Consent Management Platform
- Article 4(11): Definition of data subject consent (Reg. UE 2016/679, Chapter I)
- Article 7(1): Controller must demonstrate consent (Reg. UE 2016/679,Chapter II)
- Article 7(3): Data subject withdraws consent easily (Reg. UE 2016/679,Chapter II)
- Article 12(1): Concise, clear and transparent information (Reg. UE 2016/679,Chapter III, Section 1)
- Article 22(3): Safeguards for automated decisions (Reg. UE 2016/679, Chapter III, Section 4)
- R(32): Consent must be a clear affirmative act (Reg. UE 2016/679, Preamble)
- R(43): Consent must be freely given (Reg. UE 2016/679, Preamble)
Subject Rights Request Management
- Article 12(1): Concise, clear and transparent information (Reg. UE 2016/679, Chapter III, Section 1)
- Article 12(2): Controller must facilitate the exercise of data subject rights (Reg. UE 2016/679, Chapter III, Section 1)
- Article 12(3): Obligation to respond within one month (Reg. UE 2016/679, Chapter III, Section 1)
- Article 12(5): Requests shall be free of charge (Reg. UE 2016/679, Chapter III, Section 1)
- Article 21(4): Inform data subjects of the right to object (Reg. UE 2016/679, Chapter III)
Secure Data Access & Subject Request Portals
- Article 15: Right of access by the data subject (Reg. UE 2016/679, Chapter III, Section 2)
- R(63): Secure remote access systems should be provided where possible (Reg. UE 2016/679, Preamble)
Data Remediation & Notification Service
- Article 16: Right to rectification (Reg. UE 2016/679, Chapter III, Section 3)
- Article 17(2): Obligation to inform controllers to erase public data (Reg. UE 2016/679, Chapter III, Section 3)
- Article 19: Notification obligation regarding rectification or erasure (Reg. UE 2016/679, Chapter III, Section 3)
Data Restriction Controls
- Article 18(1): Right to restriction of processing (Reg. UE 2016/679, Chapter III, Section 3)
- R(67): Restriction of processing through technical measures (Reg. UE 2016/679,Preamble)
Data Security & Resilience Infrastructure
- Article 32(1)(b): Ensure ongoing confidentiality, integrity and resilience (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 32(1)(c): Ability to restore availability and access to data quickly (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 32(1)(d): Regular testing of technical and organisational security measures (Reg. UE 2016/679, Chapter IV, Section 2)
Encryption Management
- Article 32(1)(a): Pseudonymisation and encryption of personal data (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 34(3)(a): Encryption may exempt from breach notification to data subjects (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 25(1): Data protection by design (Reg. UE 2016/679, Chapter IV, Section 1)
- R(83): Encryption as a measure to mitigate risks (Reg. UE 2016/679, Preamble)
DPIA / Risk Management Software
- Article 35(1): Obligation to conduct a DPIA for high-risk processing (Reg. UE 2016/679, Chapter IV, Section 3)
- Article 35(3): Mandatory DPIA in specific cases (Reg. UE 2016/679, Chapter IV, Section 3)
- Article 36(1): Prior consultation in case of residual risk (Reg. UE 2016/679, Chapter IV, Section 3)
- R(87): High-risk processing should be identified in advance (Reg. UE 2016/679, Preamble)
Data Minimization & Privacy by Design Tools
- Article 25(1): Data protection by design – minimisation principle (Reg. UE 2016/679, Chapter IV, Section 1)
- Article 25(2): Data protection by default (Reg. UE 2016/679, Chapter IV, Section 1)
- R(78): Data protection by design and by default (Reg. UE 2016/679, Preamble)
Incident Response & Breach Notification System
- Article 33(1): Notify personal data breach within 72 hours (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 33(2): Processor notifies controller without undue delay (Reg. UE 2016/679, Chapter IV, Section 2)
- Article 34(1): Communication of high-risk breaches to data subjects Reg. UE 2016/679, (Chapter IV, Section 2)
- R(90): Assess risks before processing begins (Reg. UE 2016/679, Preamble)
Incident Response Documentation
- Article 33(5): Obligation to document all data breaches (Reg. UE 2016/679, Chapter IV, Section 2)
Records Management System
- Article 30(1): Controller must maintain records of processing activities (Reg. UE 2016/679, Chapter IV, Section 1)
- Article 30(2): Processor must maintain records of processing activities (Reg. UE 2016/679, Chapter IV, Section 1)
- Article 30(4): Records must be made available to supervisory authority upon request (Reg. UE 2016/679, Chapter IV, Section 1)
- R(86): Documentation and mitigation of breaches (Reg. UE 2016/679, Preamble)