Automate GDPR Accountability, End to End

Lawful processing, data subject rights, DPIAs, processor oversight, and breach response — mapped to Articles, tracked to deadlines, and evidenced in one platform

Enforcement exposure. Article 83 sets two tiers of administrative fine: up to 10 million euro or 2% of total worldwide annual turnover for the lower tier, and up to 20 million euro or 4% for the higher tier, whichever figure is greater in each case.

The Clocks GDPR Runs On

Most GDPR failures are not failures of intent. They are missed deadlines on obligations that run continuously.

Breach notification

Within 72 hours

Notify the supervisory authority where feasible, counted from the moment you become aware. Article 33.

Data subject request

Within 1 month

Extendable by two further months for complex or numerous requests, if you say so in the first month. Article 12.

Impact assessment

Before go and live

A DPIA is completed before high and risk processing starts, not documented after it. Article 35.

What GDPR Requires, and Where It Says So

The obligations that shape how a compliance programme is built, with the provisions behind them.

Obligation What it requires Provision
Territorial scope Applies to organizations established in the EU, and to those outside it that offer goods or services to, or monitor the behaviour of, individuals in the EU. Art. 3
Principles and accountability Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality, with the controller responsible for demonstrating compliance. Art. 5
Lawful basis and consent A documented lawful ground for every processing activity, with consent captured, withdrawable, and evidenced where it is the basis relied on. Art. 6 to 8
Records of processing A record of each processing activity covering purposes, categories of data and data subjects, recipients, retention, and security measures. Art. 30
Data subject rights Access, rectification, erasure, restriction, portability, and objection, answered within the Article 12 deadline. Ch. III, Art. 12
Impact assessments A DPIA before processing likely to result in a high risk to rights and freedoms. Art. 35
Processor oversight A written agreement with every processor, ongoing monitoring, and safeguards for transfers outside the EEA. Art. 28 to 29, Ch. V
Breach response Assessment, notification to the supervisory authority, and communication to individuals where the risk to them is high. Art. 33 to 34

GDPR Implementation Architecture

How Sigmify GRC's modules are put to work against the obligations above.

Eight obligation areas, one control library underneath them, monitored continuously.

Controls mapped to articles

The Unified Compliance Framework links each control to the provision it satisfies, so Article 5(2) accountability is evidenced rather than assembled later.

Records built from discovery

The Article 30 record is generated from automated data discovery and classification rather than maintained as a separate spreadsheet exercise.

Deadlines tracked, not
remembered

Requests, assessments, and breach workflows carry owners and due dates, with alerts as those dates approach.

What This Looks Like in Practice

The details teams ask about most. Tap any line to expand it.

Article 3 sets territorial scope by activity rather than address. GDPR applies to:

  • Organizations established in the EU, wherever the processing takes place
  • Organizations outside the EU that offer goods or services to individuals in the EU, whether or not payment is required
  • Organizations outside the EU that monitor the behaviour of individuals in the EU

Sigmify GRC records which activities bring an organization into scope and maps the resulting obligations onto its own processing.

Article 30 requires a record of each processing activity, covering:

  • The purposes of the processing
  • The categories of data subjects and of personal data
  • Recipients, including any outside the EU
  • Retention periods, where possible
  • A general description of the technical and organisational security measures in place

Sigmify GRC generates the record from its own data discovery and classification, so it reflects the systems in use rather than the last time someone circulated a survey.

Article 6 recognises six lawful bases for processing personal data:

  • Consent
  • Performance of a contract
  • Compliance with a legal obligation
  • Protection of vital interests
  • A task carried out in the public interest or official authority
  • Legitimate interests

The basis relied on has to be identified and documented against each activity. Where consent is the basis, Articles 7 and 8 require it to be freely given, specific, informed, and as easy to withdraw as to give, with additional conditions for children. Sigmify GRC’s Consent Management module holds capture, purpose linkage, withdrawal, and the audit trail behind each consent state.

