GDPR

One workspace for your data-protection records: subject requests, processing activities, impact assessments, processor agreements, transfers, retention and consent.

GDPR (the European Union's data-protection law) places record-keeping duties on any organisation that handles personal data. This module gathers that work under one GDPR entry in the sidebar. It does not replace your legal team's judgement; it gives you the records and the audit trail to show a supervisory authority (your data-protection regulator) that you are accountable.

This chapter is the module reference. For the most common journey worked end to end — a person asking for their data, from inbox to closure — see the full walkthrough in Scenario: handling a data-subject request; HR staff who receive such requests first should start with the HR scenario.

If you do not see GDPR in the sidebar

The module is provisioned per tenant. When it is not enabled the entry is hidden and the registers cannot load. Ask your account manager to switch it on.

Who uses it

A Viewer and a Contributor can open every register. Creating and editing records needs Manager or Admin. Those buttons are absent rather than disabled for lower roles, which is why the register captures here show no Add button: they were taken as a Contributor. A Contributor may still acknowledge or refuse an existing subject request; deciding a DPIA needs the approval right only Manager and Admin hold.

What's on this screen

The landing page at /gdpr is headed GDPR Compliance. The Deadline Alerts panel fills the first screen: five pills — All, DSR, DPA, Consent, Transfer — above rows that each name a record and the party it concerns, with the due date underneath and a coloured days marker on the right. Scrolling on brings four metric cards — Processing Activities, Data Subject Requests, Data Processing Agreements, Consent Records — then the Quick Actions tiles (Handle DSR, Start DPIA, Add Activity, Transfers), Recent Subject Requests and a Compliance Checklist. The module has one sidebar entry, so those cards and tiles are how you reach its registers.

  1. In the sidebar, open PRIVACY & WHISTLEBLOWING and choose GDPR. The landing page opens and the alerts panel loads.
  2. Select a pill in Deadline Alerts. All is active on arrival; another narrows the feed to that one kind of record.
  3. Read down the list. For a subject request, the line gives the right being exercised and the person's email address.
  4. Treat red markers first — that date has passed. This workspace opens with an access request marked 380 days overdue.
  5. The ? in the top bar opens this guide inside Aegis. Scroll on and select a card or tile to open the register behind it.
The GDPR Compliance landing page with the Deadline Alerts panel and its filter pills — /gdpr.
The GDPR Compliance landing page with the Deadline Alerts panel and its filter pills — /gdpr.
Alert lines are signals, not links

The rows are read-only. Open the register yourself and act there.

Handling a data subject request

A data subject request (DSR) is a person asking to see, correct or delete the data you hold about them — or to restrict it, object, or receive a portable copy. The queue at /gdpr/dsr carries All Types and All Statuses dropdowns and an Overdue Only tickbox above a table of Type, Subject, Status, Requested, Due Date and colour-coded Time Left.

  1. Open the queue from the Data Subject Requests card or the Handle DSR tile. The sidebar entry under PRIVACY & WHISTLEBLOWING returns you to the landing page.
  2. Narrow the queue with the dropdowns or the tickbox. The filters combine.
  3. Read Time Left to decide what comes first. The capture shows an acknowledged access request with 21 days left beside refused rows showing a dash.
  4. Select a row. The request opens on its own page with a details grid and a Fulfillment stepper: PendingAcknowledgedVerifiedIn ProgressCompleted or Refused.
  5. Select Acknowledge Request (shown only while Pending). Aegis records the acknowledgement and its operator before attempting the notification. The delivery panel remains available after reload: send a pending notification only if no attempt has started. An uncertain or stalled attempt is never resent. Check the original outcome or contact the person through another channel, then record your confirmation and a note. Human confirmation is labelled separately from the mail service’s acceptance.
  6. To turn a request down, select Refuse, type the Refusal Reason and select Confirm Refusal. Acknowledge and refuse are the only two transitions the page offers today (see The AI assist below), so send your answer through your normal channel and file it under COMPLIANCEEvidence.
  7. If the request uncovers a personal-data breach, log it under SECURITY INCIDENTS. The 72-hour notification clock is handled there.
  8. Open AUDITAudit Log to see who moved a request, when, and to what.
The data subject request queue with its type and status filters and the Time Left countdown — /gdpr/dsr.
The data subject request queue with its type and status filters and the Time Left countdown — /gdpr/dsr.
Status What it means
Pending Logged; no acknowledgement sent
Acknowledged Receipt recorded; check the separate notification delivery status
Verified Identity confirmed by the recorded method
In Progress Being worked on
Completed A response is recorded; final
Refused Turned down with a recorded reason; final
Expired Set automatically once the deadline passes an open request

