General Data Protection Regulation.
Rules for processing personal data
What GDPR requires.
The General Data Protection Regulation (Regulation (EU) 2016/679) sets the EU rules for processing personal data, with fines up to 4% of global turnover.
Why it's hard.
Processing happens with others
Personal data is often processed by suppliers and service providers.
Keeping records current
Suppliers and processing change over time, and records have to follow.
Many parties to follow up
Every supplier that processes personal data needs follow-up.
Overlap with security requirements
Data protection requests often come together with NIS2 and other security requirements.
How Regweaver helps.
GDPR requirements as structured requests
Turn GDPR requirements into structured requests that run through the same relationships as your other frameworks.
Across the value chain
Send requests to suppliers and partners in every tier you work with, and see which answers are outstanding.
Evidence tied to the requirement
Every answer and document is linked to the requirement it supports, so the trail is there when someone asks.
Versioned records
Answers and evidence are versioned and timestamped, so you can show what was known and when.
Who's affected.
You may not be in scope — but your customers are.
Companies in scope
Regulation impacts organisations — but execution happens across teams.
Teams responsible for compliance
Related: Multi-tier value chain governance
Not sure how GDPR applies to you?
Request a RegCheck and get a tailored regulatory overview from our team.
Monitor GDPR
We watch for changes and send a reviewed notice when something actually changes.
See the monitoring option