Apart from the privacy policy and retention policy are there any other documents we MUST do for GDPR? Do we HAVE to do a data audit or is it just recommended? Only started looking into this all yesterday