Logging a new request

With Manager or Admin rights the queue shows New Request, which opens the full-page form at /gdpr/dsr/new, headed New Data Subject Request. Its subtitle says it plainly: the GDPR response clock starts on creation.

  1. Choose the Request Type. Access is preselected, and the line under the box explains the right each type exercises — here Article 15.
  2. Type the Data Subject Email. It is the address the request came from, used to verify identity and to send the response.
  3. Record the Verification Method — how the person's identity was confirmed, if it already has been.
  4. Add Notes for whoever handles the request. They are internal, never shared with the data subject.
  5. Select Create Request at the foot of the form. The request saves as Pending with a due date 30 days out, and its detail page opens.
The full-page form for logging a new data subject request — /gdpr/dsr/new.
The full-page form for logging a new data subject request — /gdpr/dsr/new.
The deadline counts from the date you log it

Aegis sets the due date 30 days from the moment the record is created, not from the date the request arrived. If it reached you earlier, note the real received date so your team manages the true legal deadline. The acknowledgement is the only message Aegis sends.

Building the record of processing activities

A record of processing activities (ROPA) is the map, required by Article 30, of every activity in which you process personal data. The page at /gdpr/processing has a Search activities… box and an All Legal Bases dropdown on the left, Export ROPA on the right, and a table of Name, a coloured Legal Basis badge, Data Categories, a Special Data flag and Retention.

  1. Open the register from the Processing Activities card. PRIVACY & WHISTLEBLOWINGGDPR in the sidebar takes you back to the landing page.
  2. Search by name, or pick a legal basis. The seeded rows include Employee Benefits on Contract, Cookie Consent on Consent and DSAR Handling on Legal Obligation.
  3. Select a row to open the activity: purposes, data categories, recipients, retention and safeguards, plus a Related Data block counting attached consents and transfers. A Yes under Special Data means Article 9 special-category data.
  4. Select Export ROPA. A dialog offers JSON, CSV or PDF; choose a format and it downloads.
  5. With Manager or Admin rights, Add Activity sits beside the export button and opens the form for name, legal basis, purposes, categories, recipients, retention and safeguards.
  6. File the export under COMPLIANCEEvidence so an auditor can find the version you relied on.
The processing-activities register with legal-basis badges, the Special Data flag and the Export ROPA button — /gdpr/processing.
The processing-activities register with legal-basis badges, the Special Data flag and the Export ROPA button — /gdpr/processing.

Assessing high-risk processing

A data protection impact assessment (DPIA) is the analysis Article 35 requires before high-risk processing. The page at /gdpr/dpia opens with a When is a DPIA Required? panel listing four triggers, then a count — 12 assessments in the capture — with Start from Processing Activity beside it, then the table: Processing Activity, Status, Residual Risk, Consultation, Approved.

  1. Open PRIVACY & WHISTLEBLOWINGGDPR, then take the Start DPIA tile.
  2. Read the trigger panel first. If none of the four applies, record why instead.
  3. Open an assessment: necessity, proportionality, risks and mitigations, and a residual risk of Low, Medium, High or Critical. Where Article 36 prior consultation applies, Consultation reads Required.
  4. Decide it. With Manager or Admin rights the detail page carries Approve DPIA and Reject DPIA; a rejection asks for a reason. A decided assessment cannot be decided again.
  5. A high residual risk you accept rather than mitigate belongs in RISKS as well. Aegis does not raise the risk for you.
  6. Keep the signed write-up under COMPLIANCEEvidence.
The DPIA register with the trigger-conditions panel and the assessments table — /gdpr/dpia.
The DPIA register with the trigger-conditions panel and the assessments table — /gdpr/dpia.

