Data protection
The record of processing activities, the vendor DPA tracker and the breach log UK GDPR asks for — with two of the three doing something rather than merely recording it.
Records of processing
The ROPA is the register UK GDPR Article 30 requires: what personal data the company processes, on what lawful basis, where it is stored, who it is shared with, and how long it is kept. In most companies it is a document someone wrote once. Here it is rows in the same database as the data it describes.
Vendor DPAs
Every processor you use — mail, model providers, hosting, analytics — is a row with its review status and its data-processing agreement. The compliance dashboard reads the same rows, so "which vendors have we actually reviewed" is a query rather than a search through someone's inbox.
The breach log
Article 33 requires a record of every personal-data breach, reportable or not — including the ones you assessed and decided not to report, and the reasoning that got you there. Each one gets a row here.
Retention that runs
A retention entry that names a store and a day count is not documentation — it is configuration. An hourly sweep enforces it. That is the difference between a retention policy and a retention schedule: one describes an intention, the other deletes the data.
Erasure requests
Article 17 requests are carried out from the erasure panel, and the evidence that they were met is kept — what was erased, when, and by whom. Because the appliance is one database, an erasure reaches the contact, the mail threads, the deal notes and the event references together rather than leaving copies in a system nobody remembered to check.