GDPR makes you accountable for the processors you engage and for notifying a breach within 72 hours. Polestead surfaces every processor by the data they hold — and can keep that personal data inside your own jurisdiction.
The logical-data-access vector classifies vendors by the personal data they hold, so processors are identified and assessed to the right depth.
CIIC keeps the 72-hour clock to the supervisory authority and drafts the notification — in parallel with any other regime that applies.
Self-host or air-gap to keep personal data in your environment; EU cloud and managed SaaS are EU-resident.
A personal-data breach must reach the supervisory authority within 72 hours of awareness, where it is likely to result in risk to individuals. CIIC starts that clock at classification, drafts the notification, and runs it alongside DORA or NIS2 duties triggered by the same incident. Verify specifics with counsel. Dataset last verified July 2026. Not legal advice.
It classifies every vendor by the personal data and access they hold, so processors are identified and assessed at the depth their exposure warrants — across the whole register.
Yes. CIIC schedules the 72-hour clock from classification and drafts the notification, alongside any other regimes applying in parallel.
Wherever you deploy. Self-hosted and air-gapped keep it in your environment; EU cloud and managed SaaS are EU-resident.