Data protection reports
Weitere Optionen
Under "Data Protection → Reports", it's possible to generate a number of reports for data protection.

To generate a report, first decide which type of report it should be. After choosing the desired type, add which data the report is to be generated for (e.g. processing activity or DPIA).
Formats:
Reports are available for download as PDF or DOCX files. To generate a report and download it, click on the pink button. Then, you can choose whether to download the report as PDF or DOCX.
Remembering report options:
Some of the report options can be found for various reports. For these, the selected options are remembered within the management system and for the individual user, and then also applied for other reports with that same option. For example, if the option "Table of contents" is selected, then it will already be selected when accessing any other report pages that use this option.
Licenses:
If no valid license for HITGuard is available, this will be displayed in the footer of the report! To change this, an expert or administrator has to request/upload a license under "Administration → Licensing".
The following reports are offered in the data protection section of HITGuard:
Processing registers
Under "Data protection → Reports → Processing registers", it's possible to choose from a number of reports for processing activities.

=Own processing activity
Here, you find the report for one or more processing activities your company is responsible for.
Pre-filtered in the system are those most recent versions of processing activities with the status "Editing completed". This restriction can be adjusted as needed or removed with the "clear filter" button.
If a DPIA exists for a processing activity, its results will be added to the report.
Generate report for own processing activities
To generate a report about your own processing activities, choose the desired processing activities here. To generate and download the report, click the pink button.

Joint responsibilities
Here, you find the report for one or more processing activities that have more than one responsible party assigned to them. (Joint responsibility must be activated in the processing activity.)
Pre-filtered in the system are those most recent versions of processing activities with the status "Editing completed". This restriction can be adjusted as needed or removed with the "clear filter" button.
Generate reports for joint responsibilities
To generate a report for joint responsibilities, choose the desired processing activities here. In the report options, it's possible to configure the processing activities to be downloaded as a ZIP file. To generate and download the report, click the pink button.

On behalf of others
Here, you find the report on processing activities carried out by your organization on behalf of others.
You can either generate a report containing processing activities performed by the selected organizational area, or you can generate a report for the external organization for which you perform the processing.
Note that the selection is limited to the last completed version of the respective processing activity.
Generate report for processing activities on behalf of others
Organizational units that carry out processings:
- Here, you can choose the organizational units that handle processing activities on behalf of others.
- The report contains all current information on the processing activities the selected organizational units handle on behalf of others.
External responsible parties on whose behalf processing is carried out:
- Here, you can choose an external responsible party your organization performs processing activities for.
- The report contains all information for all processing activities that are performed for this responsible party.

External processors
Here, you find the report for processing activities that other companies perform on behalf of your organization. Note that the selection is limited to the last completed version of the respective processing activity.
Generate report for external processors
Here, choose the desired external processor. The report contains all information on processing activities they perform for your organization. To generate and download the report, click the pink button.

DPIA
Under "Data protection → Reports → DPIA" you can choose whether to generate a report for the consultation of the authority or a general report on a data protection impact assessment.

Consultation of the authority
Here, you find the report for the data protection impact assessment that contains the relevant information for the consultation of the authority.
Generate consultation report for the authority
Here, first select the desired data protection impact assessment. If the DPIA contains multiple PA-responsibilities, also choose the desired PA-responsibility. To generate and download the report, click the pink button.
Report options | |
---|---|
Table of contents | This option determines whether a table of contents is included in the report. |
Attachments/evidences as zip-file | The report is downloaded in a zip-folder along with any attachments/evidences. |

General report
Here, you find the general report about the data protection impact assessments.
Generate data protection impact assessment report
Here, select the desired data protection impact assessment. The report contains all relevant information on the chosen DPIA. To generate and download the report, click the pink button.
Report options | |
---|---|
Table of contents | This option determines whether a table of contents is included in the report. |
Attachments/evidences as zip-file | The report is downloaded in a zip-folder along with any attachments/evidences. |

TOMs
Here, you find the report on the technical and organizational measures and controls.
By default, the report is generated for the general TOMs. The selection can also be limited to PA-responsibles (internal or external organizational units, e.g. clients) or to company or organizational registers. PA-responsibles, company registers, and organizational registers can be combined freely. Then, also the specific TOMs for those PAs are added into the report. Specific TOMs are added for the latest completed versions of a processing activity. Not yet completed PAs are not taken into account.
Generate TOMs report
To generate and download the report, click the pink button. A list for the selection of PAs is added for additional configuration if the option "Specific TOMs" is activated.
Berichtsoptionen | |
---|---|
Table of contents | This option determines whether a table of contents is included in the report. |
Specific TOMs | Determines whether the specific TOMs of a processing activity are included in the report in addition to the general TOMs. |
Only completed measures and active controls | Limits the selection of TOMs to effective tasks. |
Description | Determines whether the description or control measure for measures and controls are included in the report. |
Attachments/evidences as zip-file | The report is downloaded in a zip-folder along with any attachments/evidences. |

Data subject categories
Here, you find the report for data subject categories. This report can be used to issue information.
Caution: Only visible for experts in data protection!
Generate informative report
Here, first select the desired data subject category. The report contains all information (e.g. time limit for erasure) for all processing activities it is part of. Therefore, it can be used to issue information to inquirers. To generate and download the report, click the pink button.
