Solutions · GDPR

Prove GDPR compliance to any regulator, without it consuming your team.

GDPR is an accountability regime: it is not enough to comply, you have to show it, on demand, while your processing keeps changing underneath you. Acuna runs GDPR as a live programme. Your records of processing stay current, your DPIAs and processor checks come from one connected record, data subject requests are handled on time, and the evidence a regulator asks for already exists. Hosted in Switzerland.

Swiss-hosted privacy dataGDPR, Swiss FADP, and UK GDPR on one record50+ frameworks on one core

HOW ACUNA HELPS WITH GDPR

Acuna is GDPR compliance software built into a wider GRC platform. It keeps your records of processing activities (ROPA) current, runs data protection impact assessments, processor assessments, and transfer assessments from one shared record, handles data subject requests through a dedicated intake, and lets you scope a breach inside the 72-hour window. Because it maps to 50+ frameworks on one core, the same processing activity can carry GDPR, Swiss FADP, and UK GDPR with independent legal bases, and privacy connects to the controls, risk register, and vendor records the rest of your programme already uses. Privacy data is hosted in Switzerland.

Stop running GDPR as an annual scramble.

For most teams, GDPR lives in spreadsheets and a privacy tool that talks to nothing else. The ROPA is current the day it is approved and stale by the next meeting. DPIAs, processor agreements, and transfer assessments are filled in separately each time. Data subject requests arrive in a shared inbox. And when a regulator or an auditor asks, the evidence gets reconstructed by hand. The cost is not just time; it is the risk of an answer you cannot defend. Acuna closes the gap between what you have documented and what is actually true, and keeps it closed.

The four core panes, plus the two extensions GDPR needs.

Each component below does a specific GDPR job. The detail lives on its own page; this is the GDPR-specific path through each one.

Map GDPR's requirements, including the Article 32 security obligations, to your controls once, and see them reflected across every other framework you operate, so you are not maintaining a separate GDPR crosswalk by hand.

Attach owners and evidence to your GDPR controls and records, so the Article 30 records, the Article 28 processor agreements, and the Article 32 measures are not just written down but owned, evidenced, and current.

Run review cycles on processing activities, recurring assessment reviews, and breach readiness on a cadence, so your programme stays current between audits instead of drifting.

Pull the Article 30 export, the DPIA records, the breach log, and the evidence of accountability as a report, not a reconstruction, when the supervisory authority or an auditor asks.

Framework-specific extension
Data PrivacyExtension

The privacy operations module: processing activities recorded with their data subjects, assets, processors, and legal bases together; DPIA, processor, and transfer assessments drawn from that shared context; data subject requests handled through a dedicated intake; and breach impact traced across the connected records.

GDPR makes you responsible for the processors you use. Score and assess them, monitor their security continuously, and keep the documented due diligence Article 28 expects, on the same vendor record your security programme already uses.

What a live programme unlocks, and what the scramble costs.

What a live GDPR programme unlocks vs What the scramble costs
What a live GDPR programme unlocksWhat the scramble costs
Accountability you can show: records, owners, evidence, and history on one connected system, so the regulator pack already exists when asked.A ROPA that is out of date the moment a new processing activity starts.
A ROPA that reflects today's processing, not the state it was in at the last annual review.Evidence reconstructed by hand each time a regulator, auditor, or enterprise buyer asks.
GDPR, Swiss FADP, and UK GDPR governed on one record with independent legal bases, rather than duplicate workspaces that drift apart.Data subject requests that miss the one-month deadline when the inbox is a shared mailbox.
Breach readiness: scope and notify inside 72 hours because the connected records show which systems, individuals, and processors are affected.A 72-hour breach window that is too tight to scope without connected records.

We will not quote you an invented ROI figure. The real calculation is the regulator or auditor request that arrives next quarter, and whether the answer is a report you already have or a reconstruction that takes a week.

Run your own numbers.

GDPR Art. 83 sets the fine ceiling at the higher of a fixed floor or a percentage of global annual turnover. Use your own revenue below to see your exposure, anchored against real enforcement decisions.

Your organisation

Annual global revenue

EUR / CHF approximately at parity for Swiss organisations

€ 50M

€1M€5B

Your maximum fine exposure

Art. 83(5) — serious violations

Basic principles · lawful basis · data subject rights · international transfers

€20M

max(€20M, 4% of global annual turnover)

Art. 83(4) — procedural violations

Processor obligations · DPO requirements · data protection by design

€10M

For scale — real Art. 83(5) enforcement decisions

H&M

Hamburg DPA · 2020 · Inadequate legal basis for processing employee data

€35M

WhatsApp / Meta

Ireland DPC · 2021 · Transparency and information obligations (ROPA)

€225M

Meta

Ireland DPC · 2023 · Unlawful data transfers to the US (SCCs)

€1.2B

Acuna starts from

CHF 5'388 / year — connected privacy, risk, and compliance

3.7K×

your Tier 2 cap

These are the legal maximums under Art. 83 GDPR, not predictions. Actual fines depend on severity, duration, cooperation, previous violations, categories of personal data, and supervisory authority discretion. Fine amounts are in EUR as defined in GDPR Art. 83. Reference fines are publicly documented (GDPR Enforcement Tracker). Use this to frame the board conversation, not to quantify your specific exposure.

Swiss-hosted, connected, and built by operators.

