GDPR One
Privacy operations and data protection assurance

GDPR One

Know where personal data sits, whether you are answering the request inside the deadline, and whether you could reconstruct the decision years later. Not in someone's inbox. On the record.

Data subject rights

All six

Every data subject right is run end to end as a case, not just access requests.

Assurance frameworks

Three, one pass

GDPR, SOC 2 and ISO 27001 assessed from a single document set.

Breach notification

72 hours

The clock the workflow is built around, managed rather than remembered on a Saturday.

Regulativ GDPR One: The problem section
The problem

The register says one thing. The organisation does another.

Most privacy teams are not short of process. They are short of a current, evidenced answer to questions that arrive without warning and carry a deadline.

Nobody can say where the data is

Personal data accumulates across customer systems, HR, marketing, support desks, file shares and spreadsheets nobody registered. The record of processing describes the organisation as it was understood at the last audit, not as it runs this week.

The one month clock is unforgiving

A subject request arrives. Locating the records, deciding what is releasable, and protecting other people's information inside it is expert work that does not scale. The deadline does not move for holidays, resignations or a busy quarter.

Releasing the wrong thing is its own breach

A colleague's name, a second customer's account number or a privileged legal opinion inside a response creates the incident you were trying to avoid. The review is line by line, and one missed item is enough.

Decisions cannot be reconstructed

When a supervisory authority asks why a processing activity proceeded, why a request was refused in part, or who approved a retention period, the answer usually lives in an inbox and somebody's memory.

Regulativ GDPR One: What it is section
What this is

An assurance layer, not another register to maintain.

It is

The layer above your systems

  • A current picture of what personal data you hold and on what lawful basis.
  • Subject requests run as cases with a named owner and a visible clock.
  • Assessment findings that become owned, dated work rather than a report.
  • An evidence trail produced as the work happens, not assembled afterwards.
It is not

Categories it is often mistaken for

  • A consent banner or cookie management tool.
  • A scanner pointed at your production databases without supervision.
  • A document management system or a data loss prevention product.
  • A security monitoring platform, and it does not give legal advice.

Consent tools manage the banner. Scanners map the database, unattended. GDPR One is deliberately the layer between them: what you hold, what it means, and what you did about it.

Regulativ GDPR One: What changes section
What changes

The difference a privacy team notices in the first quarter.

Today With GDPR One
TodayThe record of processing is refreshed by a project, and is stale on delivery.
With GDPR OneIt reflects the inventory, and the inventory is refreshed rather than rewritten.
TodayThe status of a subject request is a question you have to ask someone.
With GDPR OneStage, owner and due date are visible without asking anyone.
TodayRedaction is done by hand, and the risk sits with whoever reviewed last.
With GDPR OneA reviewer confirms and corrects a draft, and the approval is attributed.
TodayYou learn your assurance position when an auditor tells you.
With GDPR OneYou hold a current position, with findings that are owned and dated.
TodayEvidence for an inspection is assembled from inboxes under time pressure.
With GDPR OneThe evidence is the record of what the team already did.
Regulativ GDPR One: Capabilities section (LCA accordion style)
Capabilities

What you get.

Six capabilities, one assurance layer, described as what each one produces for you. Open any entry.

The assurance layer 06 capabilities

A maintained picture of which systems hold personal data, which information inside them is personal, and the lawful basis, purpose and retention that apply. Records of processing are produced from it.

Why it mattersThe register a supervisory authority asks for, current on the day they ask for it.

In the assurance layer
Personal data inventory and records

Every request runs as a case with a named owner, a stage and the statutory clock in view, covering all six data subject rights rather than access alone.

Why it mattersMeeting the deadline stops depending on who happens to be in the office.

In the assurance layer
Subject request management

Information belonging to other people is identified in the documents you are about to release, and a reviewer confirms or corrects every decision before anything leaves.

Why it mattersThe third-party disclosure risk is handled at the point it arises, by a person who owns it.

In the assurance layer
Redaction before release

Incidents recorded from the moment of awareness, with notifications to the authority and to affected individuals tracked as separate obligations.

Why it mattersThe seventy-two hour clock is managed rather than remembered on a Saturday.

In the assurance layer
Breach and incident response

Your documents assessed against GDPR, SOC 2 and ISO 27001, producing findings that carry a severity and become owned, dated remediation work.

Why it mattersThree assurance programmes served by one pass, and findings that actually close.

In the assurance layer
Assurance and gap assessment

Ask a question about a privacy obligation and get an answer that arrives with the passage it came from, so an interpretation can be checked before it becomes a decision.

