Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.5.33 Protection of Records

Control Objective

Records shall be protected from loss, destruction, falsification, unauthorised access and unauthorised release.

Policy Statement

anDREa enforces rigorous technical and administrative safeguards to protect organizational, compliance, and user records from unauthorized modifications, premature destruction, or data leaks.


Record Protection Framework

To guarantee the confidentiality, integrity, and availability of sensitive records, anDREa integrates the following lifecycle controls:

  • Inventory and Classification: All data processing operations and the records they generate are logged within the Record of Processing Activities (ROPA). The ROPA explicitly defines specific retention periods and tailored security requirements for each information system.
  • Access Governance: Access to systems containing sensitive records is restricted using strict role-based access controls and identity management baselines (see: A.05.15 - Access control).
  • Cryptographic Safeguards: To prevent unauthorized release or falsification, records are encrypted both at rest and in transit using industry-standard cryptographic algorithms (see: A.08.25 - Secure development life cycle).
  • Platform Security: All proprietary SaaS applications developed and maintained by anDREa are engineered, deployed, and supported under secure lifecycle practices (see: Clause 7 - Support).