Compyl
Framework · GDPREU · EEA personal data

GDPR you operate every day, not just publish.

GDPR lives in operations: knowing where personal data sits, answering data subject requests on deadline, keeping Records of Processing current, and proving a lawful basis for everything. Compyl’s GDPR compliance software runs it continuously, data mapping, DSAR and DPIA workflows, and breach-ready evidence.

7 data principles125+ integrationsContinuous data mapping
GDPR · programme readiness2 DSARs open · 0 breaches
91%ready
Processing activities with a lawful basis58 / 61
Article 32 security evidence93%
Evidence Health92
Art 6 Lawful basisArt 30 RoPAArt 15–22 DSARs · 1 due in 4 daysArt 35 DPIAsArt 32/33 Security
DSAR #2041 · access requestData located across 6 systems via the data map · response drafted · due in 4 days
Due soon
RoPA · marketing analyticsNew Snowflake flow detected and added · lawful basis: legitimate interests
Updated
Breach clock · 72-hour workflow armed · no open incidentsRegulator-ready
The problem

You can’t protect, or prove, data you can’t find

GDPR turns on operational reality: where personal data lives, who can access it, and how fast you respond. When that drifts from your paperwork, the regulator and the DSAR clock find it first.

Data maps go out of date

New tools and integrations move personal data constantly. A Record of Processing built once is wrong within a quarter, and wrong is exactly what a regulator audits.

DSARs arrive on a clock

A data subject access request gives you one month. Without knowing where their data lives, every request becomes a manual fire drill across teams.

The 72-hour breach window is brutal

From detection to regulator notification you have 72 hours. Scattered evidence and unclear scope make that deadline almost impossible to hit.

How it works

One continuous loop, from connected systems to audit-ready

Compyl runs your GDPR program as an always-on cycle, data mapping, lawful basis, and evidence stay in sync automatically.

01

Connect

Integrate cloud, identity, code, endpoint, and HR systems.

02

Collect evidence

Pull audit evidence automatically, in real time.

03

Map to obligations

Link every artifact to its GDPR article and lawful basis.

04

Monitor

Watch controls continuously and flag drift early.

05

Stay audit-ready

Hand auditors a current evidence pack on demand.

Core obligations

The operational heart of GDPR

GDPR is built on seven principles, but compliance is proven through operational duties. Compyl maps evidence to each one.

Lawful basis

Foundation
Art 6

Establish and record a lawful basis for every processing activity, and manage consent where it applies.

Six lawful bases · Art 7 consent

Records of Processing

Record
Art 30

Maintain a current RoPA describing what data you process, why, and where it flows.

Continuous · data map

DSARs

One month
Art 15–22

Answer access, erasure, and portability requests (DSARs) within one month.

DSAR clock · one month

DPIAs

Pre-processing
Art 35

Run Data Protection Impact Assessments for high-risk processing before it begins.

High-risk processing

Security & breaches

72 hours
Art 32 / 33

Implement appropriate security and notify regulators of a breach within 72 hours.

Breach clock · 72 hours
Automated evidence

Stop assembling GDPR evidence by hand

GDPR proof isn’t a single report, it’s a current data map, a lawful basis for every processing activity, and Article 32 security evidence. Compyl collects it continuously from the systems you already run.

  • Pull evidence automatically from cloud, identity, code, and endpoint tools
  • Every artifact mapped to the GDPR article it supports
  • No more screenshots, spreadsheets, or last-minute requests
  • Export a complete, auditor-ready evidence pack on demand
Data map & evidence · collected automatically61 processing activities · live
Salesforce · customer recordsLawful basis: contract · EU data · mapped to Art 6, Art 30
Synced 4m
HubSpot · marketing consentLawful basis: consent · consent log retained · Art 7
Synced 9m
AWS · encryption, access logs318 artifacts · mapped to Art 32 security of processing
Synced 2m
Snowflake · analytics warehouseNew personal-data flow detected · added to RoPA
New flow
Every artifact mapped to the GDPR article it supportsRegulator-ready pack
Evidence Health · New in 26.2

Know your evidence is audit-ready, automatically

Collecting evidence is only half the battle; stale or incomplete proof is where audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces before a regulator or a 72-hour clock, not during.

