1Lawful Basis & Consent Engineering
Articles 6, 7, 8, 9, 12, 13, 22 Auditable lawful-basis and consent capture for every processing purpose.
Consent Management Platform recording auditable proof of consent (timestamp, version, exact text) with one-click withdrawal.
11 requirements54 checklist items51 evidence items
Risk profile: 9 High, 2 Moderate
downloadGet full requirement index2Breach & Change Notification Pipeline
Articles 6, 13, 14, 17, 18, 19, 33, 34 Automated breach detection, escalation, multi-party notification.
End-to-end breach pipeline: processor-to-controller alerting + controller-to-supervisory-authority notification within 72 hours.
16 requirements79 checklist items74 evidence items
Risk profile: 14 High, 2 Moderate
downloadGet full requirement index3Data Subject Rights Operations
Articles 11, 12, 15, 16, 20, 21, 22, 26, 28 Intake, fulfilment, and audit trails for all data-subject rights.
SAR system covering all Art. 15(1)(a)–(h) fields; portability in structured machine-readable formats; automated marketing opt-out suppression.
15 requirements80 checklist items76 evidence items
Risk profile: 10 High, 5 Moderate
downloadGet full requirement index4Access Control & Security Measures
Articles 5, 9, 10, 18, 22, 23, 28, 29, 32, 34, 47 Encryption, access controls, and security safeguards across systems.
Pseudonymisation and encryption at rest (AES-256) and in transit (TLS 1.2+), KMS with key rotation. Technical necessity score: 0.95.
19 requirements95 checklist items89 evidence items
Risk profile: 17 High, 2 Moderate
downloadGet full requirement index5Controller Governance & Accountability
Articles 10, 11, 24, 25, 26, 27, 28, 30, 31, 32, 35, 36, 37, 38, 39 RoPA, DPO mandate, DPIA, organisational accountability.
Both Article 25 requirements live here, alongside RoPA, DPIA gate, and DPO mandate. The largest pillar and the foundation every other rests on.
32 requirements150 checklist items144 evidence items
Risk profile: 18 High, 14 Moderate
downloadGet full requirement index6Codes, Certifications & BCR Compliance
Articles 24, 40, 41, 47 Evidencing adherence to codes, certifications, and BCR commitments.
Article 25(3) makes certification "an element to demonstrate compliance." This pillar operationalises that track.
9 requirements41 checklist items35 evidence items
Risk profile: 1 High, 7 Moderate, 1 Low
downloadGet full requirement index7International Transfer Governance
Articles 14, 15, 20, 44, 45, 46, 47, 48, 49 Register, safeguard, and monitor all cross-border transfers.
Transfer-compliance system enforcing Chapter V conditions before any third-country transfer, including onward transfers.
16 requirements77 checklist items71 evidence items
Risk profile: 10 High, 6 Moderate
downloadGet full requirement index