What this Preview includes
- Preview requirement catalog
- Preliminary shared-control mappings
- Likely evidence examples
- Open questions for product feedback
GDPR
PreviewReview preliminary Article mappings, shared controls, likely evidence, and open questions. Active GDPR readiness programs are not yet available.
Shared work
Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A mapping is a planning aid, not proof that a requirement is satisfied.
Review preliminary control relationships across the 28 represented article groupings, including lawful bases, notices, rights handling, processing records, impact assessments, and transfers.
Explore which privacy and data-protection documents may support represented Article groupings without treating a draft or mapping as legal approval.
Explore where encryption, access control, resilience, and testing may relate to controls already used for SOC 2 or ISO 27001.
Identify which processor, agreement, location, and transfer questions require complete records and qualified privacy review.
The General Data Protection Regulation is the EU law governing personal data and can apply outside Europe in defined circumstances. Personal data is broad and may include names, emails, IP addresses, device identifiers, and other information relating to an identifiable person. Qualified legal guidance should determine a specific organization’s scope.
Operationally, GDPR requires a working program around lawful processing, individual rights, security, processors, transfers, and incident handling. Some notification and response duties carry short statutory deadlines depending on the circumstances. Qualified privacy guidance should determine the obligations for a specific organization and event.
For many B2B companies, privacy questions also appear during procurement. Customers may ask about data processing agreements, subprocessors, transfers, and security practices before they sign.
28 article groupings are represented in preliminary Preview mappings alongside possible shared-control relationships.
Minimization, purpose limits, consent, special categories
Privacy notices and clear communication
Access, erasure, portability, objection
Governance, privacy by design, processors, ROPA
Encryption, resilience, and regular testing
72 hour notification and impact assessments
Adequacy, SCCs, and transfer assessments
Quick answers about the product, frameworks, and getting started.
GDPR can apply to organizations outside the EU in defined circumstances, including some offerings to people in the EU or monitoring of their behavior. Applicability depends on the specific facts and should be reviewed with qualified counsel.
A Data Protection Officer is required in defined circumstances. The organization should document a fact-specific assessment with qualified privacy guidance rather than infer the answer from a Preview mapping.
Some organizations outside the EU may need a representative, subject to the regulation’s conditions and exceptions. Qualified privacy counsel should review the company’s exact processing and establishment facts.
Article 32 security may overlap with controls used for SOC 2 or ISO 27001. GDPR also includes privacy obligations such as lawful bases, rights workflows, records of processing, impact assessments, and transfer safeguards. Preview mappings help explore overlap without claiming legal equivalence or completeness.
Did not find what you were looking for? Talk to us.
Preview access
Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.