12 - GDPR Compliance

A data subject request has a 30-day deadline. Without a register, that cannot be proved.

The DPO reviews a spreadsheet, nobody knows where personal data is stored, and an erasure request sits in an inbox for three weeks. GDPR compliance is not a document but a system that works every day.

Order GDPR module

Similar challenge?

We respond within one business day.

Send inquiry
Why it hurts

A spreadsheet is not a processing register. An email is not proof of consent. And when a request arrives, the clock starts.

GDPR (EU Regulation 2016/679) requires every organisation to maintain a record of processing activities, protect personal data, and report a security incident to the supervisory authority within 72 hours.

30 days

The statutory deadline for responding to a data subject request under GDPR: the right of access, erasure, rectification, or portability. You must respond in writing. Without a request-tracking system and a central register of personal data, meeting this deadline reliably is extremely difficult.

up to €20 M

Maximum fine under Article 83(5) GDPR (Regulation EU 2016/679) for serious infringements, or 4% of total global annual turnover, whichever is higher. In Slovenia, enforcement is by the IP (Information Commissioner); in Croatia, by AZOP.

72 hours

Deadline for notifying a personal data breach to the supervisory authority under Article 33 GDPR. Without an incident register, documented procedures, and internal contact points, this deadline cannot be met reliably.

What you get

GDPR compliance: implemented, not just documented.

Record of Processing Activities (RoPA) under Article 30 GDPR
Consent management with proof and timestamp
Data subject request portal (access, erasure, rectification, portability)
Incident register for personal data breaches
Email alerts for pending data subject requests
Retention period tracking and anonymisation on expiry Business+
DPIA templates for your DPO (your DPO conducts the assessment; we supply the templates) Business+
Register of data processing agreements with processors Business+
DPO compliance report (status overview) Business+
CRM integration for customer anonymisation Enterprise
API access Enterprise

Similar challenge?

We respond within one business day.

Send inquiry
Comparison

Before: spreadsheets, email, nobody knows. After: a register with evidence and traceable requests.

Before
Consents in Excel RoPA Word/PDF Requests by email DPO does not know where data is or if consent is valid Request waits 3 weeks → 30-day deadline missed → complaint to supervisory authority
After
GDPR module art. 30 ✓ RoPA register Consent with proof Request portal Incident register DPO report Retention periods 30-day deadline met ✓
Pricing

Three plans for different organisation sizes.

Every plan includes the RoPA register, consent management, and the data subject request portal. Larger plans add integrations and advanced reporting.

SaaS subscription (packages below): the GDPR module runs on our platform, accessed via browser. The one-time setup covers implementation and configuration; the monthly subscription covers access and updates. Source code is not part of the delivery.

Custom development: from €9,000. Your own GDPR system, source code yours, integration with your existing ERP, HR system, or CRM. For organisations with non-standard requirements or an in-house IT team.

Starter
Setup 1,490 €
excl. VAT
+ 49 €/mo. (excl. VAT)

RoPA register, consent management with proof, data subject request portal, incident register, email alerts.

Business
Setup 2,490 €
excl. VAT
+ 99 €/mo. (excl. VAT)

Everything in Starter. Retention period tracking, anonymisation on expiry, processor register, DPIA templates for your DPO (we supply the templates; your DPO conducts the assessment), DPO report.

Enterprise
Setup from 4,500 €
excl. VAT
+ subscription by arrangement (excl. VAT)

Everything in Business. CRM integration for customer anonymisation, advanced DPO dashboard, multilingual request portal, API access.

FAQ

Questions about GDPR compliance.

Ownership & Terms

What is yours. What is not.

Your data is yours at all times. When you leave, you receive a complete export - no delays.

You receive
Unlimited access to the platform for the duration of your subscription
Full export of your data at any time (CSV, Excel, JSON)
30-day data-transfer window after subscription cancellation
SLA by agreement (response time and uptime)
Daily backups with 7-day retention
You can switch to custom development at any time - we migrate your data to your own system.
You cannot demand
The source code of our platform - this is SaaS, not a software licence; buying out the code is not possible, not even retrospectively
Continued access after subscription expiry without payment
Transfer of the subscription to a third party without written consent
Access to other tenants' data - each database is fully isolated

The next GDPR request is coming. Will you be ready to respond within 30 days?

Order GDPR module