  • Every artifact scored on relevance, freshness, and completeness
  • An AI summary spells out exactly what’s missing and why
  • Re-scores automatically whenever the underlying evidence changes
  • Gaps surface with time to fix, not during an investigation
Evidence HealthNew in 26.2 · re-scores on change
ArtifactDPIA · customer analytics · Art 35
Score56 / 100
RelevanceHigh
FreshnessStale · 15 months
AI summary · what’s missingThe DPIA predates two changes to the processing: a new sub-processor (Snowflake) and profiling for churn scoring. Neither risk is assessed. Re-run the DPIA for the updated activity before the next data-flow change.
Create taskOpen DPIA
Gaps surface before a regulator or a 72-hour clock, not duringScored continuously
Continuous monitoring

Catch drift before the regulator does

Regulators and DSARs don’t wait for your annual review. Compyl monitors every obligation continuously, scores your posture in real time, and turns the moment something slips into a tracked task.

  • Live posture across every GDPR obligation and lawful basis
  • Automatic alerts the moment a control drifts out of compliance
  • Remediation tasks auto-assigned with owners and deadlines
  • A defensible, time-stamped trail across every processing activity
Continuous monitoringObligations · checked hourly
Detected09:14 · EU data replicated to us-east-1
AlertedOwner: Data platform
Task openDATA-418 · due in 2 days
Verifiedauto re-check
Art 44 · International transfersDrifted 09:14 · transfer outside adequacy scope · remediation in progress
Drifting
Art 32 · Encryption at restAll personal-data stores encrypted · last check 08:00
Passing
A defensible, time-stamped trail across every processing activityAudit trail
Collect once, reuse everywhere

Your GDPR work becomes a head start on every other framework

GDPR’s Article 32 security obligations overlap heavily with SOC 2, ISO 27001, and NIST. Compyl cross-maps each control so one piece of evidence satisfies every framework it touches.

  • One control mapped to its equivalent across 70+ frameworks
  • Collect evidence once and reuse it across every report
  • See instantly how GDPR readiness translates to SOC 2 or ISO 27001
  • Add the next framework without starting the program over
One GDPR controlArt 32 · Security of processingEncryption of personal data at rest and in transit · evidence from AWS KMS and TLS configuration1 piece of evidence
Also satisfies
SOC 2CC6.1 · CC6.7 Logical access and transmission
Satisfied
ISO 27001A.8.24 Use of cryptography · A.5.15 Access control
Satisfied
HIPAA Security Rule§164.312(a)(2)(iv) Encryption · (e) Transmission security
Satisfied
NIST CSF 2.0PR.DS-01 · PR.DS-02 Data-at-rest and in-transit
Satisfied
+ 70 more frameworks cross-mapped automatically
Two clocks that define GDPR

The deadlines that make GDPR operational

GDPR isn’t a once-a-year audit, it’s two clocks that can start any day. Compyl is built to help you beat both.

The DSAR clock

One month to respond

A data subject request starts a one-month deadline to find, compile, and deliver everything you hold on a person.

Trigger
Any individual exercising their rights
Deadline
One month, extendable by two further months
With Compyl
A live data map so you know where their data lives
The breach clock 72 hours

72 hours to notify

From becoming aware of a breach, you have 72 hours, where feasible, to notify the supervisory authority of a breach that poses a risk, with scope, impact, and response.

Trigger
A personal-data breach
Deadline
72 hours to the regulator
With Compyl
Breach-ready evidence and clear processing scope
Why Compyl for GDPR

Not a checkbox tool, a continuous compliance engine

Plenty of tools store a privacy policy. Compyl operationalizes GDPR, data maps, DSARs, and evidence that stay true every day.

01

Continuous, not point-in-time

Data maps, lawful basis, and evidence stay live year-round, so audits and DSARs never catch you out.

02

One connected system

Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.

03

125+ integrations

Pulls live data from the stack you already run, so posture reflects reality, not snapshots.

04

Agentic AI

AI maps controls, drafts remediations, and offloads busywork, your team stays in control.

05

Multi-framework by design

GDPR evidence carries over to SOC 2, ISO 27001, HIPAA, and NIST without redoing the work.

Beyond GDPR

Map personal data once, extend to every framework that follows

Compyl cross-maps controls so the work you do for GDPR carries straight into the next framework on your roadmap.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
7
Core data-protection principles mapped to evidence
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
Audit readiness instead of a pre-audit scramble

“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”

JSJon SeniorCTO · via G2

What is GDPR, and how does Compyl help?

