01
Controlled data subject request workflow
Capture access, erasure, portability and rectification requests in a controlled workflow. Accountability, deadline, review and completion remain traceable on the request.
GDPR
Connect RoPA, DPIAs, data-subject requests, legal bases and evidence with assets, vendors and accountable owners, in the same data model as ISMS, BCMS and AIMS.
One control, several standards
Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.
One control
Supplier & third-party due diligence
From control to policy
A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.
One control
Supplier & third-party due diligence
Management systems
Policies and procedures
01
Capture access, erasure, portability and rectification requests in a controlled workflow. Accountability, deadline, review and completion remain traceable on the request.
02
Data Protection Impact Assessments are mandatory for high-risk processing activities. KaitoSec guides teams through the structured DPIA process, captures prior consultation requirements, and links assessments to your processing register for ongoing review.
03
Connect processing activities with systems, purposes, legal bases, data categories and accountable owners. Changes in the linked context show which entries require professional review.
04
A processor risk identified in the DSMS feeds the ISMS supplier review. An ISO 27001 access control also evidences a GDPR security measure. The breach notification chain feeds NIS2 incident reporting. One asset register, one risk register, three audit regimes answered from the same workspace.
01
Map every processing activity to a data category, legal basis, retention period, and responsible team. KaitoSec keeps your Record of Processing Activities audit-ready and exportable for supervisory authority requests at any time.
02
Track all third-party data processors, their DPA status, and sub-processor chains. KaitoSec alerts you when DPAs are missing, expired, or no longer reflect current processing scope, a common source of regulatory findings.
03
Maintain a structured record of consent mechanisms across your products. KaitoSec integrates with your consent management platform to provide a unified view of consent status, withdrawal handling, and purpose limitation.
A Data Protection Impact Assessment is a structured process to identify and minimise privacy risks before starting a high-risk processing activity. GDPR requires a DPIA when processing is likely to result in a high risk to individuals, for example, large-scale profiling, systematic monitoring, or processing special categories of data. KaitoSec provides a guided DPIA template aligned with EDPB guidelines. Our DPIA knowledge article walks through the process step by step.
A controller determines the purposes and means of processing personal data. A processor handles data on behalf of a controller. Both have distinct obligations under GDPR, and the relationship must be formalised in a Data Processing Agreement. KaitoSec's vendor module tracks all processor relationships and DPA status. Our data protection knowledge hub covers RoPA, DPIAs and breach response in depth.
GDPR requires you to notify your supervisory authority within 72 hours of becoming aware of a personal data breach, and to notify affected individuals without undue delay if the breach is high risk. KaitoSec's incident module provides breach assessment workflows, severity scoring, and pre-filled notification templates to meet both deadlines.
A DPO is mandatory for public authorities, organisations that systematically monitor individuals at large scale, or organisations processing special category data at large scale. Even if not mandatory, a DPO or privacy lead is strongly recommended. In Germany, section 38 BDSG additionally requires a DPO once at least 20 people are regularly and permanently involved in automated processing of personal data. KaitoSec supports DPO workflows including DPIA consultation, training records, and authority liaison.
Both regulations require appropriate technical and organisational security measures to protect personal data and IT systems respectively. GDPR focuses on personal data protection, while NIS2 covers broader network and information security. KaitoSec maintains a shared control library so overlapping requirements are implemented once and evidenced across both frameworks.