Loading Vaultize
Skip to main content

Compliance/Global/GDPR

Ninety-nine articles: eighteen leave evidence in the file.

The Regulation makes the controller and processor responsible for personal data wherever it is processed. Vaultize adds records that stay with the file.

  • Regulation (EU) 2016/679
  • Adopted 27 April 2016
  • Applicable from 25 May 2018
  • Capability mapping, not legal advice

5(1)(f)Principles

processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

Vaultize Seal

  1. I

    General provisions

    0 of 4

    • 1
    • 2
    • 3
    • 4
  2. II

    Principles

    1 of 7

    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
  3. III

    Rights of the data subject

    1 of 12

    • 12
    • 13
    • 14
    • 15
    • 16
    • 17
    • 18
    • 19
    • 20
    • 21
    • 22
    • 23
  4. IV

    Controller and processor

    7 of 20

    • 24
    • 25
    • 26
    • 27
    • 28
    • 29
    • 30
    • 31
    • 32
    • 33
    • 34
    • 35
    • 36
    • 37
    • 38
    • 39
    • 40
    • 41
    • 42
    • 43
  5. V

    Transfers to third countries

    1 of 7

    • 44
    • 45
    • 46
    • 47
    • 48
    • 49
    • 50
  6. VI

    Independent supervisory authorities

    0 of 9

    • 51
    • 52
    • 53
    • 54
    • 55
    • 56
    • 57
    • 58
    • 59
  7. VII

    Cooperation and consistency

    0 of 17

    • 60
    • 61
    • 62
    • 63
    • 64
    • 65
    • 66
    • 67
    • 68
    • 69
    • 70
    • 71
    • 72
    • 73
    • 74
    • 75
    • 76
  8. VIII

    Remedies, liability and penalties

    0 of 8

    • 77
    • 78
    • 79
    • 80
    • 81
    • 82
    • 83
    • 84
  9. IX

    Provisions relating to specific processing situations

    0 of 7

    • 85
    • 86
    • 87
    • 88
    • 89
    • 90
    • 91
  10. X

    Delegated acts and implementing acts

    0 of 2

    • 92
    • 93
  11. XI

    Final provisions

    0 of 6

    • 94
    • 95
    • 96
    • 97
    • 98
    • 99
18of 99 articles, in 4 of 11 chapters

The answer in 30 seconds

Vaultize adds file-level records to eighteen provisions across ten articles in four of the Regulation’s eleven chapters: the principles, the rights of the data subject, the controller and processor’s obligations, and transfers outside the EU. Lawful basis, consent, supervisory authorities and penalties sit outside a governed file, with the organisation and its counsel.

The Regulation in one view

Eleven chapters. Ninety-nine articles. Where file evidence lands.

The Regulation runs in eleven chapters. Chapter summaries are in our words. Select a chapter to see which of its articles a governed file can evidence.

IIIIIIIVVVIVIIVIIIIXXXI

I

General provisions

Articles 1 to 4. The Regulation’s subject matter and objectives, its material and territorial scope, and its definitions.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Scope and definitions are matters for counsel. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Article by article

    What each provision asks. What the file can answer.

    Wording is quoted from Regulation (EU) 2016/679 as published in the Official Journal. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Regulation and take advice on applicability, roles and lawful basis.

    Using this page

    Where these rows fit in a GDPR programme.

    The Regulation has applied since 25 May 2018. The rows above are evidence for the obligations that touch documents.

    1. 1

      Confirm scope

      Article 3. Whether the processing, the controller’s establishment, or an offer of goods or services to data subjects in the EU brings the Regulation into play.

    2. 2

      Establish the lawful basis

      Chapter II. Consent, contract or another basis under Article 6, and the principles in Article 5 that follow from it.

    3. 3

      Apply technical measures

      Article 32. Encrypt personal data, restrict access to it, and keep a record of both. These rows belong here.

      Bring the eighteen rows above as evidence of the technical measures and the records that back them.

    4. 4

      Follow the breach process

      Articles 33 and 34. Notify the supervisory authority without undue delay and, where the risk is high, the data subject.

    5. 5

      Keep the records

      Articles 5(2), 24 and 30. For the supervisory authority, and for demonstrating compliance.

    Responsibility boundary

    Controls support compliance. They are not legal advice.

    Vaultize contributes technical measures and evidence for personal data held in documents. It does not decide whether the Regulation applies, what lawful basis or legitimate interest supports a given processing activity, or whether a transfer meets Chapter V’s conditions. Read the Regulation and take qualified advice before relying on this page.

    “Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation.”

    Article 24(1), Regulation (EU) 2016/679 (GDPR)

    A practical next step

    Bring one document that carries personal data.

    We will show which articles the governed document can evidence today. We will name the owner responsible for the rest.

    Request a compliance mapping session