Home › Frameworks › GDPR

GDPR compliance software, EU-native and audit-ready.

A breach register with a 72-hour countdown and the Article 33 notification fields, recurring GDPR controls, Article 30 records of processing and DPIA registers linked to vendors and risks, and a sub-processor register from Pro. EU-built, EU-hosted. Free for one framework; Basic from €29 a month.

When did you become aware?

Indicative. Clocks run from awareness; check your national law and the full calculator for options such as trust service providers or a fix date.

Article 6, 9Lawful basis records and special-category checks per processing activity.
Article 28Vendor and sub-processor register with DPA URLs and review dates (Pro and Enterprise).
Article 30Records of processing activities as a register, linked to the vendors involved.
Article 32Technical and organisational measures, with controls shared with ISO 27001 if both are enabled.

What is GDPR?

EU General Data Protection Regulation. Any organisation processing personal data of EU residents: SaaS vendors, e-commerce, healthcare, finance, public sector, education.

Who needs to comply

  • B2B SaaS companies serving EU customers
  • Health-tech, fintech and edtech with sensitive personal data
  • E-commerce and marketing operators handling EU consumer data
  • Public-sector and non-profit organisations under GDPR scope

Key GDPR controls covered by Dazr

Article 6, 9Lawful basis records and special-category checks per processing activity.
Article 28Vendor and sub-processor register with DPA URLs and review dates (Pro and Enterprise).
Article 30Records of processing activities as a register, linked to the vendors involved.
Article 32Technical and organisational measures, with controls shared with ISO 27001 if both are enabled.
Article 33-34Breach register with regulator-notification fields and 72-hour clock.
Article 35DPIA register linked to processing activities and risks, plus a recurring review.

What auditors look for

Supervisory authorities sample evidence: ROPA is up to date, breach register exists and is populated, sub-processor changes follow notice, DPIAs exist for high-risk processing. The platform holds each one.

How Dazr helps with GDPR

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. GDPR is one of its eleven frameworks, available from the free plan. In practice that means:

  • Keep records of processing in the Article 30 register, or link your existing ROPA and review it on cadence
  • Run the breach register with severity, timestamps, regulator-notification block and root cause
  • Maintain the sub-processor register with DPA URLs, review dates and contract-expiry flags (Pro and Enterprise)
  • Track DPIAs as recurring controls per high-risk processing activity
  • Hand the supervisory authority a clear audit trail when sampled

Back to the full Dazr Compliance overview › | Sign up free ›

GDPR questions, answered.

Does Dazr file the breach notification with the supervisory authority for me?

No. Dazr holds the Article 33 notification fields, timestamps every state change and shows a 72-hour countdown on the incident, but the filing itself goes through your authority's portal. Work out a deadline with the free breach deadline calculator at compliance.dazr.eu/tools/breach-deadline-calculator.

Can I use Dazr alongside an external DPO?

Yes. Record the DPO's name and email in the compliance profile, and add them as a member (or as a read-only auditor) so they see the registers and receive reminders.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption.

Is Dazr a sub-processor?

Yes. We are an Italian GDPR Article 28 sub-processor of yours; the DPA at /legal/dpa activates automatically when a workspace is created and we publish the current sub-processor list at /legal/subprocessors.

Ready to start your GDPR program?

Free for one user and one framework (ISO 27001, GDPR or NIS2). Basic €29/mo covers two of those for one user; Pro €99/mo covers five frameworks (from ISO 27001, GDPR, NIS2, NEN 7510, ISO 27701, ISO 22301 and SOC 2) for up to five users; Enterprise €499/mo adds all eleven. Self-serve via Mollie, prices excl. VAT. Custom is the only tier on a contract, priced on request.