Compliance / GDPR
Keep your records of processing complete, screen each activity for a DPIA, log data-subject requests by reference and assess breaches against the 72-hour clock — each step tied to the article it comes from.
What it asks
GDPR asks you to show your accountability, not just claim it. Here are the parts RegNext takes on.
A written record of your processing activities: purposes, categories of people and data, recipients, transfers, retention periods and security measures.
Article 30A record for each activity, as controller or processor, for your firm or a client — with the items Article 30 lists and how complete each record is.
A data protection impact assessment before any processing likely to result in a high risk to people’s rights and freedoms.
Article 35A screening against the cases where an assessment is mandatory and the general high-risk test: required, not required or still to screen — with the reason, and the sections a DPIA must cover.
Answer requests — access, erasure, objection and the others — without undue delay and within one month, extendable by two further months where necessary.
Articles 12–22Requests logged by reference — never the person’s details — with the right concerned, the identity check, the status and the deadline, moved when you extend it.
Notify the supervisory authority within 72 hours where feasible, unless the breach is unlikely to result in a risk — and tell the people affected when the risk to them is high.
Articles 33–34When an incident involves personal data, RegNext proposes whether to notify, counts the 72 hours from when you became aware and says whether the people affected must be told. A person confirms.
Processing by a processor is governed by a contract that sets out what the regulation requires.
Article 28Suppliers tagged as processors, with the text of Article 28 beside them and the status of their contract.
Records of processing
Record each activity as controller or processor, for your firm or for a client. RegNext asks for the items Article 30 lists for that role and shows how complete each record is.
Impact assessments
Screen each activity against the cases where the regulation makes an assessment mandatory, and against the general high-risk test. The answer comes with its reason. When an assessment is required, RegNext sets out what it must cover; when a high risk remains, it flags the prior consultation of the authority.
Data-subject requests
Log each request with the right it concerns, the date it arrived and whether identity was checked. RegNext dates the response, moves the deadline when you extend it and flags anything overdue. There is no field for a name or contact details.
Personal-data breaches
Mark that personal data is involved and give your role. RegNext proposes whether to notify the authority, counts 72 hours from when you became aware, and says whether the people affected must be told — or why not. A person confirms, and the same incident is assessed under DORA and NIS2 where they apply.
Questions
No. Each request is logged under your own reference, and there is no field for a name or contact details.
No. It proposes whether to notify, counts the 72 hours and says whether the people affected must be told. You notify through your authority’s own channel.
RegNext lists what the regulation expects in writing — from your data-protection policy and privacy notice to processor contracts and your breach register — and you mark which of your documents covers each.
Yes. Each processing activity is recorded for your firm or for a client, as controller or processor.
Recorded once
A breach is often an ICT incident too, and a processor is often an ICT provider. RegNext records each once and assesses it under every framework that applies.
Major incidents, critical functions and the register of information.
DORA NIS2Significant incidents, the measures of Article 21 and your supply chain.
NIS2 AI ActAn inventory, a risk class you confirm and the duties that follow.
AI Act OverviewRisks, controls, policies, incidents and suppliers, shared across every framework.
Compliance
Explore how RegNext supports regulatory intelligence and compliance execution in your industry.