← Home
PLEN

Data structures and data formats

Last updated: 15 September 2026

This page sets out which data sets you can download from Guardiso, the format each file comes in, and exactly what every column means. The page is public and requires no account, so that your procurement team, your lawyer and a future provider can check it before the agreement is concluded rather than at the point of leaving.

Maintaining this register is an obligation of a provider of a data processing service. It is required by Article 26(1)(b) of Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data.

We publish the same register in a machine-readable form, free of charge and without an account, at /api/formaty-danych.

1. Register of controls with implementation status

Where you download it fromAudit Package
FormatCSV w archiwum ZIP
File namecontrols.csv
Column in the fileType of valueWhat the column means
CodeTextThe identifier of the control in the standard, for example A.5.15.
TitleTextThe name of the control.
DomainTextThe domain the control belongs to, for example access control.
FrameworkTextThe standard the control comes from, for example ISO 27001.
StatusValue from a fixed listThe implementation status of the control in the organisation.
NotesTextThe organisation's own note about this control.
Last ReviewedDate and timeWhen the control was last reviewed.

2. List of policies and procedures

Where you download it fromAudit Package
FormatCSV w archiwum ZIP
File namepolicies.csv
Column in the fileType of valueWhat the column means
TitleTextThe title of the document.
StatusValue from a fixed listThe status of the document, for example draft or approved.
CategoryTextThe subject category of the document.
VersionNumberThe version number of the document.
Approved ByTextWho approved the document.
Approved AtDate and timeWhen the document was approved.
CreatedDate and timeWhen the document was created.
UpdatedDate and timeWhen the document was last changed.

3. Risk register

Where you download it fromAudit Package
FormatCSV w archiwum ZIP
File namerisks.csv
Column in the fileType of valueWhat the column means
TitleTextThe name of the risk.
Risk Level (residual)Value from a fixed listThe level of risk after the controls have been taken into account, calculated according to the methodology adopted by the organisation.
Risk Level (inherent)Value from a fixed listThe level of risk before the controls are taken into account.
StatusValue from a fixed listThe status of the treatment of the risk.
CategoryTextThe category of the risk.
LikelihoodNumberThe assessment of the likelihood of occurrence.
ImpactNumberThe assessment of the impact the risk would have.
CreatedDate and timeWhen the risk was entered in the register.
UpdatedDate and timeWhen the risk was last changed.

4. Index of the evidence register

Where you download it fromAudit Package
FormatCSV w archiwum ZIP
File nameevidence/index.csv
Column in the fileType of valueWhat the column means
TitleTextThe name of the evidence item.
TypeValue from a fixed listThe type of evidence, for example a screenshot or a document.
StatusValue from a fixed listThe status of the evidence item, for example collected or pending.
SourceTextWhere the evidence came from, for example which provider.
Collected AtDate and timeWhen the evidence was collected.
ExpiryDate and timeThe date until which the evidence remains valid.
File SizeNumberThe size of the attached file in bytes. A value of zero means that the evidence item has no file attached.

5. Register of data processing agreements collected by the customer

Where you download it fromGDPR compliance module
FormatCSV w archiwum ZIP
File namedpa-register.csv
Column in the fileType of valueWhat the column means
ProcessorTextThe name of the entity processing the data.
ContactTextThe contact person at the processor.
CountryTextThe country in which the data is processed.
Subject MatterTextThe subject matter of the processing, that is to say why the data is processed.
StatusValue from a fixed listThe status of the agreement, for example signed or being prepared.
CriticalityValue from a fixed listHow critical the entity is to the operation of the organisation.
Signed AtDate and timeWhen the agreement was signed.
Valid UntilDate and timeThe date until which the agreement is in force.
Annual ReviewDate and timeThe date of the next annual review.
ISO 27001Value from a fixed listWhether the processor holds an ISO 27001 certificate.
SOC 2Value from a fixed listWhether the processor holds a SOC 2 report.
Sub-processorsSeveral values in one fieldThe further processors used by that entity.
International TransferValue from a fixed listWhether the data leaves the European Economic Area.
SCC ModuleValue from a fixed listWhich module of the standard contractual clauses forms the basis for the transfer.
Document URLWeb addressThe address of the file containing the agreement. The file itself is in the same archive.

6. Cookie consent log

Where you download it fromGDPR compliance module
FormatCSV
File nameconsent-log-RRRR-MM-DD.csv
Column in the fileType of valueWhat the column means
idTextThe internal identifier of the log entry.
created_atDate and timeWhen the consent was given or withdrawn.
actionValue from a fixed listWhat the visitor did, for example accepted or rejected.
visitor_idTextThe identifier of the visitor assigned in the browser.
languageTextThe language in which the consent request was shown.
ip_anonymizedTextThe network address with the last part removed so that it does not identify a person.
page_urlWeb addressThe page on which the visitor answered the consent request.
choicesSeveral values in one fieldWhich categories of cookies the visitor agreed to.
user_agentTextThe description of the browser used by the visitor.

7. Security questionnaire with its answers

Where you download it fromQuestionnaires module
FormatCSV
File namequestionnaire.csv
Column in the fileType of valueWhat the column means
#NumberThe sequential number of the question in the questionnaire.
CategoryTextThe area the question concerns.
QuestionTextThe text of the question.
AnswerTextThe answer given by the organisation.
StatusValue from a fixed listThe status of the answer, for example pending or approved.
ConfidenceNumberA percentage showing how confident the assistant was in its proposal. An empty field means an answer written by a person.
SourcesSeveral values in one fieldThe organisation's documents on which the answer is based.

The register describes data sets that have named columns. Documents downloaded as PDF, DOCX and Markdown, and files you uploaded yourself, come in the form in which you uploaded them or in which they were created, so they have no columns to describe. The full list of what you can take with you is set out in the exit and data portability terms.

Exit and Data Portability Terms

If you need a description of the structure before you download the data, or you want to ask what a particular field means, write to kontakt@guardiso.com. We answer free of charge, including when the question comes from a new provider you have nominated.