Compliance / GDPR

Personal data, accounted for — without collecting more of it.

Keep your records of processing complete, screen each activity for a DPIA, log data-subject requests by reference and assess breaches against the 72-hour clock — each step tied to the article it comes from.

Regulation (EU) 2016/679Applies since 25 May 2018Controllers and processors
Reference onlyrequests logged without the person’s details
72 hourscounted from when you became aware of a breach
Complete recordsthe items Article 30 lists, and what is still missing
A person decidesthe rules propose whether to notify; you confirm

What it asks

What GDPR asks of you — and where RegNext takes it on.

GDPR asks you to show your accountability, not just claim it. Here are the parts RegNext takes on.

01

Records of processing

A written record of your processing activities: purposes, categories of people and data, recipients, transfers, retention periods and security measures.

Article 30
In RegNext

A record for each activity, as controller or processor, for your firm or a client — with the items Article 30 lists and how complete each record is.

02

Impact assessments

A data protection impact assessment before any processing likely to result in a high risk to people’s rights and freedoms.

Article 35
In RegNext

A screening against the cases where an assessment is mandatory and the general high-risk test: required, not required or still to screen — with the reason, and the sections a DPIA must cover.

03

Data-subject rights

Answer requests — access, erasure, objection and the others — without undue delay and within one month, extendable by two further months where necessary.

Articles 12–22
In RegNext

Requests logged by reference — never the person’s details — with the right concerned, the identity check, the status and the deadline, moved when you extend it.

04

Personal-data breaches

Notify the supervisory authority within 72 hours where feasible, unless the breach is unlikely to result in a risk — and tell the people affected when the risk to them is high.

Articles 33–34
In RegNext

When an incident involves personal data, RegNext proposes whether to notify, counts the 72 hours from when you became aware and says whether the people affected must be told. A person confirms.

05

Processors

Processing by a processor is governed by a contract that sets out what the regulation requires.

Article 28
In RegNext

Suppliers tagged as processors, with the text of Article 28 beside them and the status of their contract.

Records of processing

A record of processing that knows what it is missing.

Record each activity as controller or processor, for your firm or for a client. RegNext asks for the items Article 30 lists for that role and shows how complete each record is.

Controller or processorThe items each role must record.
For you or a clientActivities run for clients kept apart.
CompletenessSee at a glance what is still missing.
LinkedTo your risks, controls, incidents and suppliers.

Impact assessments

Know when a DPIA is required — and what it must contain.

Screen each activity against the cases where the regulation makes an assessment mandatory, and against the general high-risk test. The answer comes with its reason. When an assessment is required, RegNext sets out what it must cover; when a high risk remains, it flags the prior consultation of the authority.

Required, or notOr still to screen — never left unclear.
With the reasonThe case that triggered it.
What it must containThe sections Article 35 lists.
Prior consultationFlagged when a high risk remains.

Data-subject requests

Every request on time — logged by reference.

Log each request with the right it concerns, the date it arrived and whether identity was checked. RegNext dates the response, moves the deadline when you extend it and flags anything overdue. There is no field for a name or contact details.

Every rightAccess, rectification, erasure, objection and the rest.
DatedThe response deadline, and the new one when extended.
Overdue flaggedLate requests stand out.
Reference onlyYour own reference, never the person’s details.

Personal-data breaches

When an incident involves personal data, the clock starts.

Mark that personal data is involved and give your role. RegNext proposes whether to notify the authority, counts 72 hours from when you became aware, and says whether the people affected must be told — or why not. A person confirms, and the same incident is assessed under DORA and NIS2 where they apply.

To notify, or notProposed from Article 33, confirmed by a person.
72 hoursCounted from when you became aware.
The people affectedWhether they must be told, and the exemptions.
As a processorNotify the controller instead.

Questions

Questions about GDPR.

Do you store the personal data of people who make requests?

No. Each request is logged under your own reference, and there is no field for a name or contact details.

Does RegNext notify the authority for us?

No. It proposes whether to notify, counts the 72 hours and says whether the people affected must be told. You notify through your authority’s own channel.

Which documents does GDPR expect us to have?

RegNext lists what the regulation expects in writing — from your data-protection policy and privacy notice to processor contracts and your breach register — and you mark which of your documents covers each.

Can we keep records for our clients too?

Yes. Each processing activity is recorded for your firm or for a client, as controller or processor.

image of brainstorming session for a productivity tools business

Transform compliance.
Accelerate outcomes.

Explore how RegNext supports regulatory intelligence and compliance execution in your industry.