Framework · GDPR

2.1 billion € in GDPR fines in 2023. Your DPA is watching.

The General Data Protection Regulation applies to any organisation processing personal data of EU residents—regardless of where the organisation is located. Data Protection Authorities issue fines of up to 4% of global annual turnover. Sentrix automates the technical controls required by Article 32, manages DPIAs and DSRs, and crosswalks your GDPR compliance to Law 25 for Canadian organisations.

€2.1B
Total GDPR fines issued in 2023—enforcement is accelerating across all EU member states
72h
Maximum time to notify your supervisory authority after discovering a personal data breach
Art.32
Technical security controls required by Article 32—all mapped to infrastructure controls in Sentrix
Canadian
data residency—all Sentrix compliance data stored in Canada, critical for organisations subject to cross-border transfer provisions
What GDPR requires

Article 32 technical controls. DPIAs. Data subject rights. All of it.

GDPR is both a data protection regulation and a technical security framework. Article 32 requires appropriate technical and organisational security measures based on risk. Articles 33–34 require breach notification within 72 hours. Articles 13–22 establish data subject rights your organisation must honour. Sentrix maps technical controls to every obligation.

  • Art. 5: processing principles—purpose limitation, data minimisation, accuracy
  • Art. 6: lawful basis for processing—consent, legitimate interests, legal obligation documented
  • Art. 13–14: information to be provided—privacy notice records
  • Art. 17: right to erasure—deletion workflows and documentation
  • Art. 32: security of processing—encryption, pseudonymisation, resilience
  • Art. 35: DPIA required before high-risk processing projects

GDPR · Art. 32 controls

TECHNICAL MONITORING
Encryption at rest✓ PASS
Encryption in transit (TLS)✓ PASS
Access control & MFA✓ PASS
Audit logging▲ 2 gaps
Disaster recovery plan✓ PASS
Breach notification procedure✓ PASS
⚠ DB access logs: insufficient retention · Anomaly detection alert missing
Full GDPR capabilities

Every GDPR obligation. Automated. DPA-ready.

Records of Processing Activities (ROPA)

Article 30 requires a documented record of all processing activities. Sentrix maintains your ROPA automatically as new integrations and processing activities are detected across your infrastructure.

Data Protection Impact Assessment (DPIA)

Article 35 requires a DPIA before high-risk processing projects. Sentrix provides bilingual DPIA templates, tracks completions, and stores assessments as audit evidence—with alerts when new projects trigger DPIA requirements.

Data subject rights management

Track access, rectification, erasure, and portability requests with 30-day response SLAs. Request logs maintained automatically. Automated reminders before deadlines.

72-hour breach notification

Breach classification workflow, DPA notification templates, and data subject notification documentation. All evidence archived in the format DPAs expect during investigations.

Law 25 crosswalk

Canadian organisations with EU customers manage both GDPR and Law 25 from one Sentrix program. The significant overlap (consent, DPIA/PIA, breach notification, data subject rights) is mapped automatically.

Processor agreement management

Article 28 requires data processing agreements with all processors. Sentrix tracks all your processor agreements, expiry dates, and audit requirements—with alerts before expiry.

See your GDPR posture and Art. 32 gaps live.

We map your GDPR controls to your real infrastructure during the demo.