Skip to content
Framework · European Union Regulation (EU) 2016/679

GDPR

The European Union's data-protection regulation. Applies to any organization processing the personal data of EU residents — regardless of where the organization is based. Fines up to 4% of global annual revenue.

109 Talarity controls mapped
Who it's for: Any company with EU customers, employees, or website visitors. Extraterritorial scope means you don't have to be in the EU to be subject to it.
Talarity coverage

Mapped, monitored, and audit-ready.

Every GDPR control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

109
Talarity controls mapped

Talarity's pre-built control library covering GDPR, with linked evidence, owners, and testing schedules.

Cross-maps to
ISO 27001ISO 27701SOC 2UK GDPR

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • Records of Processing Activities (RoPA) per Article 30
  • Data Subject Access Request (DSAR) handling logs
  • Lawful basis records and consent capture
  • Cross-border transfer mechanisms (SCCs, adequacy decisions)
  • Data Protection Impact Assessments (DPIAs)

Your GDPR dashboard

Every completed GDPR assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed GDPR assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

DSAR volume is unpredictable — and Article 12 requires response within 30 days.

Talarity

DSAR workflow with intake, identity verification, sub-request decomposition, and a 30-day clock. Bulk DSAR support for breach scenarios.

Pain

Article 30 records of processing (RoPA) drift the moment a new system or vendor goes live.

Talarity

RoPA generates from your data inventory and vendor contracts. New system added? RoPA flags it for owner review.

Pain

Cross-border transfers post-Schrems II require Standard Contractual Clauses + transfer impact assessments — most teams haven't documented these well.

Talarity

TIA workflow with country-risk lookups, SCC clause selection, and supplementary measures evaluation. Auditable trail for every transfer.

Pain

Lawful basis tracking — consent vs. legitimate interest vs. contract — is hard to maintain at scale.

Talarity

Consent management with version history. Every personal-data field tags to its lawful basis; basis changes trigger a re-consent workflow.

GDPR — common questions

What is the difference between a controller and a processor?
A controller determines the purposes and means of processing personal data; a processor acts on the controller's documented instructions. The distinction drives your obligations — controllers own lawful basis, transparency and data subject rights, while processors owe security, sub-processor control and assistance to the controller. The roles are determined by what you actually do with the data, not by what a contract labels you, and one organisation is frequently a controller for some processing and a processor for other processing.
When is a Data Protection Impact Assessment required?
A DPIA is required where processing is likely to result in a high risk to individuals — notably systematic and extensive automated evaluation producing legal or similarly significant effects, large-scale processing of special category data, and large-scale systematic monitoring of publicly accessible areas. Supervisory authorities also publish their own lists of operations that require one. The assessment has to happen before the processing starts, which makes it a design-time gate rather than a review.
How quickly must a personal data breach be reported?
Controllers must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals. Where the risk to individuals is high, affected individuals must also be told without undue delay. Processors must notify their controller without undue delay. Because the clock runs from awareness, when you became aware is itself a fact you need to be able to evidence.
What is a Record of Processing Activities?
Article 30 requires controllers and processors to maintain a record of their processing activities — purposes, categories of data and data subjects, recipients, transfers, retention periods and security measures. There is a limited exemption for organisations under 250 employees, but it falls away for processing that is not occasional, risks individuals' rights, or involves special category data, so most organisations end up needing one. It is usually the first document a supervisory authority asks for.
How can personal data be transferred outside the EEA?
Transfers need a legal basis: an adequacy decision for the destination country, or appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow derogation. Where safeguards are used, a transfer impact assessment considers whether local law undermines them and whether supplementary measures are needed. This is why knowing where each sub-processor actually stores and accesses data matters more than where the vendor is headquartered.

Working with GDPR

Step-by-step walkthroughs from the Talarity library.

Ready to ship GDPR?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.