GDPR, Regulation (EU) 2016/679
Data protection records you can show at any time
The GDPR asks you to know what personal data you process, to answer people's requests on time and to report breaches quickly. CloudSignLab keeps the record of processing activities, the requests and the breach log next to your security controls.

What the GDPR asks of you
Record of processing activities (Article 30)
Purposes, categories of people and data, recipients, transfers outside the EU, retention periods and security measures, for each processing activity.
Rights of individuals (Articles 12 to 22)
Answer requests for access, rectification, erasure and other rights without undue delay and within one month, which can be extended by two further months when needed.
Breach notification (Articles 33 and 34)
Report a personal data breach to the supervisory authority within 72 hours of becoming aware of it, and inform the people affected when the risk to them is high.
Security and impact assessments (Articles 32 and 35)
Appropriate technical and organizational security, and a data protection impact assessment for processing likely to result in a high risk.
How CloudSignLab helps
Record of processing activities
Each activity with purpose, legal basis, data categories, recipients, transfers, retention, processors and whether an impact assessment is required, with a review date.
Requests with deadlines
Log each request with the date it was received; the due date follows, can be extended, and the person handling it gets a reminder.
Breach log with the 72-hour clock
Record when you became aware, the risk and the measures, when the authority and the people affected were told, or why no report was needed, linked to the incident.
Privacy readiness
Readiness steps for GDPR and ISO 27701 worked out from your registers, so you see what an auditor or authority looks at first.
Questions about the GDPR
Does CloudSignLab replace a data protection officer?
No. CloudSignLab keeps the records and deadlines your data protection officer or privacy lead works with; the legal assessments stay with them.
Can I use it for data breaches and security incidents together?
Yes. A personal data breach can be linked to the security incident, so the NIS2 and GDPR deadlines are both visible.
Bring your GDPR records into one place
Start free and add your first processing activities today.
