OnwynStandards › GDPR — Operational Compliance

Regulation · 2016/679

GDPR — Operational Compliance

The General Data Protection Regulation applies to essentially every company handling personal data of people in the EU — customers, users, employees, prospects. This pack focuses on the operational program a company must run, not the legal theory: knowing your processing, having lawful bases, honoring individual rights on deadline, keeping processors under contract, securing the data, and being ready for the 72-hour breach notification. Fines scale to 4% of global turnover, but the more common commercial pain is failing customer due-diligence checks.

21
Requirements
6
Areas
18
Recommended documents
2
Mapped frameworks
Start GDPR free Have us do it instead

What this standard asks for

Every requirement in GDPR — Operational Compliance, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Accountability & records

5 requirements

  • Art. 5Processing principles and accountability
  • Art. 30Records of processing activities
  • Art. 5(1)(e)Retention and deletion
  • Art. 37-39Data protection officer or responsible ownership
  • Art. 25Data protection by design and by default

Transparency & lawful basis

3 requirements

  • Art. 6Lawful basis for each processing purpose
  • Art. 7Consent management
  • Art. 13-14Privacy notices and information duties

Data subject rights

5 requirements

  • Art. 12Handling requests — process and deadlines
  • Art. 15Right of access
  • Art. 16-17Rectification and erasure
  • Art. 18-21Restriction, portability and objection
  • Art. 22Automated decision-making safeguards

Processors & transfers

2 requirements

  • Art. 28Processor management and data processing agreements
  • Ch. VInternational data transfers

Security of processing

3 requirements

  • Art. 32Security of processing
  • Art. 32(4)Staff access and confidentiality
  • Art. 35-36Data protection impact assessment

Breach management

3 requirements

  • Art. 33Breach notification to the supervisory authority
  • Art. 34Communication of breaches to affected individuals
  • Art. 33(2)Processor breach support obligations

The documents you will end up with

The recommended document set for GDPR — Operational Compliance — 18 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

Records of Processing Activities

The inventory of what personal data you hold, why, who you share it with and how long you keep it — named in Article 30 and the first thing a regulator asks for.

Privacy Notice

The public explanation of what you do with people's data and what rights they have, written so a normal person can follow it.

Lawful Basis Register

For each processing purpose, which lawful basis you rely on and the reasoning behind it — including the balancing test where it is legitimate interests.

Consent Procedure and Records

How consent is asked for, what you store to prove it was given, and how someone withdraws it as easily as they gave it.

Retention and Deletion Schedule

Sets out how long you keep each kind of record, who decided that, and how it actually gets deleted when the time is up.

Data Subject Request Procedure

What happens from the moment someone asks for their data: who handles it, how identity is checked, what you send back, and the one-month clock.

DPO Appointment or Privacy Ownership Record

Who is accountable for data protection, what independence and resources they have, and how people reach them.

Privacy by Design Standard

The rules product and engineering follow so new features collect the minimum and default to the private setting.

Automated Decision-Making Safeguards

Where software decides something significant about a person: the safeguards in place and how they can ask a human to look again.

Data Processing Agreement Template

The Article 28 contract you put in place with every supplier who touches personal data on your behalf, and the terms you accept when a customer sends you theirs.

International Transfer Policy and Clause Pack

Which countries personal data may go to, on what legal footing, and the standard clauses or adequacy decision each transfer rests on.

Transfer Impact Assessment

For transfers relying on standard clauses: what you checked about the destination country's laws and what extra protection you added.

Data Flow Map

A picture of where personal data enters, where it is stored, and where it leaves — the thing that makes the processing records tractable.

Technical and Organisational Measures Document

The description of how you actually protect personal data, which customers ask for in due diligence and which you attach to processing agreements.

Staff Confidentiality and Access Rules

The rule that staff only see the personal data their job needs, and the confidentiality undertaking that backs it up.

DPIA Procedure and Template

When a project needs a data protection impact assessment, what the assessment has to answer, and what happens when the residual risk stays high.

Personal Data Breach Register

The record of every personal data breach, its effects and what you did — required whether or not the breach was ever reportable.

Breach Response Procedure

Who assesses a suspected breach, how the 72-hour clock is judged, when individuals have to be told, and what a processor owes its controller.

Work that counts twice

GDPR — Operational Compliance overlaps with 2 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start GDPR today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.