GDPR work is shaped by what you process and for whom, so it starts with stocktaking rather than policy writing. Run the checklist first to see how much of lawful basis, data-subject rights, security, breach handling, DPIAs and transfers you already cover. Then build the Article 30 record of processing activities, because every later decision, including whether a DPIA is needed, reads from it. DPIAs follow for the processing that carries high risk. Only then is it worth comparing software, and the comparison turns on whether a tool holds the register, runs DPIAs and tracks the breach clock, and on where it stores your data.
6 pages on GDPR, in the order the work happens. Jump to the stage you are at, or read straight through.
See which of the checklist's 51 items you already satisfy, from lawful basis to transfers, and which need work.
Build the Article 30 record of processing activities with the columns it requires, and run a DPIA that covers every Article 35(7) element.
Judge platforms on whether they hold the register, run DPIAs and track the breach clock, and on where your data is hosted.
These sit under another subject but bear directly on GDPR.
The free compliance check runs the GDPR gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users