GDPR accountability workspace | Compliancify

Connect processing context, legal interpretation, accountable controls, evidence, rights, incidents, processors, transfers, and human review.

Public scope

Structured context for people and machine readers.

This is a public product and knowledge surface. Illustrative workflows do not establish a professional conclusion, legal or tax advice, guaranteed outcome, or live customer implementation.

  • Processing inventory & roles
  • Lawful basis & transparency
  • Data subject rights
  • Privacy by design & DPIA
  • Processors & transfers
  • Personal-data breach response

Public knowledge 01

Source and applicability boundary

  1. 01

    Official regulation text on EUR-Lex

  2. 02

    EDPB and supervisory-authority guidance may shape interpretation

  3. 03

    Entity-specific legal assessment is required

  4. 04

    Applicability, lawful basis, controller or processor role, risk, national law, and required response depend on facts and qualified legal or privacy review.

  5. 05

    Official starting point: https://eur-lex.europa.eu/eli/reg/2016/679/oj

Public knowledge 02

Obligation and control themes

  1. 01

    Processing inventory & roles — Maintain processing purpose, data, subjects, systems, recipients, transfers, retention, role, and ownership context.

  2. 02

    Lawful basis & transparency — Preserve purpose, lawful-basis assessment, notice content, timing, channel, consent context, and change decisions.

  3. 03

    Data subject rights — Route intake, identity verification, system search, exceptions, response, delivery, and deadline oversight.

  4. 04

    Privacy by design & DPIA — Trigger privacy review, assess risk, document mitigations, approve residual risk, and escalate consultation questions.

  5. 05

    Processors & transfers — Govern processor role, contract, instructions, subprocessor, transfer mechanism, assessment, monitoring, and exit.

  6. 06

    Personal-data breach response — Classify incidents, assess personal-data impact, preserve timeline, route notification decisions, and track corrective actions.

Public knowledge 03

Evidence and review expectations

  1. 01

    Processing inventory & roles: Processing record, data map, product facts, agreements, recipients, retention, and approval history. Owner: Privacy operations owner. Reviewer: Privacy counsel. State: Mapped.

  2. 02

    Lawful basis & transparency: Assessment, notice versions, collection screens, consent records where applicable, translations, and approvals. Owner: Product privacy owner. Reviewer: Privacy counsel. State: Interpretation pending.

  3. 03

    Data subject rights: Request log, verification, system search, decision, approvals, response, delivery, and exception rationale. Owner: Rights operations owner. Reviewer: Privacy reviewer. State: Evidence requested.

  4. 04

    Privacy by design & DPIA: Product assessment, data-flow review, DPIA, risk treatment, sign-off, and change triggers. Owner: Product owner. Reviewer: Data protection reviewer. State: Reviewer decision.

  5. 05

    Processors & transfers: Vendor facts, DPA, transfer mechanism, assessment, notices, monitoring, changes, and termination evidence. Owner: Vendor privacy owner. Reviewer: Privacy counsel. State: Reassessment due.

  6. 06

    Personal-data breach response: Incident facts, timeline, risk assessment, notification decision, communications, approvals, and follow-up. Owner: Incident commander. Reviewer: Privacy counsel. State: Mapped.

Public knowledge 04

Relationships without false equivalence

  1. 01

    ISO/IEC 27001 information-security management

  2. 02

    SOC 2 privacy and security criteria

  3. 03

    NIST CSF 2.0 cyber-risk outcomes