Skip to content
Privacy

Operationalise GDPR — not just a privacy policy

Comply gives you the working machinery for GDPR — records of processing, data-subject request workflows, consent and lawful-basis tracking, and the breach clock — mapped to your security controls.

Typical readiness: 6–10 weeks to a defensible baseline

What it is

The General Data Protection Regulation is the European Union's data-protection law. It governs how organisations collect and process the personal data of people in the EU and EEA, with obligations around lawful basis, consent, transparency, data-subject rights, records of processing (RoPA), data protection by design, and 72-hour breach notification. Fines reach up to €20 million or 4 percent of global annual turnover, whichever is higher.


Who needs it

Any organisation that offers goods or services to, or monitors the behaviour of, people in the EU or EEA — regardless of where the company itself is based. That includes most SaaS, e-commerce and global B2B firms.

How Comply helps

Get GDPR-ready, then stay that way

Connect your stack, map controls once, and let continuous monitoring keep evidence fresh — across every framework you run.

Records of processing (RoPA)

Build and maintain your Article 30 records — what personal data you process, why, where it lives and who it is shared with — kept current as your systems change.

Consent & lawful basis

Capture, version and withdraw consent, and document the lawful basis for every processing activity so you can prove compliance, not just claim it.

Data-subject requests

End-to-end workflows for access, rectification, erasure and portability — with identity checks, system-wide data location, approvals and SLA tracking.

72-hour breach clock

Detect, log and run the breach-notification timeline to your supervisory authority and affected individuals, with the evidence trail regulators expect.

Transfers & vendor governance

Track international data transfers, SCCs and processor obligations, with continuous third-party monitoring built in.

Shared control set

GDPR security obligations map straight to your SOC 2 and ISO 27001 controls, and to India's DPDP — run them as one programme, not three.

GDPR you can actually operate

A privacy policy is not GDPR compliance. The regulation expects working processes — records, consent, rights handling and breach response — that you can demonstrate on demand. Comply provides the machinery:

  • Map every processing activity into a living Article 30 record.
  • Govern consent and lawful basis with versioned, auditable evidence.
  • Respond to access, erasure and portability requests inside the legal timeline.
  • Reuse your SOC 2 and ISO 27001 security controls to satisfy security-of-processing.

Because GDPR shares Comply’s evidence engine with DPDP and your security frameworks, one privacy programme covers your obligations across regions.

FAQ

GDPR questions, answered

Yes. GDPR's security-of-processing requirements overlap with your SOC 2 and ISO 27001 controls, and Comply maps them automatically. You then layer on the privacy-specific machinery — RoPA, DSARs, consent and the breach clock — on top of work already done.

They are conceptually close — both cover consent, notice, data-subject rights and breach notification — but differ in detail and authority. Comply runs both natively from one control set, so global firms operating in India satisfy both regimes without duplicate programmes, something global-only tools cannot offer.

Yes. Comply manages the full DSAR lifecycle — intake, identity verification, locating the data across your systems, approvals, fulfilment and SLA tracking — with an auditable record of every request.

GDPR applies based on whose data you process, not where you are. If you offer goods or services to, or monitor, people in the EU or EEA, it applies. Comply helps you scope exactly which activities are in play.

GDPR requires notifying your supervisory authority within 72 hours of becoming aware of a qualifying breach. Comply runs the clock, captures the evidence and guides the notification so the deadline does not slip.

One platform, every framework

Comply maps a single control set across all of these — add a framework without adding work.

Start your GDPR program free

Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.

Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.