Privacy data is hosted in Switzerland, which matters when data residency is part of the compliance question rather than an afterthought. The processors in your ROPA are the same vendors your third-party risk programme assesses. Your DPIA risks belong in the same risk register as everything else. GDPR that connects to the rest of your programme is GDPR you can keep current and defend, rather than a separate tool to reconcile at audit time.

  1. Swiss-hosted privacy data. Data residency is part of the compliance answer, not a side note.

  2. Connected, not a silo. Vendors, controls, and risk records are shared across your whole programme.

  3. GDPR, Swiss FADP, and UK GDPR on one record with independent legal bases and review cycles.

  4. Built for DPOs, compliance leaders, and CISOs by practitioners who have operated privacy programmes.

  5. 50+ frameworks on one core. One organisation price, no per-seat fees.

GDPR: common questions.

Related answers

Questions practitioners ask.

What is a DPIA under GDPR?

A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when processing is likely to result in a high risk to the rights and freedoms of individuals. This includes systematic profiling with legal effects, large-scale processing of special categories of data, and systematic monitoring of public areas. A DPIA must describe the processing, assess necessity and proportionality, identify risks, and define mitigating measures. If residual risk remains high after mitigation, the controller must consult the supervisory authority under Article 36. DPIA workflows are on the Acuna Data Protection module roadmap; currently, processing activities can be documented and linked to controls and assets to support DPIA preparation.

How does the Data Protection module work in Acuna?

The Data Protection module provides an operational privacy register built around processing activities (Article 30 ROPA). A 7-step wizard guides creation through purpose, legal basis, data subjects, data categories, retention, and transfers, with a four-state workflow (Draft → In Review → Approved → Needs Update). Activities link to assets via a data inventory with personal data grids, to third parties with DPA status and transfer country tracking, and to frameworks (GDPR and Swiss FADP pre-configured). An interactive data flow diagram visualizes how personal data moves across the organisation. A privacy dashboard surfaces PA status distribution, data inventory coverage, DPA completeness, and framework assignments. The module also supports structured migration from OneTrust.

What is a Record of Processing Activities (ROPA)?

A Record of Processing Activities (ROPA) is the internal register required by GDPR Article 30 that documents how your organisation processes personal data — purpose, data categories, recipients, transfers outside the EU or EEA, retention periods, and security measures. Controllers and processors must keep one in writing and produce it to a supervisory authority on request. It is the source of truth that a DPIA, a DSAR, a breach assessment, and a transfer assessment all read from. Acuna's data privacy management treats each processing activity as a living record tied to your asset and vendor inventory, so the people closest to the data keep the register honest.

When is a DPIA required under the GDPR?

A Data Protection Impact Assessment (DPIA) is mandatory under GDPR Article 35 whenever processing is likely to result in a high risk to the rights and freedoms of individuals. Article 35(3) names three cases that always require one: systematic and extensive profiling with legal effects, large-scale special-category data processing, and systematic monitoring of a publicly accessible area at scale. The EDPB adds nine criteria; two or more typically require a DPIA. Acuna's data privacy management carries a built-in screener against the EDPB criteria on every processing activity, so the question is answered as part of recording the activity, not as a separate project.

What is the GDPR 72-hour breach notification rule?

Under GDPR Article 33, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to individuals. Where the breach is likely to result in a high risk, the controller must also notify affected data subjects under Article 34. The clock starts at awareness, not at the conclusion of the investigation; Article 33(4) permits phased notification as facts emerge. Every breach must be documented under Article 33(5) whether or not it meets the notification threshold.

How long do you have to respond to a DSAR?

Under GDPR Article 12(3), a controller must respond to a data subject access request without undue delay and within one month of receiving it. The period can be extended by two further months for complex or numerous requests, giving a three-month maximum, provided you notify the individual within the first month and explain the reasons. The legal unit is one month, not 30 days; a month is calculated by the calendar. Acuna's data privacy management tracks each DSAR against a response deadline with a colour-coded countdown, records the one permitted extension with its rationale, and links the request to the processing activities that hold the subject's data.

What is a Data Processing Agreement (DPA)?

A Data Processing Agreement (DPA) is the written contract GDPR Article 28 requires whenever a controller engages a processor to handle personal data on its behalf. It must bind the processor to obligations covering the subject matter, duration, nature, and purpose of the processing — plus data subject rights assistance, breach notification, DPIA support, sub-processor controls, and audit access. Without a compliant DPA the processing relationship is unlawful. Acuna's data privacy management generates an Article 28 agreement pre-filled from the processing activity it covers and tracks each agreement through its lifecycle on the matching supplier record in third-party risk management.

What is a Transfer Impact Assessment (TIA)?

A Transfer Impact Assessment (TIA) is the analysis required under GDPR Chapter V before transferring personal data to a country outside the EU or EEA without an adequacy decision. Following Schrems II, relying on Standard Contractual Clauses alone is insufficient: you must assess whether the destination country's law and practice provide essentially equivalent protection and, where it falls short, apply supplementary measures or stop the transfer. Acuna's data privacy management builds the TIA from the cross-border recipients already recorded on a processing activity and defaults to a higher-risk outcome so a transfer has to earn a lower rating rather than be assumed safe.

GET STARTED

See GDPR run as a live programme.

Bring a real processing activity, a real processor chain, or a real audit scenario, and we will show how Acuna handles it.