1Lawful Basis & Consent Engineering
Articles 6, 7, 8, 9, 12, 13, 22 Auditable lawful-basis and consent capture for every processing purpose.
Consent Management Platform recording auditable proof of consent — timestamp, version, exact text — with one-click withdrawal.
11 requirements54 checklist items51 evidence items
Risk profile: 9 High, 2 Moderate
downloadGet full requirement index2Breach & Change Notification Pipeline
Articles 6, 13, 14, 17, 18, 19, 33, 34 Automated breach detection, escalation, multi-party notification.
End-to-end breach pipeline: processor-to-controller alerting + controller-to-supervisory-authority notification within 72 hours.
16 requirements79 checklist items74 evidence items
Risk profile: 14 High, 2 Moderate
downloadGet full requirement index3Data Subject Rights Operations
Articles 11, 12, 15, 16, 20, 21, 22, 26, 28 Intake, fulfilment, and audit trails for all data-subject rights.
SAR system covering all Art. 15(1)(a)–(h) fields; portability in structured machine-readable formats; automated marketing opt-out suppression.
15 requirements80 checklist items76 evidence items
Risk profile: 10 High, 5 Moderate
downloadGet full requirement index4Access Control & Security Measures
Articles 5, 9, 10, 18, 22, 23, 28, 29, 32, 34, 47 Encryption, access controls, and security safeguards across systems.
Pseudonymisation and encryption at rest (AES-256) and in transit (TLS 1.2+), KMS with key rotation. Technical necessity score: 0.95.
19 requirements95 checklist items89 evidence items
Risk profile: 17 High, 2 Moderate
downloadGet full requirement index5Controller Governance & Accountability
Articles 10, 11, 24, 25, 26, 27, 28, 30, 31, 32, 35, 36, 37, 38, 39 RoPA, DPO mandate, DPIA, organisational accountability.
Both Article 25 requirements live here — alongside RoPA, DPIA gate, and DPO mandate. The largest pillar and the foundation every other rests on.
32 requirements150 checklist items144 evidence items
Risk profile: 18 High, 14 Moderate
downloadGet full requirement index6Codes, Certifications & BCR Compliance
Articles 24, 40, 41, 47 Evidencing adherence to codes, certifications, and BCR commitments.
Article 25(3) makes certification "an element to demonstrate compliance." This pillar operationalises that track.
9 requirements41 checklist items35 evidence items
Risk profile: 1 High, 7 Moderate, 1 Low
downloadGet full requirement index7International Transfer Governance
Articles 14, 15, 20, 44, 45, 46, 47, 48, 49 Register, safeguard, and monitor all cross-border transfers.
Transfer-compliance system enforcing Chapter V conditions before any third-country transfer, including onward transfers.
16 requirements77 checklist items71 evidence items
Risk profile: 10 High, 6 Moderate
downloadGet full requirement index