Article 30
Records of processing
Maintain records for core processing activities, systems, purposes, and processors.
Due: active
GDPR applies to organisations that process personal data. It requires processing records, data subject rights, processor contracts, risk assessments, and breach notification within 72 hours when required.
Article 30
Maintain records for core processing activities, systems, purposes, and processors.
Due: active
Article 35
Assess risk and safeguards before high-risk personal data processing starts.
Due: before high-risk processing
Article 33
Notify the competent authority when a personal data breach meets the reporting threshold.
Due: 72 hours
Article 28
Keep processor terms and supplier reviews for vendors handling personal data.
Due: active
Build processing records from systems, teams, vendors, and purposes.
Track risk assessment steps, approvals, mitigations, and review dates.
Keep a defensible breach timeline and exportable notification record.
Cookies
We use required cookies and optional traffic measurement to improve Splnit.eu.