The Authorities may impose fines if you do not review your GDPR documentation every three years!
The mandatory 3-year review is provided for by the Info Act (Act CXII. of 2011), according to which - unless other legislation specifies a different period - the controller shall review at least every three years from the start of processing, whether the processing of personal data is necessary for the purposes of the data management - points out Dr. Roland Zsidi, senior lawyer at ICT LEGAL, Dr. Termel Law Office.