Regulation · EU

GDPR, without the spreadsheets.

Show, not just claim, that personal data is handled lawfully.

What is GDPR?

The GDPR governs how organisations process personal data of people in the EU. It applies whether you are a controller deciding why data is processed or a processor handling it on someone else’s behalf, and it asks you to demonstrate compliance — accountability is a principle in its own right.

Who needs it

  • Any company processing personal data of people in the EU
  • SaaS vendors acting as processors who must sign Article 28 DPAs
  • Teams that need records of processing and breach procedures ready for a regulator

What GDPR looks at

Lawful basis and transparency

A documented lawful basis for each processing activity and privacy notices that explain it (Arts. 6, 13, 14).

Data subject rights

Working procedures for access, rectification, erasure and portability requests (Arts. 15–22).

Security of processing

Appropriate technical and organisational measures proportionate to the risk (Art. 32).

Processors and transfers

Article 28 contracts with every processor and a lawful mechanism for transfers outside the EEA.

How Beviso gets you there

  • GDPR controls mapped to article numbers, linked to the technical evidence behind them
  • Vendor register that tracks sub-processors and their DPAs for Article 28
  • Incident log with a 72-hour breach notification clock
  • Shared security controls with ISO 27001, so Article 32 work is done once

12 GDPR controls, ready on day one

These controls are loaded when you enable GDPR, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

Art.5

Data Minimisation Principle

Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.

Evidence from

  • Segment
  • Notion
  • Dropbox

Art.13

Privacy Notice (Transparency)

Provide information to data subjects at the time of collection, including identity of controller, purposes, legal basis, and rights.

Evidence from

  • Ironclad
  • DocuSign

Art.17

Right to Erasure

Implement procedures to erase personal data upon request without undue delay, subject to applicable exceptions.

Evidence from

  • Jira
  • ServiceNow
  • Zendesk

Art.25

Privacy by Design and Default

Implement appropriate technical and organisational measures to implement data protection principles from the outset.

Evidence from

  • GitHub
  • GitLab
  • SonarCloud
  • Snyk

Art.30

Records of Processing Activities (ROPA)

Maintain records of processing activities and make available to supervisory authority upon request.

Evidence from

  • Notion
  • Ironclad

Art.28

Data Processing Agreements

Ensure all data processors are bound by a written contract (DPA) that meets GDPR requirements.

Evidence from

  • Ironclad
  • DocuSign

Art.33

Data Breach Notification

Notify supervisory authority within 72 hours of becoming aware of a personal data breach likely to risk rights and freedoms.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira

Art.12

Data Subject Rights Procedures

Implement procedures to handle data subject requests within 30 days.

Evidence from

  • Zendesk
  • Freshdesk
  • ServiceNow
  • Jira
  • Intercom

Art.35

Data Protection Impact Assessment

Conduct DPIA for processing likely to result in high risk to rights and freedoms.

Evidence from

  • Jira
  • Notion
  • Ironclad

Art.32

Security of Processing

Implement appropriate technical and organisational measures to ensure security appropriate to risk, including encryption and pseudonymisation.

Evidence from

  • HashiCorp Vault
  • Doppler
  • 1Password
  • Bitwarden
  • CrowdStrike
  • SentinelOne
  • Snyk
  • Wiz

Art.37

Data Protection Officer

Designate a Data Protection Officer where required.

Evidence from

  • BambooHR
  • HiBob
  • Personio
  • Workday

Art.44

International Data Transfers

Ensure adequate safeguards for transfers of personal data to third countries.

Evidence from

  • Ironclad
  • DocuSign
  • Segment

GDPR questions

Can we be “GDPR certified”?
There is no general GDPR certificate. Compliance is shown through accountability: records, policies, contracts and evidence that the measures work. Beviso keeps that evidence in one place.
We are a processor. What do we need?
A signed Article 28 DPA with each customer, a list of your own sub-processors, appropriate security under Article 32 and a way to notify controllers of breaches without undue delay.
Where is Beviso data stored?
Beviso is built in Berlin and hosts customer data in the EU. See our sub-processor list for details.

Start your GDPR programme today.

Free while Beviso is in beta. No credit card required.

Get started free