Chapter III gives individuals the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Article 12 sets the response deadline at one month from receipt, extendable by two further months where the request is complex or numerous, provided the individual is told within the first month.

Sigmify GRC runs these as data subject request workflows with an owner, a due date drawn from the Article 12 clock, and alerts as it approaches. Because the same platform holds the data map, the team fulfilling a request can see which systems hold that person’s data.

Article 35 requires a DPIA before processing that is likely to result in a high risk to individuals’ rights and freedoms. The regulation names three cases in particular:

  • Systematic and extensive automated evaluation of personal aspects, including profiling, where decisions produce legal or similarly significant effects
  • Large-scale processing of special categories of data, or of data on criminal convictions and offences
  • Systematic monitoring of a publicly accessible area on a large scale

Sigmify GRC’s Assessments and Risk Management modules carry the DPIA, its risk scoring, and its mitigations, with owners and review dates attached so reassessment happens when processing changes.

Article 5(2) makes the controller responsible for demonstrating compliance with the principles, and Articles 24, 25, and 32 frame that in terms of appropriate technical and organisational measures. Sigmify GRC’s Unified Compliance Framework:

  • Centralises the Article 5 principles and aligns them with existing policies, controls, and enterprise systems
  • Links each control to the provision it satisfies, so evidence is produced on demand rather than reconstructed at audit time
  • Maps a control once where it serves several frameworks, and carries a change to it across all of them

Article 28 requires a written contract with every processor, setting out the subject matter, duration, nature and purpose of the processing, the types of data and categories of data subjects, and the controller’s rights and obligations. The contract must also bind the processor to:

  • Process only on documented instructions from the controller
  • Ensure confidentiality commitments from personnel handling the data
  • Take the security measures required under Article 32
  • Engage sub-processors only with the controller’s authorisation
  • Assist with data subject rights, breach notification, and audits

Sigmify GRC’s Vendor Risk Management module keeps each processor’s assessment, agreed obligations, and supporting documents in one place, with review dates and alerts when something falls due.

Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after the controller becomes aware of a personal data breach. Where notification is later than that, the delay has to be explained. Notification is not required where the breach is unlikely to result in a risk to individuals. Article 34 adds communication to the affected individuals without undue delay where the breach is likely to result in a high risk to them.

Sigmify GRC’s Breach and Exceptions Management module runs the incident as a structured workflow, tracking investigation steps, decisions, owners, and timing, and holds the evidence behind the notification decision.

Chapter V allows transfers of personal data outside the EEA only on a recognised basis, principally an adequacy decision from the European Commission, or appropriate safeguards such as Standard Contractual Clauses or binding corporate rules. Sigmify GRC identifies transfers through its data mapping, records the mechanism relied on for each one, and holds the supporting documentation alongside the vendor relationship it belongs to.

Article 83 sets two tiers of administrative fine, each expressed as a fixed ceiling or a percentage of turnover, whichever is higher:

  • Up to 10 million euro, or 2% of total worldwide annual turnover for the preceding financial year, for breaches including controller and processor obligations under Articles 25 to 39
  • Up to 20 million euro, or 4% of total worldwide annual turnover, for breaches including the basic principles, data subject rights, and transfer rules

Supervisory authorities also hold corrective powers beyond fines, including ordering processing to stop.

Sigmify GRC’s compliance monitoring dashboard shows control status, open tasks, and outstanding risks in real time, and highlights defaults before the situation gets out of hand. SIEM and HRM integration feeds it continuously rather than at reporting time, so an overdue request, a lapsed control, or an unmitigated risk surfaces while there is still time to act.

Demonstrating compliance means answering a supervisory authority or an internal audit with documentation, not recollection. Sigmify GRC collects evidence against each control as work is done, keeps it traceable to the provision it supports, and exports it as audit-ready reporting, so it sits in one place instead of across mailboxes and shared drives.

Comply with GDPR with Confidence

Manage EU data protection obligations on one platform: mapped controls, retained evidence, and a single view of where your compliance posture stands.