Audit logs should prove an action, not duplicate personal data. Core fields are actor, time, action, object identifier and outcome.
Do not write national identifiers, health data or message bodies in clear text. Use masking or irreversible hashes where correlation is required.
Application users must not alter logs. Retention and deletion follow an authorized policy, while access attempts are audited too. Role-based reporting balances accountability and data minimization.
