Skip to content

GDPR

Make data protection decisions traceable.

Connect RoPA, DPIAs, data-subject requests, legal bases and evidence with assets, vendors and accountable owners, in the same data model as ISMS, BCMS and AIMS.

Breach notification window
72h
Data subject request deadline
1 month
Maximum fine of global turnover
4%

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • GDPRRequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • BSI IT-GrundschutzRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

Controlled data subject request workflow

Capture access, erasure, portability and rectification requests in a controlled workflow. Accountability, deadline, review and completion remain traceable on the request.

02

Guided DPIA

Data Protection Impact Assessments are mandatory for high-risk processing activities. KaitoSec guides teams through the structured DPIA process, captures prior consultation requirements, and links assessments to your processing register for ongoing review.

03

A RoPA linked to your actual systems

Connect processing activities with systems, purposes, legal bases, data categories and accountable owners. Changes in the linked context show which entries require professional review.

04

GDPR on one model with ISO 27001 and NIS2

A processor risk identified in the DSMS feeds the ISMS supplier review. An ISO 27001 access control also evidences a GDPR security measure. The breach notification chain feeds NIS2 incident reporting. One asset register, one risk register, three audit regimes answered from the same workspace.

The workflow

01

Records of Processing Activities (RoPA)

Map every processing activity to a data category, legal basis, retention period, and responsible team. KaitoSec keeps your Record of Processing Activities audit-ready and exportable for supervisory authority requests at any time.

02

Vendor Data Processing Agreements

Track all third-party data processors, their DPA status, and sub-processor chains. KaitoSec alerts you when DPAs are missing, expired, or no longer reflect current processing scope, a common source of regulatory findings.

03

Consent & Cookie Management

Maintain a structured record of consent mechanisms across your products. KaitoSec integrates with your consent management platform to provide a unified view of consent status, withdrawal handling, and purpose limitation.

FAQ

What is a DPIA and when is it required?

A Data Protection Impact Assessment is a structured process to identify and minimise privacy risks before starting a high-risk processing activity. GDPR requires a DPIA when processing is likely to result in a high risk to individuals, for example, large-scale profiling, systematic monitoring, or processing special categories of data. KaitoSec provides a guided DPIA template aligned with EDPB guidelines. Our DPIA knowledge article walks through the process step by step.

What is the difference between a data controller and a data processor under GDPR?

A controller determines the purposes and means of processing personal data. A processor handles data on behalf of a controller. Both have distinct obligations under GDPR, and the relationship must be formalised in a Data Processing Agreement. KaitoSec's vendor module tracks all processor relationships and DPA status. Our data protection knowledge hub covers RoPA, DPIAs and breach response in depth.

How do we handle a data breach under GDPR?

GDPR requires you to notify your supervisory authority within 72 hours of becoming aware of a personal data breach, and to notify affected individuals without undue delay if the breach is high risk. KaitoSec's incident module provides breach assessment workflows, severity scoring, and pre-filled notification templates to meet both deadlines.

Do we need a Data Protection Officer?

A DPO is mandatory for public authorities, organisations that systematically monitor individuals at large scale, or organisations processing special category data at large scale. Even if not mandatory, a DPO or privacy lead is strongly recommended. In Germany, section 38 BDSG additionally requires a DPO once at least 20 people are regularly and permanently involved in automated processing of personal data. KaitoSec supports DPO workflows including DPIA consultation, training records, and authority liaison.

How does GDPR interact with NIS2 for security requirements?

Both regulations require appropriate technical and organisational security measures to protect personal data and IT systems respectively. GDPR focuses on personal data protection, while NIS2 covers broader network and information security. KaitoSec maintains a shared control library so overlapping requirements are implemented once and evidenced across both frameworks.

Related frameworks