Why it mattersAn answer you cannot trace is not usable in a regulated business.

In the assurance layer
Regulatory answers with their source
Regulativ GDPR One: How it works section
How it works

Understand, decide, act, prove.

Four steps, and the same four whether the thing in front of you is a processing activity, a subject request or a supplier.

1

Understand

You bring what you already have: system extracts, inventories, policy documents. The platform establishes what personal data is present and where it moves, and shows you what it found.

2

Decide

Obligations are attached, risk is scored and gaps are identified. What the platform is confident about is presented as a proposal. What it is not confident about is routed to a person, and it says which is which.

3

Act

Work becomes owned and dated: cases with stages, findings with remediation owners, releases that wait for an approval. Nothing of consequence completes without a person recorded against it.

4

Prove

Records of processing, reports and an evidence trail are produced from the work itself, so an inspection is answered from the system rather than assembled for the occasion.

The detail is in the demonstration. How applicability is determined, how the platform decides what it is confident about, and where the approval gates sit is shown live against your own extract, because seeing it stop you is more convincing than reading about it here.
Regulativ GDPR One: Trust and security section
Trust and assurance

Built for people who have to defend the decision.

Human oversight

Human accountability

Automation proposes, classifies and scores. A named person disposes. It does not release a response, close an incident or sign off an assessment on its own, and the approval points are enforced by the platform rather than by policy.

Audit trail

Evidence and audit trail

Who did what, to what, and when, recorded as the work happens and held against the case it belonged to. The question a regulator asks two years later is answered from the record, not from memory.

Data residency

Your tenancy, your data

Your organisation's data is held in your own tenancy, and what someone is not entitled to see is not available to them rather than merely hidden. Deployment, hosting region and security review scope are confirmed in writing during the pilot.

Where accountability sits. GDPR One identifies applicable obligations with cited reasoning, records who decided what and when, and keeps the evidence. Accountability for compliance stays with your organisation, which is where the regulator puts it. Any supplier telling you otherwise is describing something a supervisory authority will not accept.
Regulativ GDPR One: Who it is for section
Who it is for

Written to the person whose name is on it.

DPO
Carries the accountability

Data protection officer

Carries personal accountability for a position that is currently hard to evidence. Gets a current picture, and an answer to the reconstruction question that takes one click rather than a week.

PM
Owns the deadline

Privacy or DSAR manager

Owns the deadline and the redaction. Gets every open request, its stage and its clock in one place, and a review step that catches what a tired reader would not.

GC
Owns the consequence

General counsel and risk

Owns the consequence when something is released that should not have been. Gets an approval that holds under time pressure, and an attributable record of who signed.

Operates across
Financial services Insurance Professional services Regulated technology
Regulativ GDPR One: Coverage section
Coverage

Regulations and frameworks.

GDPR One works to the UK and EU data protection regimes, and assesses your documents against the assurance frameworks below. These are the frameworks the platform measures you against; they are not certifications held by Regulativ.

Regimes loaded UK GDPR EU GDPR
Also assessed against
Data Protection Act 2018 SOC 2 Type II ISO 27001:2022
Regulativ GDPR One: FAQ section
Questions we are asked

Straight answers.

No, and nobody can. Accountability sits with you as controller, which is where the regulator puts it. What GDPR One produces is different and more useful: applicable obligations identified with cited reasoning, work that is owned and dated, evidence captured as it happens, and decisions you can reconstruct and defend years later.

You should not take it on trust, and the product is built on that assumption. Automated work is presented as a proposal, not a fact. What the platform is not confident about is routed to a person rather than quietly asserted, regulatory answers arrive with the source passage behind them, and nothing of consequence is released without a recorded human approval.

Not unsupervised, by design. You provide extracts, inventories and documents, and what the platform proposes is confirmed by your team before it becomes a record. That is slower than an unattended scanner and it is the reason the resulting register survives an audit.

In your own tenancy, with access governed individually rather than by a shared login. Deployment model, hosting region and the scope of the security review are confirmed with you in writing during the pilot rather than promised on a call.

One module, matched to where your pain actually sits, running against your own extract and your own policy documents, with a named owner on your side and a success measure agreed in writing before it begins.

Regulativ GDPR One: Next step section
Next step

Book a demonstration against your own data.

Send us one system extract and one policy document beforehand and the demonstration runs against your organisation rather than our sample. It is the difference between a product tour and a look at your own week.

What happens next A short qualifying call, then a working demonstration against your own scenario. Typically 45 minutes.