01 / Source and scope
Who acts, and what changes?
Principal and authority origin
Controller or processor agent. Controller instruction and lawful processing purpose.
Consequential action
Access, disclose or erase personal data.
02 / Action-time control
Make the requested effect testable.
GDPR duties include lawful basis, purpose limitation, minimization and data-subject rights. Constrain data access by task and purpose; ensure deletion or disclosure follows controller policy.
OriginController instruction and lawful processing purpose
RequestAccess, disclose or erase personal data
DecisionEvaluate and enforce before effect
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Purpose, instruction, data classes, recipient, decision and rights-request handling.
ProofGrid can evidence authorization decisions; the controller determines lawful basis and fulfills all GDPR duties.
Primary source