GDPR applies to everyone processing personal data about people in the EU, and it never went away. What changed is what regulators and customers expect: a static privacy policy is no longer enough. OptiTech turns GDPR into verifiable controls connected to your real systems.
Who it applies to
Every organization that processes personal data about people in the EU: employees, customers, or users. In practice, everyone.
What OptiTech provides
- Records of processing: the Article 30 register, kept current as your systems change
- Data protection controls: access control, encryption, retention, and deletion verified continuously through your integrations
- The 72-hour IMY flow: guided breach reporting with pre-filled forms, deadline countdown, and communication templates for those affected
- Data processor tracking: your processors and subprocessors in the vendor register, with agreements monitored
- Employee awareness: policies with e-signing and read receipts, plus training on Professional and Enterprise
Sanctions
Up to 20 million euros or 4 percent of global revenue, whichever is higher. IMY also issues reprimands and orders that become public, which often costs more in trust than the fine.
Cross-mapping
GDPR shares controls with ISO 27001 (access, encryption, incident handling) and extends naturally into ISO 27701 if your customers ask for certified privacy management.
Get started
GDPR is available on every plan, including Start. Book a free gap analysis or compare plans.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.