A data subject request has a 30-day deadline. Without a register, that cannot be proved.
The DPO reviews a spreadsheet, nobody knows where personal data is stored, and an erasure request sits in an inbox for three weeks. GDPR compliance is not a document but a system that works every day.
Order GDPR moduleA spreadsheet is not a processing register. An email is not proof of consent. And when a request arrives, the clock starts.
GDPR (EU Regulation 2016/679) requires every organisation to maintain a record of processing activities, protect personal data, and report a security incident to the supervisory authority within 72 hours.
The statutory deadline for responding to a data subject request under GDPR: the right of access, erasure, rectification, or portability. You must respond in writing. Without a request-tracking system and a central register of personal data, meeting this deadline reliably is extremely difficult.
Maximum fine under Article 83(5) GDPR (Regulation EU 2016/679) for serious infringements, or 4% of total global annual turnover, whichever is higher. In Slovenia, enforcement is by the IP (Information Commissioner); in Croatia, by AZOP.
Deadline for notifying a personal data breach to the supervisory authority under Article 33 GDPR. Without an incident register, documented procedures, and internal contact points, this deadline cannot be met reliably.
GDPR compliance: implemented, not just documented.
Before: spreadsheets, email, nobody knows. After: a register with evidence and traceable requests.
Three plans for different organisation sizes.
Every plan includes the RoPA register, consent management, and the data subject request portal. Larger plans add integrations and advanced reporting.
SaaS subscription (packages below): the GDPR module runs on our platform, accessed via browser. The one-time setup covers implementation and configuration; the monthly subscription covers access and updates. Source code is not part of the delivery.
Custom development: from €9,000. Your own GDPR system, source code yours, integration with your existing ERP, HR system, or CRM. For organisations with non-standard requirements or an in-house IT team.
RoPA register, consent management with proof, data subject request portal, incident register, email alerts.
Everything in Starter. Retention period tracking, anonymisation on expiry, processor register, DPIA templates for your DPO (we supply the templates; your DPO conducts the assessment), DPO report.
Everything in Business. CRM integration for customer anonymisation, advanced DPO dashboard, multilingual request portal, API access.
Questions about GDPR compliance.
What is yours. What is not.
Your data is yours at all times. When you leave, you receive a complete export - no delays.