- Analysis
- The exploration
- Why logs
- What is required
- By jurisdiction
- Locating the actor
- For framework builders
Why legislators ask for logs
Read in the order they were written, the sentences drafters actually wrote show one duty pointed at two different readers. The older instruments write the record for an investigator who arrives after something has gone wrong. The newer ones write it for a regulator watching a practice that has not gone wrong yet, and then for the person the system acted on.
This matters to anyone building the record, because the reader decides the fields. A record written for an investigator can be assembled afterwards from whatever survived. A record written for a person who wants to know what happened to them has to have been keeping the reasons at the time.
The record as evidence for later
The oldest duties in this survey are about a proceeding that has not started yet. A United States federal obstruction statute enacted in 2002 makes the offence turn on intent toward an investigation that comes afterwards, and the European rules on investment firms frame a telephone-recording duty the same way even while naming investor protection: the record's job is
to ensure that there is evidence to prove the term[s] of a transaction
Directive 2014/65/EU, Recital 57
once those terms are in dispute. The European trust-services regulation is more explicit still, requiring a qualified provider to record relevant information
"for the purpose of providing evidence in legal proceedings"
Regulation (EU) No 910/2014, Article 24(2)(h)
and the payment-card security standard names "forensic analysis of events", forensic being the word for evidence gathered after the fact.
The record as a standing account
European data-protection law changes what the record has to be ready for. Its accountability recital does not say the record exists so a later investigator can reconstruct a breach. It says the record should
"serve for monitoring those processing operations"
Regulation (EU) 2016/679, Recital 82
present tense, ongoing. And the accountability principle itself does not wait for a complaint: a controller must be able to demonstrate compliance at any time, which only works if the record already exists before anyone asks. That is the difference between a log you can produce and a log you are keeping.
The record as something the person can reach
The European Union's AI law shows the reader shifting once more, to the person a decision was made about. The Commission's own explanatory memorandum ties traceability to
"effective redress for affected persons"
Proposal for a Regulation laying down harmonised rules on artificial intelligence, explanatory memorandum, 2021
and the committee stage went further, proposing to write traceability into a general principle whose own name pairs it with redress. The enacted text keeps the regulator-facing purposes and adds a right the affected person holds against the deployer directly rather than through a regulator.
Two American instruments complete the same move in opposite directions. Colorado still routes the record through a regulator, but narrows the regulator's brief from market integrity to one specific harm against one specific class of person. New York City drops the regulator from its own bias-audit summary entirely: the record is posted on the employer's website, for the candidate about to be screened, before the tool is used. What began as a criminal obstruction statute protecting an investigation that had not happened yet became, seventeen years later, a notice the person about to be scored can read in advance.
The move is a change of emphasis, not an invention
This survey contains its own counter-evidence and it is worth stating plainly. Two of the oldest instruments here already pointed at the individual: the investment-firm recording duty is tied to investor protection in the interest of clients, and the trust-services record is evidence available to a party to a disputed transaction rather than only to a supervisory body. What changed with data-protection law and then AI law is which reader the duty is written for first, and how specific the thing owed to the individual became. Reading the shift as the individual arriving for the first time would contradict two rows of the same survey.
The same distinction shows up from a different direction, reading what an audit clause requires rather than what a drafter said. Both European data-protection law's binding-corporate-rules audit clause and the Council of Europe's AI framework convention code as continuous: a check with no interval, applied throughout the lifecycle, rather than one triggered by a complaint. Three independent readings land on the same line between a point-in-time record and a standing one.
What each purpose asks the record to hold
Eight purposes came out of the reading, and each one implies a different set of fields. This is the table the rest of the analysis is built on: the categories on the requirements page are these purposes seen from the record's side.
| What the record is for | What it therefore has to hold |
|---|---|
| Reconstructing an incident | when it happened, which system, what went in, what came out, and proof none of it changed since |
| Oversight and correction | when, which system, where a person was in the loop, and the basis for the outcome |
| Supervision by a regulator | which system, who was acting, who has looked at the record, and proof it is intact |
| Redress for an individual | who was affected, why the outcome, what came out, and whether a person was involved |
| Market surveillance | which system, what came out, and what disclosure was shown at the time |
| Demonstrating accountability | which system, the basis for the outcome, where the data came from, and proof it is intact |
| Monitoring bias and performance | what came out, who was affected, why, and where the data came from |
| Provenance and authenticity | which system, where the data came from, proof it is intact, and what was disclosed |
Three things a record can hold appear in no row above: the state of a person's consent or opt-out, the result of an age-assurance check, and the jurisdiction that was in play. Nothing read for this document tied them to a purpose a drafter stated. They belong to the question the fourth document asks, and a row inventing the link would be the defect this analysis exists to avoid.
Where the wording comes from
Every quotation on this page was read from the instrument's own published text, with the source and the date of reading recorded beside it in the research determination behind this page. Where a drafting body's own punctuation differs from ours, the quotation keeps theirs. The instruments themselves, with their status and their citations, are on the corpus pages. A standards draft published by the IETF is discussed in the last document rather than here, because it is not law.
- Analysis
- The exploration
- Why logs
- What is required
- By jurisdiction
- Locating the actor
- For framework builders
LexLint is a research index and a lint, not a lawyer. These pages describe published law as read on the date beside each figure, and set out what would have to be recorded to show it was followed. They do not apply that law to any product, project or organisation, and they are not a certification, an assurance or a compliance programme. Whether a duty reaches a particular system, and what to do about it, is a question for counsel.
The instruments behind every figure are on the LexLint software-law corpus, indexed by jurisdiction and dated on every row. The terms these pages share are defined in the LexLint glossary.