GDPR
The GDPR catalog covers accountability, human intervention in automated decisions, data protection by design, records of processing, integrity, breach notification and DPIAs. The design resolves the classic conflict between Art 17 erasure and an immutable log: identities never enter a record, so erasure never needs to touch the evidence tables.
| Registry id | gdpr |
| Kind | regulation |
| Jurisdiction | EU |
| Instrument | Regulation (EU) 2016/679 |
| Catalog versions | 2026-09 from 2018-05-25 (current) — As applicable from 25 May 2018 |
| Verified against instrument | yes |
| Tagging key (compliance tags) | gdpr_art_30 |
Roles (frameworks.gdpr.role) |
controller, joint_controller, processor |
| Incident deadline rules | standard: 3 days |
| Retention floors | none at classification level |
| Obligations | 8 |
The Art 33 breach clock is 72 hours (standard: 3 days). The existing Art 30 export (GET /v1/admin/compliance/gdpr/article-30) is kept.
Deadline rules
Section titled “Deadline rules”Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.
| Rule | Deadline from became_aware_at |
|---|---|
standard |
3 days |
Deadlines are computed and shown, never enforced — see incidents.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
Accountability
Section titled “Accountability”art5-2-accountability · Art 5(2) · applies from 2018-05-25
The controller is responsible for, and able to demonstrate, compliance with the principles. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
| A documentation export exists for the active contract version, with its digest sealed. | recomputed | docs.technical_documentation {"framework": "gdpr"} |
A skeleton generated from the register and contract; its adequacy is not evaluated. |
Right to erasure against an immutable log
Section titled “Right to erasure against an immutable log”art17-erasure · Art 17 · applies from 2018-05-25
Personal data is erased on a valid request. Records carry no identities and no bodies, so erasure never needs to reach the evidence log. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The erasure procedure is declared; it touches no evidence table. | declared | profile.field_declared {"path": "frameworks.gdpr.erasure_procedure_reference"} |
Erasure of data held outside the platform is not observed. |
Human intervention in automated decisions
Section titled “Human intervention in automated decisions”art22-3-human-intervention · Art 22(3) · applies from 2018-05-25
Where decisions based solely on automated processing are permitted, the data subject can obtain human intervention and contest the decision. Applies to: profile flag core.automated_decisions_about_persons.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A human can override or stop the system. | recomputed | oversight.override_available |
Shows the controls exist and are assigned, not that the assigned people are competent. |
| Human approval requests were decided by humans (requested, decided, lapsed). | recomputed | oversight.exercised |
Records the fact of human disposition, not its quality. |
Data protection by design and by default
Section titled “Data protection by design and by default”art25-by-design · Art 25 · applies from 2018-05-25
Appropriate measures implement data-protection principles — here the never-enters allow-list and digest-only defaults. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The data-protection-by-design measures are declared. | declared | profile.field_declared {"path": "frameworks.gdpr.dpbd_reference"} |
The allow-list is a published design property; other measures are declared, not evaluated. |
Records of processing activities
Section titled “Records of processing activities”art30-records-of-processing · Art 30 · applies from 2018-05-25
A record of processing activities is maintained (the existing Art 30 export, now citing records). Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every processing call the tagging engine marked Art 30 produced a sealed record. | recomputed | access.sensitive_reads_recorded {"tag": "gdpr_art_30"} |
Counts actions the tagging engine marked; untagged traffic is not in the denominator. |
Security of processing — integrity and testing
Section titled “Security of processing — integrity and testing”art32-integrity-testing · Art 32(1)(b), (d) · applies from 2018-05-25
Ongoing integrity of processing systems and a process for regularly testing the effectiveness of measures. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The audit row chain over the window recomputes intact, or every gap is a declared prune. | recomputed | records.integrity_verified |
Detects alteration after the fact; it cannot show that a row was accurate when written. |
| Changes went through the lifecycle gate (replay suite before promotion). | recomputed | change.promotions_sealed |
Shows the gate was used; the sufficiency of the tests is not evaluated. |
Notification of a personal data breach
Section titled “Notification of a personal data breach”art33-breach-notification · Art 33 · applies from 2018-05-25
The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
| Breaches were notified within 72 hours of awareness. | recomputed | incidents.reported_within_deadline {"framework": "gdpr"} |
Deadlines are computed and shown, not enforced; awareness time is operator-entered. |
Data protection impact assessment
Section titled “Data protection impact assessment”art35-dpia · Art 35 · applies from 2018-05-25
A DPIA is carried out where processing is likely to result in a high risk to rights and freedoms. Applies to every system for which the framework is active.
Review: Whether a DPIA is required depends on the processing — record the determination.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| A current DPIA is on file. | recomputed | evidence.pointer_on_file {"kind": "dpia"} |
A pointer to a document produced outside the platform; its content is not evaluated. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

