systems That Process Personal Data | |||
| GDPR Art. 22+ EU AI Act Art. 14 | Verifiable human oversight in AI systems that have a significant impact on individuals | ✓ Complete | V-Proof AI AI Orchestrator |
| GDPR Art. 25+ EU AI Act Art. 10 | Privacy by Design in the Processing of Training Data for AI Models | ✓ Complete | AI Orchestrator |
◐ Partial = V-PROOF seals the results of the assessment; the design and implementation of the DPIA are the responsibility of the DPO or a specialized legal advisor.
GDPR + EU AI Act: The Dual Obligation Affecting Nearly All AI Systems
Almost any enterprise AI system processes personal data: credit scoring systems, customer behavior analytics platforms, AI-assisted recruitment tools, and intelligent video surveillance systems. All of these are subject to the GDPR and, if they are high-risk, to the General Data Protection Regulation for High-Risk AI ( EU AI Act). This overlap creates obligations that neither framework addresses on its own.
Article 22 of the GDPR establishes that data subjects have the right not to be subject to decisions based solely on automated processing that produce significant legal or similar effects on them. Article 14 of the EU AI Act requires that high-risk AI systems have verifiable human oversight. Both require the same thing from different frameworks: that a person has reviewed, understood, and approved the decision, and that this can be demonstrated.
A single piece of evidence for two frameworks
V-PROOF ’s “ V-Proof ” AI module records the human reviewer’s identity, their role, the AI-to-human ratio of the decision, and the applicable regulatory context for each decision logged in the system. This record simultaneously fulfills the requirement for human oversight under the EU AI Act (Art. 14) and the obligation to demonstrate human intervention under Art. 22 of the GDPR. The DPO and the AI governance team have a single source of evidence for two different regulators.
Why the Location of the Compliance Provider Matters Under the GDPR
The GDPR (Articles 44–49) restricts the transfer of personal data to third countries without equivalent safeguards. A U.S.-based AI Governance or GRC platform provider that manages a European organization’s GDPR compliance documentation may be transferring compliance data—including records of processing activities and evidence of data breaches—outside the EU without adequate safeguards.
Even more serious: The U.S. CLOUD Act may compel that provider to hand over those records to U.S. authorities—potentially including records of personal data breaches—before the organization has been able to notify the AEPD, which could violate Article 33 of the GDPR by compromising the confidentiality of the notification process.
V-PROOF has its registered office in Spain. GDPR compliance records, the RAT, evidence of accountability, and timestamps for breach detection remain under EU jurisdiction. There is no international data transfer, no CLOUD Act risk, and no incompatibility with Articles 44–49 of the GDPR.
V-PROOF in light of the GDPR and the ENS
Strengths, Regulatory Use Cases, and Scope Limitations
- RAT with cryptographic chain of custody: verifiable, retroactively verifiable by the AEPD—the difference between declaring compliance and being able to demonstrate it Art. 30 GDPR, RAT
- Timestamp blockchain record of the time a breach was discovered, evidence demonstrating compliance with the 72-hour deadline under Article 33 or proving that compliance was technically impossible Article 33 of the GDPR, Data Breach Notification
- Evidence of privacy by design: a record of when and how privacy controls were implemented during system development, not as a retroactive fix Art. 25 GDPR, Privacy by Design
- Verifiable human oversight in AI systems that process personal data: covers Article 22 of the GDPR and Article 14 of the EU AI Act with a single record GDPR Art. 22 + EU AI Act Art. 14
- ENS Audit Trail: Technical evidence of security measures in the Medium and High categories, verifiable by CCN-CERT ENS Medium/High Category, RD 311/2022
- Legal headquarters in Spain: GDPR and ENS compliance records under EU jurisdiction, with no risk of the CLOUD Act or incompatibility with Articles 44–49 of the GDPR Articles 44–49 of the GDPR + ENS sovereignty
- DPOs of organizations with AI systems that process personal data and need technical evidence of accountability for the AEPD Art. 5(2) GDPR, Accountability
- Companies that have experienced data breaches and need to document the exact time of discovery to demonstrate compliance with the 72-hour deadline Art. 33 GDPR, Data Breaches
- ICT providers for Spanish public administrations that must certify the ENS compliance of their systems in the Medium or High categories ENS, Royal Decree 311/2022
- Organizations with automated decision-making platforms (scoring, AI-powered recruitment, citizen services) subject to the dual obligation under GDPR Art. 22 + EU AI Act GDPR and EU AI Act convergence
- Development teams that implement systems involving personal data and need to demonstrate "privacy by design" during the development cycle, not after the fact Art. 25 GDPR, Privacy by Design
- The design of the privacy policy and legal texts: V-PROOF provides verifiable evidence that controls exist and have been implemented; it does not draft legal clauses or provide advice on the legal basis for data processing. Privacy Policy
- The Data Protection Impact Assessment (DPIA, Art. 35): V-PROOF formalizes the results of the DPIA and its approval, but the risk analysis and the design of measures are carried out by the DPO or specialized legal advisors. Art. 35 GDPR, DPIA
- Formal notification of data breaches to the AEPD (Art. 33) and to data subjects (Art. 34): V-PROOF records the time of discovery; formal notification is the responsibility of the data controller. Articles 33–34 of the GDPR, Notification
- Legal Analysis of International Data Transfers (Articles 44–49): V-PROOF does not handle standard contractual clauses or assess the adequacy of third countries. Such analysis requires specialized legal counsel. Articles 44–49 of the GDPR, Transfers
Can your organization demonstrate to the AEPD that its AI-based data processing complies with Article 5 of the GDPR?
V-PROOF offers a 48-hour strategic assessment that maps the GDPR and ENS requirements applicable to your systems, identifies gaps in technical evidence, and defines the integration needed to demonstrate accountability.
Request a Strategic GDPR/ENS AssessmentSources and Regulatory References
- Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR) · EUR-Lex CELEX:32016R0679
- Royal Decree 311/2022, dated May 3, regulating the National Security Framework, BOE-A-2022-7191
- AEPD, Guide to Risk Analysis in the Processing of Personal Data Using AI, 2024, aepd.es
- AEPD, Practical Guide to Risk Analysis for the Processing of Personal Data, 2021, aepd.es
- CCN-CERT, ENS Implementation Guide (CCN-STIC 800 Series) · ccn-cert.cni.es
- EDPB, Guidelines 05/2022 on the Use of Facial Recognition Technology in Law Enforcement, edpb.europa.eu
- Regulation (EU) 2024/1689 (EU AI Act) · GDPR Convergence Reference for AI Systems That Process Personal Data, EUR-Lex
