The evidence already assembles itself. This writes the document that goes on top, for whoever is about to read it.
Generating the package is a click today. What still costs a DPO two days is writing the covering note.
Active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — read at the moment you generate it.
Each section carries its own SHA-256, and a manifest hash is computed across all of them. Change one record afterwards and the hashes stop agreeing.
The manifest hash is written back into the append-only consent log, so the pack can be shown later to be the same pack — by anyone holding it.
Your password again, then a fifteen-minute window. An evidence pack is a concentrated view of your compliance posture and it should not be one click from a logged-in tab.
Who generated it, when, and which variant they took. The act of producing evidence becomes part of the evidence, which is the question an auditor asks second.
Not whether you have a process. What you did about one named person on one date, and how quickly.
When the Board sets a penalty it must consider the mitigation you undertook and how promptly. That is a story about your conduct, and it has to be told from records.
Rule 13 puts an independent data auditor in front of a Significant Data Fiduciary every twelve months. They arrive with questions and no time to read a log.
A pack assembled the week you are asked for it proves you can assemble a pack. One written as the work happened proves the work happened.
This is why the hashing matters rather than being cryptographic decoration. A record you could have edited before showing it is a claim. A record whose hash was written into an append-only log months earlier is evidence.
Nobody reads a manifest. The work that remains manual is the paragraph that makes the evidence underneath it navigable.
What the pack covers, what was handled, what was refused and on what grounds, what remains open. Written from the sections themselves, not from anyone’s recollection of the quarter.
Each claim points at the record behind it, so a reader can drop from the summary into the evidence at any line. A narrative you cannot check against the pack is a story, and nobody is buying a story.
The overdue item, the refusal with thin grounds, the vendor whose agreement lapsed mid-period. An auditor finds these anyway; meeting them in your own summary is a materially better position than being shown them.
Where the record is silent, the summary says so rather than writing around it. A pack that reads well while the evidence reads badly is the one outcome that would make all of this worthless.
The facts do not change and the hashes do not change. What a reader needs explained changes completely.
DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical
HELD
“Erasure request DSR-2026-000026 was partially fulfilled. Two of three systems were erased within the window. The clinical record was retained under the statutory minimum-retention period, and the refusal with grounds was issued to the data principal on the same day.”
DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical
HELD
“One deletion request this quarter could not be completed in full, because another law requires the clinical record to be kept. The patient was told why, in writing, the same day. No deadline was missed.”
No reference numbers, no section numbers, and the reassurance stated explicitly because that is the question actually being asked.DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical
HELD
“Erasure requests are fulfilled across every system holding the individual, with statutory retention handled as a documented partial refusal rather than silent non-deletion.”
Framed as capability rather than as an incident, because they are clearing you as a supplier, not investigating you.The facts do not change. What a reader needs explaining, and what they can be assumed to know, changes completely.
Wants provisions, dates and traceability. Assumes the law. Needs to get from a question to the underlying record in as few steps as possible.
Wants position and direction — better or worse than last quarter, and what it would cost if it went wrong. Does not want section numbers.
Wants to close a questionnaire and clear you as a supplier. Needs the same facts framed as assurance rather than as a filing.
Three variants exist today — the regulator pack, the board report and a handover pack — and each is currently written by hand from the same underlying sections. Generating all three from one dataset, with the same evidence behind each, is the part worth automating.
You are handing this to someone who may act on it. That signature has to belong to a person.
The summary is editable and the download still requires re-authentication. Nothing is sent anywhere on your behalf.
Three breached deadlines is three breached deadlines. The summary describes the record it was given, and the record is hashed.
Whoever approved the pack is named in the log alongside it, which is precisely the fact an auditor is establishing when they ask who signed it.
Seven hashed sections, a manifest anchored in a log nobody can edit, and re-authentication before download. Only the covering note is still written by hand.
The package itself, which is the substantial part. Seven sections — active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — each hashed with SHA-256, with the manifest hash written back into an append-only log so the pack can be shown later to be unaltered. Downloading it requires re-authentication and a fifteen-minute window. What you write by hand today is the covering summary.
No, and it is worth being careful with that number because it appears in DPDP material a lot. The only 48 hours in the DPDP framework is Rule 8(2)'s pre-erasure notice — the warning you must give a person before erasing their data on inactivity. It has nothing to do with audits. The timings that do exist are Rule 7's breach obligations, which are without delay to the Board and to affected people plus full particulars within 72 hours, and Rule 13's annual audit for a Significant Data Fiduciary.
Not at the time of writing, and anyone claiming their pack conforms to an official investigation format is describing something that does not exist. What you can do is structure evidence the way an investigation actually proceeds — by obligation, by person, by date — and make every claim traceable to a record. That is what the sections are organised around.
It does not, strictly. A DPO can write one, and they do — it costs a day or two per quarter and it is the least interesting day of the quarter. The reason to automate it is consistency rather than effort: a summary generated from the record covers the awkward parts, and one written by the person being assessed sometimes does not. The audience variants are the other reason — the same evidence has to become three quite different documents.
Please do not. Those logs contain hashed data principal identifiers and the full shape of your processing, and putting them into a general model is itself a processing decision you would have to justify — possibly in the very audit you are preparing for. Doing it inside the platform keeps the summary tied to hashed evidence that never leaves the boundary you have already assessed.
No date. Join the waitlist and we will tell you when the summary is one we would put in front of an auditor ourselves. The pack it sits on top of is live and does not depend on it.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Every action recorded as it happened, hashed, and anchored where it cannot be revised. That part is live now.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.