.ai

GDPR

Preview

Explore how GDPR privacy and security work could connect to your existing program.

Review preliminary Article mappings, shared controls, likely evidence, and open questions. Active GDPR readiness programs are not yet available.

What this Preview includes

  • Preview requirement catalog
  • Preliminary shared-control mappings
  • Likely evidence examples
  • Open questions for product feedback

What this Preview does not provide

  • No active readiness score
  • No complete regulatory-coverage claim
  • No legal, audit, or certification conclusion
  • No production framework activation

Shared work

Explore where existing work may be reusable.

Preview mappings show possible relationships to controls already supporting SOC 2 or ISO 27001. A mapping is a planning aid, not proof that a requirement is satisfied.

Gap analysis with privacy built in

Review preliminary control relationships across the 28 represented article groupings, including lawful bases, notices, rights handling, processing records, impact assessments, and transfers.

Policies and the privacy notice

Explore which privacy and data-protection documents may support represented Article groupings without treating a draft or mapping as legal approval.

Article 32 security examples

Explore where encryption, access control, resilience, and testing may relate to controls already used for SOC 2 or ISO 27001.

Processor, DPA, and transfer questions

Identify which processor, agreement, location, and transfer questions require complete records and qualified privacy review.

What is GDPR?

The General Data Protection Regulation is the EU law governing personal data and can apply outside Europe in defined circumstances. Personal data is broad and may include names, emails, IP addresses, device identifiers, and other information relating to an identifiable person. Qualified legal guidance should determine a specific organization’s scope.

Operationally, GDPR requires a working program around lawful processing, individual rights, security, processors, transfers, and incident handling. Some notification and response duties carry short statutory deadlines depending on the circumstances. Qualified privacy guidance should determine the obligations for a specific organization and event.

For many B2B companies, privacy questions also appear during procurement. Customers may ask about data processing agreements, subprocessors, transfers, and security practices before they sign.

The articles a program answers for

28 article groupings are represented in preliminary Preview mappings alongside possible shared-control relationships.

Art. 5-9

Principles and lawful bases

Minimization, purpose limits, consent, special categories

Art. 12-14

Transparency

Privacy notices and clear communication

Art. 15-22

Data subject rights

Access, erasure, portability, objection

Art. 24-30

Accountability

Governance, privacy by design, processors, ROPA

Art. 32

Security of processing

Encryption, resilience, and regular testing

Art. 33-35

Breach and DPIA

72 hour notification and impact assessments

Art. 44-46

International transfers

Adequacy, SCCs, and transfer assessments

Questions the production workspace must answer

  • Which obligations apply to this organization?
  • Which mappings need qualified review?
  • What program records are still missing?
  • What evidence is current and approved?

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

GDPR basics

Does GDPR apply to US companies?

GDPR can apply to organizations outside the EU in defined circumstances, including some offerings to people in the EU or monitoring of their behavior. Applicability depends on the specific facts and should be reviewed with qualified counsel.

Do we need a Data Protection Officer?

A Data Protection Officer is required in defined circumstances. The organization should document a fact-specific assessment with qualified privacy guidance rather than infer the answer from a Preview mapping.

Do we need an EU representative?

Some organizations outside the EU may need a representative, subject to the regulation’s conditions and exceptions. Qualified privacy counsel should review the company’s exact processing and establishment facts.

How does GDPR overlap with SOC 2 and ISO 27001?

Article 32 security may overlap with controls used for SOC 2 or ISO 27001. GDPR also includes privacy obligations such as lawful bases, rights workflows, records of processing, impact assessments, and transfer safeguards. Preview mappings help explore overlap without claiming legal equivalence or completeness.

Did not find what you were looking for? Talk to us.

Preview access

Help shape the GDPR workspace.

Tell us what your team needs. Active readiness remains limited to SOC 2 and ISO 27001 today.

Do not include credentials, security findings, regulated data, or other sensitive information.