Skip to content

GDPR

The GDPR catalog covers accountability, human intervention in automated decisions, data protection by design, records of processing, integrity, breach notification and DPIAs. The design resolves the classic conflict between Art 17 erasure and an immutable log: identities never enter a record, so erasure never needs to touch the evidence tables.

Registry id gdpr
Kind regulation
Jurisdiction EU
Instrument Regulation (EU) 2016/679
Catalog versions 2026-09 from 2018-05-25 (current) — As applicable from 25 May 2018
Verified against instrument yes
Tagging key (compliance tags) gdpr_art_30
Roles (frameworks.gdpr.role) controller, joint_controller, processor
Incident deadline rules standard: 3 days
Retention floors none at classification level
Obligations 8

The Art 33 breach clock is 72 hours (standard: 3 days). The existing Art 30 export (GET /v1/admin/compliance/gdpr/article-30) is kept.

Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.

Rule Deadline from became_aware_at
standard 3 days

Deadlines are computed and shown, never enforced — see incidents.

Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.

art5-2-accountability · Art 5(2) · applies from 2018-05-25

The controller is responsible for, and able to demonstrate, compliance with the principles. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The tenant log’s tree heads covering the window were countersigned by an independent witness. recomputed records.witnessed A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested.
A documentation export exists for the active contract version, with its digest sealed. recomputed docs.technical_documentation {"framework": "gdpr"} A skeleton generated from the register and contract; its adequacy is not evaluated.

art17-erasure · Art 17 · applies from 2018-05-25

Personal data is erased on a valid request. Records carry no identities and no bodies, so erasure never needs to reach the evidence log. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The erasure procedure is declared; it touches no evidence table. declared profile.field_declared {"path": "frameworks.gdpr.erasure_procedure_reference"} Erasure of data held outside the platform is not observed.

art22-3-human-intervention · Art 22(3) · applies from 2018-05-25

Where decisions based solely on automated processing are permitted, the data subject can obtain human intervention and contest the decision. Applies to: profile flag core.automated_decisions_about_persons.

Statement Basis Resolver Does not show
A human can override or stop the system. recomputed oversight.override_available Shows the controls exist and are assigned, not that the assigned people are competent.
Human approval requests were decided by humans (requested, decided, lapsed). recomputed oversight.exercised Records the fact of human disposition, not its quality.

art25-by-design · Art 25 · applies from 2018-05-25

Appropriate measures implement data-protection principles — here the never-enters allow-list and digest-only defaults. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The data-protection-by-design measures are declared. declared profile.field_declared {"path": "frameworks.gdpr.dpbd_reference"} The allow-list is a published design property; other measures are declared, not evaluated.

art30-records-of-processing · Art 30 · applies from 2018-05-25

A record of processing activities is maintained (the existing Art 30 export, now citing records). Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every processing call the tagging engine marked Art 30 produced a sealed record. recomputed access.sensitive_reads_recorded {"tag": "gdpr_art_30"} Counts actions the tagging engine marked; untagged traffic is not in the denominator.

Security of processing — integrity and testing

Section titled “Security of processing — integrity and testing”

art32-integrity-testing · Art 32(1)(b), (d) · applies from 2018-05-25

Ongoing integrity of processing systems and a process for regularly testing the effectiveness of measures. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
The audit row chain over the window recomputes intact, or every gap is a declared prune. recomputed records.integrity_verified Detects alteration after the fact; it cannot show that a row was accurate when written.
Changes went through the lifecycle gate (replay suite before promotion). recomputed change.promotions_sealed Shows the gate was used; the sufficiency of the tests is not evaluated.

art33-breach-notification · Art 33 · applies from 2018-05-25

The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
An incident register is kept and no open incident is past its deadline. recomputed incidents.register_exists Shows incidents someone entered; an incident nobody recorded cannot be counted.
Breaches were notified within 72 hours of awareness. recomputed incidents.reported_within_deadline {"framework": "gdpr"} Deadlines are computed and shown, not enforced; awareness time is operator-entered.

art35-dpia · Art 35 · applies from 2018-05-25

A DPIA is carried out where processing is likely to result in a high risk to rights and freedoms. Applies to every system for which the framework is active.

Review: Whether a DPIA is required depends on the processing — record the determination.

Statement Basis Resolver Does not show
A current DPIA is on file. recomputed evidence.pointer_on_file {"kind": "dpia"} A pointer to a document produced outside the platform; its content is not evaluated.