GDPR readiness assessment — data mapping, privacy controls and DPA requirements
| Activity | Controller/Processor | Purpose | Legal Basis | Data Subjects | Retention | Actions |
|---|---|---|---|---|---|---|
| Customer Account Management | Controller | Service delivery and account management | Contract | Customers | 7 years | |
| Marketing Communications | Controller | Email newsletters and product updates | Consent | Prospects, customers | Until withdrawn |
| Request Type | Requester | Date Received | Deadline | Days Left | Status | Notes | Actions |
|---|---|---|---|---|---|---|---|
| No DSARs logged — click "+ Log DSAR" to add one | |||||||
| Vendor | DPA Signed | SCCs | Adequacy Decision | Status | Actions |
|---|---|---|---|---|---|
| Anthropic | 2025-01-01 | No (ZDR policy) | No | Current | |
| Supabase | 2024-06-01 | Yes | No (US → EU SCCs) | Current |
| Discovered | Reported to DPA | Nature | Volume | Consequences | Measures Taken | DPA Notified | Subjects Notified |
|---|---|---|---|---|---|---|---|
| No breaches logged | |||||||