GDPR lives in operations: knowing where personal data sits, answering data subject requests on deadline, keeping Records of Processing current, and proving a lawful basis for everything. Compyl’s GDPR compliance software runs it continuously, data mapping, DSAR and DPIA workflows, and breach-ready evidence.
GDPR turns on operational reality: where personal data lives, who can access it, and how fast you respond. When that drifts from your paperwork, the regulator and the DSAR clock find it first.
New tools and integrations move personal data constantly. A Record of Processing built once is wrong within a quarter, and wrong is exactly what a regulator audits.
A data subject access request gives you one month. Without knowing where their data lives, every request becomes a manual fire drill across teams.
From detection to regulator notification you have 72 hours. Scattered evidence and unclear scope make that deadline almost impossible to hit.
Compyl runs your GDPR program as an always-on cycle, data mapping, lawful basis, and evidence stay in sync automatically.
Integrate cloud, identity, code, endpoint, and HR systems.
Pull audit evidence automatically, in real time.
Link every artifact to its GDPR article and lawful basis.
Watch controls continuously and flag drift early.
Hand auditors a current evidence pack on demand.
GDPR is built on seven principles, but compliance is proven through operational duties. Compyl maps evidence to each one.
Establish and record a lawful basis for every processing activity, and manage consent where it applies.
Maintain a current RoPA describing what data you process, why, and where it flows.
Answer access, erasure, and portability requests (DSARs) within one month.
Run Data Protection Impact Assessments for high-risk processing before it begins.
Implement appropriate security and notify regulators of a breach within 72 hours.
GDPR proof isn’t a single report, it’s a current data map, a lawful basis for every processing activity, and Article 32 security evidence. Compyl collects it continuously from the systems you already run.
Collecting evidence is only half the battle; stale or incomplete proof is where audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces before a regulator or a 72-hour clock, not during.
Regulators and DSARs don’t wait for your annual review. Compyl monitors every obligation continuously, scores your posture in real time, and turns the moment something slips into a tracked task.
GDPR’s Article 32 security obligations overlap heavily with SOC 2, ISO 27001, and NIST. Compyl cross-maps each control so one piece of evidence satisfies every framework it touches.
GDPR isn’t a once-a-year audit, it’s two clocks that can start any day. Compyl is built to help you beat both.
A data subject request starts a one-month deadline to find, compile, and deliver everything you hold on a person.
From becoming aware of a breach, you have 72 hours, where feasible, to notify the supervisory authority of a breach that poses a risk, with scope, impact, and response.
Plenty of tools store a privacy policy. Compyl operationalizes GDPR, data maps, DSARs, and evidence that stay true every day.
Data maps, lawful basis, and evidence stay live year-round, so audits and DSARs never catch you out.
Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.
Pulls live data from the stack you already run, so posture reflects reality, not snapshots.
AI maps controls, drafts remediations, and offloads busywork, your team stays in control.
GDPR evidence carries over to SOC 2, ISO 27001, HIPAA, and NIST without redoing the work.
Compyl cross-maps controls so the work you do for GDPR carries straight into the next framework on your roadmap.
“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”
GDPR is the EU regulation governing the personal data of EU and EEA residents, built on seven principles and six lawful bases. Beyond policy, it imposes operational duties: Records of Processing (Article 30), data subject access requests answered within one month, Data Protection Impact Assessments (Article 35), and breach notification to regulators within 72 hours. Fines reach €20M or 4% of annual worldwide turnover, whichever is higher. Compyl makes GDPR operational. It maps where personal data lives, runs DSAR and DPIA workflows, keeps your Records of Processing current, collects Article 32 security evidence, and flags drift, so you can prove compliance on demand instead of scrambling for a regulator or a 72-hour clock.
GDPR is a set of clocks and records rather than a certificate. These are the obligations that recur, with the article that sets each one.
| Obligation | Article | Deadline | With Compyl |
|---|---|---|---|
| Answer data subject requests | Art. 15–22 | One month, extendable | DSAR intake, routing and deadline tracking |
| Notify a personal data breach | Art. 33 | Without undue delay, within 72 hours where feasible | Incident workflow with the clock and the notification record |
| Keep records of processing | Art. 30 | Continuous | Data map and processing register kept current |
| Run a DPIA for high-risk processing | Art. 35 | Before processing starts | DPIA workflow tied to the processing record |
| Contract with processors | Art. 28 | Before sharing data | Vendor records with DPA status and renewal dates |
| Prove a lawful basis | Art. 6 | Continuous | Lawful basis captured per processing activity |
GDPR is the EU regulation governing the personal data of EU and EEA residents. It is built on seven principles and six lawful bases, and imposes operational duties including Records of Processing (Article 30), data subject access requests within one month, Data Protection Impact Assessments (Article 35), and 72-hour breach notification (Article 33). Fines reach €20M or 4% of annual worldwide turnover, whichever is higher.
Any organization that processes the personal data of people in the EU or EEA, regardless of where the organization is based. That includes most SaaS companies and any business with EU customers, users, or employees.
A Record of Processing Activities (RoPA, Article 30) documents what personal data you process, for what purpose, and where it flows. A lawful basis (Article 6, consent, contract, legitimate interests, and others) is the legal justification you must have and record for each processing activity.
Compyl maps where personal data lives, runs DSAR and DPIA workflows, keeps your RoPA current, collects Article 32 security evidence, scores evidence health, and flags drift, so you can prove compliance on demand instead of scrambling for a regulator or a DSAR deadline.
Compyl 26.2 introduced Evidence Health, which continuously scores every piece of evidence on relevance, freshness, and completeness, with an AI summary of what is missing, so gaps surface before a regulator or a 72-hour clock, not during.
Yes. Compyl cross-maps each control so a single control and its evidence can satisfy GDPR alongside SOC 2, ISO 27001, HIPAA, and 70+ other frameworks. Collect once, reuse everywhere it applies.
Security, privacy, and GRC teams, CISOs, DPOs, and IT leaders, at any organization that handles the personal data of EU or EEA residents and needs to run GDPR as an operational program, not a static policy.
Not yet. The European Commission’s November 2025 Digital Omnibus proposal would extend breach notification to 96 hours for high-risk breaches only, create a single incident reporting point and narrow the definition of personal data. It is still being negotiated, and the EDPB opposes key parts, so current GDPR obligations still apply.
It is 72 hours. Article 33 requires notifying the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals. The 96-hour threshold exists only in the Digital Omnibus proposal.
Regulation (EU) 2025/2518 harmonizes how data protection authorities handle cross-border complaints, with common admissibility rules, procedural rights and investigation deadlines. It entered into force on January 1, 2026 and applies from April 2, 2027.
See how Compyl maps your personal data, runs DSARs and DPIAs on time, and keeps you ready for the 72-hour breach clock.