EU General Data Protection Regulation (GDPR)
Version: Regulation (EU) 2016/679
The EU regulation governing the processing of personal data, applicable to controllers and processors established in the EU and to those outside it that offer goods or services to, or monitor the behavior of, people in the EU. This catalog covers the operative obligations in Chapters II to V (Articles 5 to 49).
Where we stand
Controls
81%
Evidence
18%
Policies
27%
11 of 45 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| Ch. II Principles | |||||
| Art. 5 | Principles relating to processing of personal data Controls: DATA-04, LEGAL-01 | Passing | Not current | Not approved | Not yet |
| Art. 6 | Lawfulness of processing | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 7 | Conditions for consent | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 8 | Conditions applicable to child's consent in relation to information society services | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 9 | Processing of special categories of personal data | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 10 | Processing of personal data relating to criminal convictions and offenses Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| Art. 11 | Processing which does not require identification | Unmapped | Unmapped | Unmapped | Not yet |
| Ch. III Rights of the data subject | |||||
| Art. 12 | Transparent information, communication and modalities for the exercise of the rights of the data subject Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| Art. 13 | Information to be provided where personal data are collected from the data subject Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| Art. 14 | Information to be provided where personal data have not been obtained from the data subject Controls: LEGAL-01 | Passing | Not current | Approved | Not yet |
| Art. 15 | Right of access by the data subject | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 16 | Right to rectification | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 17 | Right to erasure ('right to be forgotten') Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| Art. 18 | Right to restriction of processing | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 19 | Notification obligation regarding rectification or erasure of personal data or restriction of processing | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 20 | Right to data portability | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 21 | Right to object | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 22 | Automated individual decision-making, including profiling | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 23 | Restrictions | Unmapped | Unmapped | Unmapped | Not yet |
| Ch. IV Controller and processor | |||||
| Art. 24 | Responsibility of the controller Controls: BIZ-04, BIZ-14 | Passing | Not current | Not approved | Not yet |
| Art. 25 | Data protection by design and by default | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 26 | Joint controllers | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 27 | Representatives of controllers or processors not established in the Union | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 28 | Processor Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| Art. 29 | Processing under the authority of the controller or processor Controls: PEOPLE-02 | Passing | Not current | Not approved | Not yet |
| Art. 30 | Records of processing activities | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 31 | Cooperation with the supervisory authority | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 32 | Security of processing Controls: BIZ-01, DATA-02, DATA-03, DATA-12, IAM-04, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| Art. 33 | Notification of a personal data breach to the supervisory authority Controls: BIZ-03 | Passing | Current | Not approved | (8 h ago) |
| Art. 34 | Communication of a personal data breach to the data subject | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 35 | Data protection impact assessment | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 36 | Prior consultation | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 37 | Designation of the data protection officer | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 38 | Position of the data protection officer | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 39 | Tasks of the data protection officer | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 40 | Codes of conduct | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 41 | Monitoring of approved codes of conduct | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 42 | Certification | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 43 | Certification bodies | Unmapped | Unmapped | Unmapped | Not yet |
| Ch. V Transfers of personal data to third countries or international organisations | |||||
| Art. 44 | General principle for transfers | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 45 | Transfers on the basis of an adequacy decision | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 46 | Transfers subject to appropriate safeguards | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 47 | Binding corporate rules | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 48 | Transfers or disclosures not authorized by Union law | Unmapped | Unmapped | Unmapped | Not yet |
| Art. 49 | Derogations for specific situations | Unmapped | Unmapped | Unmapped | Not yet |
