Solutions

GDPR compliance software

The GDPR module keeps the records a privacy program has to show: who the data subject is, what was consented, which processing exists, and what happened in a breach.

The records

The module includes a data-subject and consent registry, the record of processing activities, data-subject requests, retention policies, a data protection impact assessment, breach incidents, reports, and export. GDPR is also one of the frameworks in the compliance module, so the control evidence can sit beside these registers.

What it does not decide

The module does not replace a privacy lawyer or a supervisory authority. A personal-data breach recorded here is not the same object as a general security incident, which stays in the incident registry. The knowledge base has a GDPR overview for the regulation itself.

Questions

Data subjects, consents, processing activities, requests, retention, DPIA, and breach incidents, plus reports and export.

The registers are this module. GDPR can also be a framework instance in compliance, with mapped controls and evidence.

In the knowledge base article GDPR overview.

No. The module stores the breach record and can export reports. Notification is a decision and an action outside the record.

Related