Frameworks & regs
EUv2016/679Pre-reviewed pack

GDPR

3 extracted obligations

Compliance position — GDPRNot signed off
This framework position has not been signed off yet.
67%
Mapping coverage
3 applicable obligations
0
Compliant
fully supported + fresh evidence
2
Partial
mapped, evidence gap
1
Gaps
no internal material mapped
5
Countries in scope
UK · FR · IE · NL · DE
Requirements3AI extractedStatus is derived from each row's mapping
RefRegulatory requirementInterpretation AIStatusScope
Art. 32(1)
Requirement
The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Apply risk-based security controls covering encryption, pseudonymisation, and resilience.
Confidence 94%
Partial Global
Art. 33(1)
Requirement
In the case of a personal data breach, the controller shall notify the supervisory authority not later than 72 hours after having become aware of it.
Wire breach detection to a 72-hour notification clock per lead supervisory authority.
Confidence 92%
Partial
Regional
FRIENLDE
Art. 30
Requirement
Each controller shall maintain a record of processing activities under its responsibility.
Keep a current RoPA covering all processing activities and lawful bases.
Confidence 90%
Gap Global