Frameworks

GDPR accountability, evidenced.

GDPR asks you to be able to demonstrate compliance, not just achieve it. TruOps keeps the demonstration current.

GDPR · readinessevidence current
GDPR · coverage by obligation
Art. 5 Principlessatisfied · 91%
Art. 28 Processorspartial · 71%
Art. 30 Records of processingsatisfied · 94%
Art. 32 Security of processingsatisfied · 100%
Art. 33–34 Breach notificationsatisfied · 92%
Art. 35 DPIAspartial · 63%
The same work also counts toward
ISO 2700141% · partials shown
SOC 2 Privacy61% · partials shown
NIS256% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, has applied since 25 May 2018 to organizations that process personal data of people in the EU. It sets principles for processing, rights for individuals, obligations for controllers and processors, security requirements (Article 32), and a duty to notify supervisory authorities of personal data breaches within 72 hours where feasible. Fines can reach €20 million or 4% of worldwide annual turnover.

This page is for you if
  • Article 32 and processor oversight are the GRC team's problem, and they are still in a privacy tool nobody updates
  • You need to show security measures and vendor due diligence, not run DSAR workflows
  • A DPIA exists; the security controls it assumes are not evidenced
Instrument
Regulation (EU) 2016/679
Applies since
25 May 2018
Breach notification
Within 72 hours where feasible
Maximum fine
€20 million or 4% of global turnover

Where GRC meets privacy

  • Article 5: principles, including accountability
  • Article 28: requirements for processors, which makes vendor assessment part of GDPR
  • Article 30: records of processing activities
  • Article 32: appropriate technical and organizational security measures
  • Articles 33–34: breach notification
  • Article 35: data protection impact assessments for high-risk processing

The actual challenge

GDPR accountability is a demonstration. Security and processor controls are where GRC has the records, if they are not trapped in a privacy suite that does not talk to the ISMS.

  • Processors signed DPAs; they were never assessed against Article 32.
  • Records of processing are elsewhere; the security measures they depend on are here, unlinked.
  • Breach notification needs current control status, not last year's TOMs.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts GDPR from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

How TruOps helps with GDPR

Pick GDPR as your anchor, or map it to the framework you already run. TruOps keeps GDPR's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your GDPR assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

TruOps focuses on the security and accountability side of GDPR: evidencing Article 32 measures, assessing processors, and tracking findings. It does not replace a privacy management tool for data subject requests.

If this is your situation

TruOps is the security and accountability layer: Article 32 evidence, processor assessments, findings. It does not replace a privacy tool for data-subject requests. Bring your processor list.

How TruOps helps

Anchor or map
Run GDPR as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your GDPR assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

Does GDPR apply to companies outside the EU?

Yes, when they offer goods or services to people in the EU or monitor their behavior.

What does Article 32 require?

Appropriate technical and organizational measures to ensure security appropriate to the risk, such as encryption, resilience, restoration, and regular testing.

Can TruOps assess our processors?

Yes. Vendor assessments run on the same engine, with processors tiered by the personal data they handle.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.