GDPR, without the spreadsheets.
Show, not just claim, that personal data is handled lawfully.
What is GDPR?
The GDPR governs how organisations process personal data of people in the EU. It applies whether you are a controller deciding why data is processed or a processor handling it on someone else’s behalf, and it asks you to demonstrate compliance — accountability is a principle in its own right.
Who needs it
- Any company processing personal data of people in the EU
- SaaS vendors acting as processors who must sign Article 28 DPAs
- Teams that need records of processing and breach procedures ready for a regulator
What GDPR looks at
Lawful basis and transparency
A documented lawful basis for each processing activity and privacy notices that explain it (Arts. 6, 13, 14).
Data subject rights
Working procedures for access, rectification, erasure and portability requests (Arts. 15–22).
Security of processing
Appropriate technical and organisational measures proportionate to the risk (Art. 32).
Processors and transfers
Article 28 contracts with every processor and a lawful mechanism for transfers outside the EEA.
How Beviso gets you there
- GDPR controls mapped to article numbers, linked to the technical evidence behind them
- Vendor register that tracks sub-processors and their DPAs for Article 28
- Incident log with a 72-hour breach notification clock
- Shared security controls with ISO 27001, so Article 32 work is done once
12 GDPR controls, ready on day one
These controls are loaded when you enable GDPR, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
Art.5
Data Minimisation Principle
Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
Evidence from
- Segment
- Notion
- Dropbox
Art.13
Privacy Notice (Transparency)
Provide information to data subjects at the time of collection, including identity of controller, purposes, legal basis, and rights.
Evidence from
- Ironclad
- DocuSign
Art.17
Right to Erasure
Implement procedures to erase personal data upon request without undue delay, subject to applicable exceptions.
Evidence from
- Jira
- ServiceNow
- Zendesk
Art.25
Privacy by Design and Default
Implement appropriate technical and organisational measures to implement data protection principles from the outset.
Evidence from
- GitHub
- GitLab
- SonarCloud
- Snyk
Art.30
Records of Processing Activities (ROPA)
Maintain records of processing activities and make available to supervisory authority upon request.
Evidence from
- Notion
- Ironclad
Art.28
Data Processing Agreements
Ensure all data processors are bound by a written contract (DPA) that meets GDPR requirements.
Evidence from
- Ironclad
- DocuSign
Art.33
Data Breach Notification
Notify supervisory authority within 72 hours of becoming aware of a personal data breach likely to risk rights and freedoms.
Evidence from
- PagerDuty
- ServiceNow
- Jira
Art.12
Data Subject Rights Procedures
Implement procedures to handle data subject requests within 30 days.
Evidence from
- Zendesk
- Freshdesk
- ServiceNow
- Jira
- Intercom
Art.35
Data Protection Impact Assessment
Conduct DPIA for processing likely to result in high risk to rights and freedoms.
Evidence from
- Jira
- Notion
- Ironclad
Art.32
Security of Processing
Implement appropriate technical and organisational measures to ensure security appropriate to risk, including encryption and pseudonymisation.
Evidence from
- HashiCorp Vault
- Doppler
- 1Password
- Bitwarden
- CrowdStrike
- SentinelOne
- Snyk
- Wiz
Art.37
Data Protection Officer
Designate a Data Protection Officer where required.
Evidence from
- BambooHR
- HiBob
- Personio
- Workday
Art.44
International Data Transfers
Ensure adequate safeguards for transfers of personal data to third countries.
Evidence from
- Ironclad
- DocuSign
- Segment
GDPR questions
- Can we be “GDPR certified”?
- There is no general GDPR certificate. Compliance is shown through accountability: records, policies, contracts and evidence that the measures work. Beviso keeps that evidence in one place.
- We are a processor. What do we need?
- A signed Article 28 DPA with each customer, a list of your own sub-processors, appropriate security under Article 32 and a way to notify controllers of breaches without undue delay.
- Where is Beviso data stored?
- Beviso is built in Berlin and hosts customer data in the EU. See our sub-processor list for details.
Often run alongside GDPR
ISO 27701
Turn your privacy programme into a certifiable management system.
ISO 27001
Build an information security management system an auditor will certify.
NIS 2
Meet the EU’s cybersecurity baseline before the regulator asks.
DORA
Prove operational resilience to EU financial regulators — and to the banks you supply.
Start your GDPR programme today.
Free while Beviso is in beta. No credit card required.
Get started free