Creating an assessment

Start from Processing Activity — or, for Managers and Admins, Create DPIA — leads to the full page at /gdpr/dpia/new, because every assessment is anchored to one activity. Build the ROPA first.

  1. Select the Processing activity the assessment covers. The dropdown lists your recorded activities.
  2. Necessity: why the processing is necessary for the stated purpose.
  3. Proportionality: how it is proportionate to that purpose.
  4. Under Risks & Mitigation, list the Identified risks to data subjects — one per line.
  5. Add the Mitigation measures below, one per line, then save. The assessment opens on its detail page as Pending Review, ready for a decision.
The full-page DPIA creation form — /gdpr/dpia/new.
The full-page DPIA creation form — /gdpr/dpia/new.

Recording processor agreements

A data processing agreement (DPA) is the contract Article 28 requires with every supplier that processes personal data for you. The page at /gdpr/dpa has a single All Statuses dropdown above Vendor, Status, Version, Signed Date and Expiry Date. The capture shows the empty starting state: No data processing agreements found.

  1. Create the supplier first. Vendors live under RISKSVendors, and an agreement must point at a vendor record that already exists.
  2. Return to the landing page and select the Data Processing Agreements card. The register opens on the empty table shown here.
  3. With Manager or Admin rights, Add Agreement appears beside the filter: vendor, status, DPA and SCC version, signed and expiry dates, the breach-notification window in hours, and whether encryption, audit rights and location restrictions are agreed.
  4. Use All Statuses to work one slice — Draft, Pending Signature, Signed, Active, Expired or Terminated.
  5. On renewal, open the row and update the dates. The expiry date feeds the deadline alerts on the landing page.
  6. Keep the signed contract itself under COMPLIANCEEvidence. This register holds facts about the document, not the document.
The processor-agreement register in its empty state — /gdpr/dpa.
The processor-agreement register in its empty state — /gdpr/dpa.

Transfers out of the EEA

Transfers record when personal data leaves the European Economic Area and the safeguard that authorises it. The page at /gdpr/transfers opens with a Transfer Mechanisms reference panel — adequacy decisions, standard contractual clauses (2021 version), binding corporate rules and Article 49 derogations — then a Filter by country… box and an All Mechanisms dropdown above Destination, Mechanism, Processing Activities, Last Review Date and Next Review Date. The capture shows it empty: No international transfers found.

  1. Open the register with the Transfers tile, which sits under PRIVACY & WHISTLEBLOWINGGDPR in the sidebar.
  2. Read the mechanisms panel first: the one you pick sets what the record must prove.
  3. Open a saved transfer and scroll to Transfer Impact Assessment (TIA). The section appears only where your licence includes the GDPR automation feature. Run TIA queues an AI-assisted adequacy and Schrems II analysis, which returns an overall risk, a confidence figure and recommendations.
  4. Keep Next Review Date current — it is what raises a transfer in the alerts.
  5. Use Copy, Export PDF or Export DOCX on the TIA, and file the result under COMPLIANCEEvidence.
  6. Unsure which mechanism applies? The ? in the top bar opens this chapter inside Aegis.
The international-transfers register with the mechanisms reference panel, in its empty state — /gdpr/transfers.
The international-transfers register with the mechanisms reference panel, in its empty state — /gdpr/transfers.

Recording a transfer

With Manager or Admin rights, Add Transfer opens the full page at /gdpr/transfers/new, headed New International Transfer, split into Transfer Information and Safeguards & Risk.

