Whitepaper

Audit Trail and Access Control in DMS for Police Zones

4 August 2026
Audittrail en toegangscontrole in documentbeheer voor politiezones

The Belgian Police Information Management Act (WPI) governs how law enforcement agencies may register, process, archive and destroy information. The supervisory body COC monitors compliance. The law is not an abstract standard: it demands demonstrable, technical measures at document level. Who accessed which report, attachment or personnel file, when and what did they do with it? You must be able to prove it.

The WPI differs fundamentally from the GDPR. While GDPR allows flexible legal bases for processing, police data operates under a strict purpose-limitation principle. Logging is not optional: every access to a sensitive file must be traceable, including internal access. Standard office DMS platforms are rarely adequate for this purpose.

A document management system that complies with the WPI must at minimum support the following:

Role-based access control (RBAC) per function and per unit, so that an officer from zone A cannot access files from zone B

Full audit log per access, modification, export and print, with timestamp and user identity

Retention policies per document type, so that incident reports, attachments and HR files each follow their own retention schedule

Immutable storage (WORM technology) for documents with evidential value

Encryption at rest (AES-256) and in transit (TLS 1.3)

Controlled and documented destruction once retention periods expire

On-premise or private-cloud deployment for highly sensitive data, without dependency on external data centres outside Belgian jurisdiction

Each of these requirements is auditable by the COC. A DMS that does not support them natively shifts the burden of proof onto your IT department, handled manually and with risk of error.

iGuana iDM provides JWT-based authentication and Active Directory integration for granular access control. Permissions are set not only per user but per document type, classification label and organisational unit. Every interaction with a document is logged at API level: access, modification, export and deletion each generate an immutable record in the audit log.

Retention rules are configured per document class. When a retention period expires, the system triggers a destruction workflow requiring mandatory approval. The destruction itself is documented, including timestamp, responsible officer and affected files. iGuana iStore adds WORM storage for archive documents that must remain unalterable.

On-premise installation is available for police zones that do not want to host data outside their own infrastructure. Integration with existing GPI or ISLP environments is available via API.

Put these five questions to your current system. If the answer to any one of them is "no" or "manual", you face risk in a COC audit:

Can the system show per user which files were accessed in the last 90 days?

Are exports and prints logged with user identity and timestamp?

Is retention configured per document type and automatically enforceable?

Is destruction centrally documented and approved?

Are data encrypted both at rest and in transit?

If your current document management falls short on any of these points, contact us via our contact page to arrange a compliance review. For more on NIS2 requirements and the technical architecture of iGuana iDM v7, read our NIS2 article.

Ready for digital transformation?

With over 30 years of experience, we help leading organizations in healthcare, finance, and government with their digital transformation.