GDPR Compliance Status: Compliant
DPO: Dr. Sarah Mueller | Last Audit: September 2025 | Next Review: March 2026
Active Compliance
Requirement Coverage
98.1%
58/59 requirements met
Processing Activities
42
documented in ROPA
Data Subject Requests
24
processed this year
Data Breaches
0
in the last 12 months
GDPR Article Compliance
| Article | Topic | Description | Requirements | Implemented | Status |
|---|---|---|---|---|---|
Art. 5 | Principles of Processing | Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity | 6 | 6 | Compliant |
Art. 6 | Lawfulness of Processing | Legal basis for processing personal data | 4 | 4 | Compliant |
Art. 12-14 | Transparency & Information | Privacy notices, information to data subjects | 8 | 8 | Compliant |
Art. 15-22 | Data Subject Rights | Access, rectification, erasure, portability, objection, automated decision-making | 8 | 7 | Partial |
Art. 24-25 | Controller Obligations | Data protection by design and default | 5 | 5 | Compliant |
Art. 28-29 | Processor Requirements | Data processing agreements, sub-processor management | 6 | 6 | Compliant |
Art. 30 | Records of Processing | Processing activity documentation | 3 | 3 | Compliant |
Art. 32-34 | Security & Breaches | Security measures, breach notification, communication to data subjects | 7 | 7 | Compliant |
Art. 35-36 | Impact Assessments | DPIA requirements and prior consultation | 4 | 4 | Compliant |
Art. 37-39 | Data Protection Officer | DPO designation, position, and tasks | 3 | 3 | Compliant |
Art. 44-49 | International Transfers | Cross-border data transfers and safeguards | 5 | 5 | Compliant |
| Total | 59 | 58 | 98.3% |
Data Security
Encryption at Rest
AES-256
Encryption in Transit
TLS 1.3
Pseudonymisation
Implemented
Access Controls
RBAC
Data Subject Rights
Right to Access
Active
Right to Erasure
Active
Right to Portability
Active
Response SLA30 days
International Transfers
EU/EEA
No restrictions
UK
Adequacy
US
EU-US DPF
Other
SCCs
Records of Processing Activities (ROPA) - Sample
| Activity | Purpose | Data Categories | Retention | Lawful Basis |
|---|---|---|---|---|
| Client Onboarding | Contract performance | Identity, Contact, Financial | Duration of relationship + 7 years | Contract |
| Portfolio Management | Contract performance | Financial, Investment preferences | Duration of relationship + 10 years | Contract |
| AML/KYC Compliance | Legal obligation | Identity, Source of wealth | 5 years post-relationship | Legal obligation |
| Marketing Communications | Legitimate interest/Consent | Contact, Preferences | Until withdrawal + 2 years | Consent |
| Employee Management | Contract/Legal obligation | Identity, Employment, Payroll | Duration + 7 years | Contract |
Data Subject Requests (YTD)
15
Access Requests
4
Erasure Requests
3
Rectification
2
Portability
On-Time Completion Rate
100%
Average Response Time18 days
Data Protection Impact Assessments
New CRM System Implementation
October 2025
Medium
Approved
Cloud Migration Project
August 2025
High
Approved with conditions
Client Portal Enhancement
June 2025
Low
Approved
AI-Assisted Analytics Tool
March 2025
High
Approved with conditions
Recent Data Subject Requests
Access Request
November 12, 2025
Response: 12 days
Completed
Erasure Request
November 5, 2025
Response: 21 days
Completed
Access Request
October 28, 2025
Response: 15 days
Completed
Rectification
October 15, 2025
Response: 8 days
Completed
GDPR Compliance Framework
Data Breach Notification
Personal data breaches must be reported to the Supervisory Authority within 72 hours of becoming aware. High-risk breaches require notification to affected data subjects without undue delay.
Data Protection Officer
DPO: Dr. Sarah Mueller | The DPO monitors compliance, advises on DPIAs, cooperates with the Supervisory Authority, and serves as the contact point for data subjects.
Supervisory Authority
- Lead Authority: Irish Data Protection Commission
- Registration: Active
- One-Stop-Shop Mechanism: Applicable
- Last Communication: August 2025
Compliance Activities
- ROPA Update: Quarterly
- Privacy Notice Review: Annual
- Staff Training: Bi-annual
- Third-Party Assessment: Annual