GDPR, from records of processing to breach reporting
Keep your records of processing current, manage data subject requests, and run the 72-hour IMY breach notification flow, all connected to the controls that protect the data.
20 M€ / 4%
Maximum GDPR sanction
72h
Breach notification to IMY
1 month
Data subject request deadline
GDPR is old, but still catches teams out
RoPA goes stale
Records of processing kept in a spreadsheet drift out of date the moment systems change.
The 72-hour clock
A personal data breach must be reported to IMY within 72 hours, and the clock is unforgiving.
Requests pile up
Data subject requests arrive with a one-month deadline and no clear process.
How OptiTech gets you compliant
- 01
Build your RoPA
A living record of processing activities with purposes, categories, and transfers.
- 02
Handle requests
Track data subject requests against the one-month deadline.
- 03
Report breaches to IMY
A guided 72-hour breach notification flow, prefilled from the incident.
What OptiTech gives you for GDPR
Records of processing
RoPA under Article 30, kept current.
Data subject requests
The one-month deadline tracked per request.
IMY breach flow
The 72-hour notification under Article 33, guided.
Data protection controls
Controls linked to the processing they protect.
GDPR is not hard because the rules changed. It is hard because the records stopped matching reality.
Questions
- Yes. A guided 72-hour notification flow prefills from the incident, in parallel with the NIS2 track.
- Yes. Records of processing are a living register linked to purposes, categories, and transfers.
- Each request is tracked against the one-month deadline with a clear process.
- Yes. GDPR controls extend naturally into an ISO 27701 privacy management system.
Keep GDPR current, not just documented
RoPA, data subject requests, and the IMY breach flow.