GDPR is the EU regulation governing the personal data of EU and EEA residents, built on seven principles and six lawful bases. Beyond policy, it imposes operational duties: Records of Processing (Article 30), data subject access requests answered within one month, Data Protection Impact Assessments (Article 35), and breach notification to regulators within 72 hours. Fines reach €20M or 4% of annual worldwide turnover, whichever is higher. Compyl makes GDPR operational. It maps where personal data lives, runs DSAR and DPIA workflows, keeps your Records of Processing current, collects Article 32 security evidence, and flags drift, so you can prove compliance on demand instead of scrambling for a regulator or a 72-hour clock.

Obligations

What does GDPR compliance software run day to day?

GDPR is a set of clocks and records rather than a certificate. These are the obligations that recur, with the article that sets each one.

ObligationArticleDeadlineWith Compyl
Answer data subject requestsArt. 15–22One month, extendableDSAR intake, routing and deadline tracking
Notify a personal data breachArt. 33Without undue delay, within 72 hours where feasibleIncident workflow with the clock and the notification record
Keep records of processingArt. 30ContinuousData map and processing register kept current
Run a DPIA for high-risk processingArt. 35Before processing startsDPIA workflow tied to the processing record
Contract with processorsArt. 28Before sharing dataVendor records with DPA status and renewal dates
Prove a lawful basisArt. 6ContinuousLawful basis captured per processing activity
FAQ

GDPR questions, answered

What is GDPR?

GDPR is the EU regulation governing the personal data of EU and EEA residents. It is built on seven principles and six lawful bases, and imposes operational duties including Records of Processing (Article 30), data subject access requests within one month, Data Protection Impact Assessments (Article 35), and 72-hour breach notification (Article 33). Fines reach €20M or 4% of annual worldwide turnover, whichever is higher.

Who must comply with GDPR?

Any organization that processes the personal data of people in the EU or EEA, regardless of where the organization is based. That includes most SaaS companies and any business with EU customers, users, or employees.

What is a RoPA and a lawful basis?

A Record of Processing Activities (RoPA, Article 30) documents what personal data you process, for what purpose, and where it flows. A lawful basis (Article 6, consent, contract, legitimate interests, and others) is the legal justification you must have and record for each processing activity.

How does Compyl automate GDPR?

Compyl maps where personal data lives, runs DSAR and DPIA workflows, keeps your RoPA current, collects Article 32 security evidence, scores evidence health, and flags drift, so you can prove compliance on demand instead of scrambling for a regulator or a DSAR deadline.

How does Compyl score evidence quality?

Compyl 26.2 introduced Evidence Health, which continuously scores every piece of evidence on relevance, freshness, and completeness, with an AI summary of what is missing, so gaps surface before a regulator or a 72-hour clock, not during.

Can one GDPR control satisfy other frameworks?

Yes. Compyl cross-maps each control so a single control and its evidence can satisfy GDPR alongside SOC 2, ISO 27001, HIPAA, and 70+ other frameworks. Collect once, reuse everywhere it applies.

Who is Compyl’s GDPR solution designed for?

Security, privacy, and GRC teams, CISOs, DPOs, and IT leaders, at any organization that handles the personal data of EU or EEA residents and needs to run GDPR as an operational program, not a static policy.

Has the EU Digital Omnibus changed GDPR?

Not yet. The European Commission’s November 2025 Digital Omnibus proposal would extend breach notification to 96 hours for high-risk breaches only, create a single incident reporting point and narrow the definition of personal data. It is still being negotiated, and the EDPB opposes key parts, so current GDPR obligations still apply.

Is the GDPR breach deadline 72 or 96 hours?

It is 72 hours. Article 33 requires notifying the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals. The 96-hour threshold exists only in the Digital Omnibus proposal.

What is the GDPR Procedural Regulation?

Regulation (EU) 2025/2518 harmonizes how data protection authorities handle cross-border complaints, with common admissibility rules, procedural rights and investigation deadlines. It entered into force on January 1, 2026 and applies from April 2, 2027.

GRC your way

Make GDPR something you operate, not something you document

See how Compyl maps your personal data, runs DSARs and DPIAs on time, and keeps you ready for the 72-hour breach clock.

Last reviewed September 2026 by the Compyl GRC team
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies