Reconectando con el servidor

Mantén esta pestaña abierta: tu trabajo no se ha perdido.

No hemos podido reconectar

Recarga la página para continuar donde lo dejaste.

La sesión ha caducado

Vuelve a cargar la página para iniciar sesión de nuevo.

Spain's authority is now operating and tick-box channels are under review. Would yours hold up?Act now →
People and work ›

Personal data protection

GDPR in practice: processing records, assessments, data subject rights and breaches

GDPR isn't evidenced by a published privacy policy. It's evidenced by an up-to-date record of processing, impact assessments for high-risk processing, answering rights requests on time, and documented breach handling.

5 screens of the programme
app.dsacompliance.net Personal data protection
01A privacy dashboard per entity
02The art. 30 record of processing activities
03An impact assessment with inherent and residual risk
04Data subject requests ordered by due date
05Breaches with the 72-hour clock running
DSA Compliance

Screens from DSA Compliance v6.2 in a demo environment. All data shown is fictitious.

The obligation, precisely

What the rule requires, and in which article

For information only, not legal advice. Always check against the consolidated text in force.

Art. 30 GDPR
A record of processing activities, with purposes, categories of data subjects and data, transfers, erasure periods and security measures.
Art. 35 GDPR
A data protection impact assessment where processing poses a high risk to rights and freedoms, with prior consultation of the authority if residual risk remains.
Arts. 12 to 22 GDPR
Handling access, rectification, erasure, restriction, portability and objection requests within one month, extendable by two months with justification.
Arts. 33 and 34 GDPR
Notifying the supervisory authority within 72 hours of becoming aware, and telling the individuals where the risk is high.
Penalty regime

Up to €20,000,000 or 4% of worldwide annual turnover (art. 83.5 GDPR). In Chile, Ley 21.719 sets fines of up to 20,000 UTM from December 2026.

Rules it covers
RGPDUE 2016/679LOPDGDDLO 3/2018Ley 21.719Chile

The badges identify the obligation the program digitises. They are not certifications or conformity accreditations.

What it leaves as evidence

What gets handed over when somebody asks

  • A record of processing exportable as the official register
  • Impact assessments versioned and signed by the data protection officer
  • A file for every right exercised, with identity verification and a sealed response
  • A timeline of every breach with the 72-hour count
  • A register of processors and their art. 28 contracts
Who it applies to
Any organisation processing personal data in the EU
Companies with an appointed data protection officer
Groups making international transfers
Companies operating in Chile, Brazil or Ecuador under their local rules
International framework

This programme implements certifiable ISO standards. If your organisation already is, here you see which part is solved and which laws it covers in each country where you operate.

ISO 42001 · AI management systemsISO 27001 · Information security
Frequently asked questions

What we get asked about Data protection

When is an impact assessment mandatory?

When the processing is high risk: large-scale systematic monitoring, special category data, automated decisions with legal effects, or the cases on the Spanish DPA's list.

Do the 72 hours run from the incident or from detecting it?

From when the controller becomes aware of the breach (art. 33.1 GDPR). That's why recording the time of detection matters, not just the time of the incident.

How does Chile's Ley 21.719 differ?

It follows the GDPR standard with its own agency, a different timetable and penalties denominated in UTM. The platform keeps both regimes mapped onto the same register.

Vea Data protection running with their cases

A 30-minute guided demo on the real platform, or a one-hour assessment session with a consultant.

Other programmes from People and work
← The 21 programmes of the platform