Skip to main content
GDPR

Operationalise GDPR
with Confidence

The General Data Protection Regulation is the backbone of privacy in the EU. Basenorm centralises your records of processing, lawful bases, data subject rights, DPIAs, international transfers and breach notification workflows, so you can demonstrate accountability with living evidence rather than static documents.

Records, Lawful Bases and Accountability

Maintain a complete record of processing activities, document lawful bases and link each activity to assets, suppliers and controls in the Unified Control Library.

  • Article 30 records of processing for controllers and processors
  • Lawful basis, purpose and retention documentation
  • Data mapping across systems, suppliers and jurisdictions
  • Roles, responsibilities and DPO collaboration
  • Policies and procedures aligned with accountability principles

Article 32 Security Measures

GDPR

Pseudonymisation

Data masking active

Art. 32(1)(a)

Encryption at rest

AES-256 enabled

Art. 32(1)(a)

Access control

RBAC configured

Art. 32(1)(b)

Resilience measures

Backup in progress

Art. 32(1)(b)
3 of 4 controls implemented
75%

Records of Processing (RoPA)

Art. 30
ActivityBasisRetentionSubjects
Customer onboarding
Contract
7 years
Customers
Email marketing
Consent
Until withdrawn
Subscribers
Employee records
Legal obligation
10 years
Employees
Total processing activities24 records

DPIA, Data Subject Rights and Breach Management

Operate structured workflows for DPIAs, data subject requests and personal data breaches, with timelines, approvals and evidence captured end-to-end.

  • DPIA templates and approval workflows
  • Subject access, rectification, erasure and portability requests
  • 72-hour breach notification workflow to supervisory authorities
  • Communication to affected individuals where required
  • Lessons learned and control adjustments tracked over time

International Transfers and Third-Party Oversight

Manage data transfers outside the EEA, Standard Contractual Clauses, transfer impact assessments and oversight of processors and sub-processors.

  • Transfer mechanisms and SCC management
  • Transfer impact assessments and supplementary measures
  • Processor and sub-processor inventories
  • Controller-processor agreement lifecycle
  • Governance Graph linkage between data, systems and suppliers

72-Hour Breach Response

Detection0hr
Assessment12hr
Authority72hr
IndividualsASAP

Time Remaining

Authority notification deadline

24:15:32

hours left

Risk assessment completed • High risk confirmed

Ready to make GDPR operational?

Join organisations using Basenorm to manage records, DSARs, DPIAs, breaches and international transfers in one governance platform with continuous accountability evidence.

Frequently Asked Questions

Explore frequently asked questions about the GDPR and related compliance topics.