Solutions · GDPR

Know which processors hold your personal data.

GDPR makes you accountable for the processors you engage and for notifying a breach within 72 hours. Polestead surfaces every processor by the data they hold — and can keep that personal data inside your own jurisdiction.

What GDPR asks — and how Polestead answers.

Processor due diligence
Found by data held.

The logical-data-access vector classifies vendors by the personal data they hold, so processors are identified and assessed to the right depth.

Breach notification
72 hours, drafted.

CIIC keeps the 72-hour clock to the supervisory authority and drafts the notification — in parallel with any other regime that applies.

Data residency
In your jurisdiction.

Self-host or air-gap to keep personal data in your environment; EU cloud and managed SaaS are EU-resident.

72h
Breach notification

A personal-data breach must reach the supervisory authority within 72 hours of awareness, where it is likely to result in risk to individuals. CIIC starts that clock at classification, drafts the notification, and runs it alongside DORA or NIS2 duties triggered by the same incident. Verify specifics with counsel. Dataset last verified July 2026. Not legal advice.

FAQ

GDPR questions.

How does Polestead support processor due diligence?+

It classifies every vendor by the personal data and access they hold, so processors are identified and assessed at the depth their exposure warrants — across the whole register.

Can it help with 72-hour breach notification?+

Yes. CIIC schedules the 72-hour clock from classification and drafts the notification, alongside any other regimes applying in parallel.

Where is personal data processed?+

Wherever you deploy. Self-hosted and air-gapped keep it in your environment; EU cloud and managed SaaS are EU-resident.

Map your processors, keep the data home.

Book a demo