  1. Select the Processing Activity the transfer belongs to.
  2. Select the Destination Country. Choosing Other adds a free-text field for the country name.
  3. Select the Transfer Mechanism. Standard Contractual Clauses is preselected, with the Article 46(2)(c) reference beneath; an adequacy decision asks for its reference instead.
  4. Confirm the SCC Version2021 SCCs (Current) unless you have a legacy set still in force.
  5. Name the Recipient, and fill Data Categories and Legal Basis alongside.
  6. Under Safeguards & Risk, describe the Supplementary Measures (encryption, pseudonymisation) and the risk summary, then save. The transfer opens on its detail page.
The full-page form for recording an international transfer — /gdpr/transfers/new.
The full-page form for recording an international transfer — /gdpr/transfers/new.

Retention schedules

Retention defines how long each category of personal data may be kept, as Article 5(1)(e) requires. The register is at /gdpr/retention and is reached by address — it has neither a card nor a tile on the landing page. The table lists policy name, retention period, data categories, disposal method and review date, with an All Methods filter and, for Managers and Admins, Add Policy. Each policy records the retention criteria, a disposal method — Deletion, Anonymization or Archival — and a next review date. Aegis holds the schedule but deletes nothing when a period ends; the disposal records that prove you followed it belong under COMPLIANCEEvidence.

Keeping consent records

Where consent is your lawful basis, Article 7 requires you to show it was freely given, specific, informed and unambiguous. The page at /gdpr/consent opens with a note saying plainly that consent records normally come from your own application's consent collection, and that this view is for managing and withdrawing them. A Search by email… box, an All Types dropdown and an Active Only tickbox — ticked by default — sit above Subject, Type, Purposes, Given, Status and Actions. The capture shows it empty: No consent records found.

  1. Open the register from the Consent Records card, reached through PRIVACY & WHISTLEBLOWINGGDPR in the sidebar.
  2. Search by email address, or untick Active Only to bring withdrawn records back. The tickbox filters on withdrawal alone, so a consent past its expiry date that was never withdrawn stays in the list either way.
  3. Select a row to read the full record: activity, purposes, consent type, the proof and version you recorded, and the metadata captured at the time. Its badge reads Active, Withdrawn or Expired.
  4. With Manager or Admin rights, Record Consent logs one by hand — email, activity, type, purposes, dates, proof and version.
  5. To process a withdrawal, select Withdraw in Actions and confirm. The status becomes Withdrawn, the time is stamped, and it cannot be undone.
  6. A withdrawal is a record, not an instruction to your systems: stop the processing where it happens, then use AUDITAudit Log to prove when.
  7. The wording and version shown to the person is the proof behind the record — keep it under COMPLIANCEEvidence.
The consent register with its search, type filter and Active Only tickbox, in its empty state — /gdpr/consent.
The consent register with its search, type filter and Active Only tickbox, in its empty state — /gdpr/consent.

The AI assist

Two AI actions are live in this module where your licence includes them. Draft with AI on a DPIA proposes the Article 35 sections — necessity, proportionality, risks and mitigations — from the linked processing activity, and warns you before replacing an assessment you already have. Run TIA on a transfer produces the adequacy and Schrems II analysis described above. Both are Manager or Admin actions and both consume the tenant's AI credits. The AI drafts and a person decides: you review, edit and save, and the assessor of record is always a named human.

A third surface is built but not yet connected. The AI-Drafted Response panel on a subject request would show a suggested reply with a confidence figure, but no draft yet reaches the record, so the panel does not appear and a request cannot be moved to Verified, In Progress or Completed from the page. Treat subject-request responses as entirely manual work for now.

Tips and limits

Where this connects

A personal-data breach must reach the supervisory authority within 72 hours where required — handle and time-stamp it in Incidents. Agreements depend on Vendors; residual risks you accept from a DPIA belong in Risks; contracts, exports and write-ups belong in Evidence. The cross-system lookup that would gather what you hold about a person draws on the systems joined up in Connectors. Who may do what here follows Part 3 — What each role can do, and the whole journey runs end to end in When someone asks for their data.