Data mapping & inventories
Build and maintain a complete inventory of personal data across your organisation — the foundation of GDPR compliance.
- Discover data sources: Use the built-in scanner or manually add systems (CRM, HR files, marketing tools).
- Classify data elements: Tag fields (name, email, health data, etc.) and identify special categories.
- Map data flows: Connect sources to business processes, departments and third parties.
- Link to legal basis & retention: Assign lawful basis and retention period per purpose.
- Review & publish: Validate with Data Protection Officer and mark inventory as “active”.
📌 Inventory best practices
Set up automated reminders to refresh data maps.
Limit editing to compliance leads, view-only for auditors.
Each change is logged for audit trail.
MODULE · POLICY GENERATOR
Policy and document generator
Generate GDPR‑compliant privacy policies, DPA, consent forms and more in minutes — tailored to your SME.
- Select document type (Privacy policy, Cookie policy, Records of processing, etc.)
- Fill the dynamic questionnaire: company info, purposes, third parties, contact details.
- Preview and adjust language (plain English / legal style).
- Export as PDF, DOCX or HTML — or publish directly to your website.
Available templates
- 📃 Privacy policy (Art. 12-14)
- 🍪 Cookie policy
- 🤝 Data Processing Agreement (DPA)
- ✍️ Consent forms (opt-in boxes)
- 📋 Record of processing (Article 30)
- ⚠️ Breach notification template
MODULE · DPIA
DPIA & risk assessment workflows
Perform Data Protection Impact Assessments for high‑risk processing, following WP29 guidelines step‑by‑step.
- Trigger: system flags processing that requires DPIA (or manual creation).
- Describe processing: nature, scope, context, purposes.
- Assess necessity & proportionality: pre-built checklists.
- Identify risks: to rights and freedoms (categories: unauthorized access, data modification, etc.).
- Mitigation measures: select technical/organisational controls.
- Residual risk scoring: low/medium/high — if high, consult supervisory authority.
- Approve & sign off: DPO and controller sign digitally.
📊 Risk scoring matrix
The module uses a 5x5 matrix (likelihood vs. severity) and suggests mitigation. You can override but justification is stored.
MODULE · VENDOR
Vendor / processor management
Centralise all your processors, sub‑processors and third‑party contracts. Automate DPA signature tracking.
✍️ Step‑by‑step: processor onboarding
- Create vendor profile → enter basic info.
- Link processing activities (from ROPA) handled by this vendor.
- Upload signed DPA and set review date.
- Schedule annual re‑assessment (automated task).
- If sub‑processors are used, list them and track approval.
MODULE · TRAINING
Training & awareness module
Assign GDPR courses to employees, track completion, and prove staff awareness (required under accountability).
📚 Built‑in courses
- GDPR basics for all staff (15 min)
- Data subject rights (for support teams)
- Security & breach reporting (advanced)
- Privacy by design (developers)
📝 How to assign training
- Go to Training dashboard → “Create assignment”.
- Select employees (by department, role or individually).
- Choose course(s) and deadline.
- System sends email invitations and reminders.
- Monitor completion percentage in real‑time.
MODULE · TASK
Task management & reminders
Never miss a GDPR deadline: automated tasks for DSR, breach reporting, policy review, and more.
⚙️ Creating custom tasks
- Click “Add task” from the main dashboard.
- Set title, assignee, due date, and priority.
- Attach related item (e.g., a DPIA or vendor).
- Choose reminder schedule (email, in‑app, Slack/Teams webhook).
MODULE · LEGAL BASIS
Legal basis & purpose registry
Central register of all processing purposes with the corresponding lawful basis (Art. 6) and, if applicable, special category condition (Art. 9).
Structure of an entry
- Purpose name (e.g., “direct marketing”, “payroll”)
- Description – why and how data is used
- Legal basis (consent, contract, legitimate interest, legal obligation, vital interest, public task)
- For legitimate interest: LIA test summary
- Data categories used (linked to data inventory)
- Retention period / criteria
📌 Linking to other modules
The purpose registry feeds into your consent banners (purposes), privacy policy generator, and ROPA. Changes propagate after approval.
MODULE · COOKIE / TRACKER CONTROLS
Cookie banner + tracker enforcement
The app now provides a complete implementation flow: discover trackers, categorize them, generate loader snippet, and enforce visitor choices at runtime.
- Open Tracker scan and run first pass (plus optional headless second pass).
- Categorize detected resource URLs as essential, functional, marketing, or performance.
- Save categories and copy the generated website embed snippet from the tracker scan page.
- Paste
loader.jsfirst in your website<head>, thencookie-banner.js. - Verify that non-essential requests are blocked until visitors opt in.
Stores scan runs, discovered URLs, and per-seat categorization work.
Admin-maintained global matching rules for URL substrings and inline regex patterns.
Runtime request filtering by visitor consent category on the customer website.
Category mapping used at runtime
- Essential: always allowed.
- Functional: allowed only when functional consent is enabled.
- Analytics: allowed only when analytics consent is enabled.
- Marketing: allowed only when marketing consent is enabled.
- Performance from tracker scans is mapped to Analytics in loader.js.
MODULE · TEMPLATES
Templates library for SMEs
A rich collection of ready‑to‑use GDPR templates designed for small and medium businesses. Customise and reuse.
📁 Available template categories
- ✅ Data subject request forms
- ✅ Subject access request log
- ✅ Consent records (spreadsheet style)
- ✅ Data breach register
- ✅ Employee GDPR handbook
- ✅ Records of processing (ROPA) starter
- ✅ Legitimate interest assessment (LIA) form
- ✅ DPIA screening checklist
- ✅ Vendor due diligence questionnaire
- ✅ Privacy notice for employees
📎 How to use
- Browse library by module (DPIA, vendor, etc.).
- Preview template online.
- Click “Use this template” – it creates a new record in the corresponding module pre‑filled.
- Adapt fields and save as your own.
SME templates are drafted by legal experts and updated quarterly.
MODULE · SUPPORT
Support tickets & customer assistance
Customers can submit support tickets from the in-app Support page while logged in. The form pre-fills the account email (read-only) and sends tickets to the support team.
- Open Support from the Admin section in the sidebar.
- Review account email (displayed and locked).
- Enter subject, urgency, and detailed message.
- Submit ticket; system emails
support@gdprcompliancehub.com. - Ticket is also stored in the platform database with delivery status and reference.
Support page requires valid session and redirects unauthenticated users to login.
Uses the platform notification service and company/global SMTP configuration.
Each ticket stores requester, urgency, page context, and sent/failed delivery state.
Frequently asked questions
Yes. Each module has an “Export” button (PDF, CSV, or Excel). For full audit package, use the “Audit export” in the main dashboard.
Tasks are assigned to individual seat holders (users). They receive notifications via email and on‑dashboard. You can also assign to a role (e.g., DPO) and any seat with that role can pick it up.
Yes. The generator asks for your country (or countries) of establishment and adapts recitals accordingly (e.g., French CNIL specifics, German BDSG).