GDPR, finished by agents.
Forty-seven article-level controls, from the Article 5 principles to international transfers, with the records and notices the regulation expects laid out and the Article 32 evidence collected on a schedule.
47
controls
10
article groups
59
cross-mappings
10
required documents
Accountability you can show, not assemble.
GDPR carries 59 cross-mappings into the other eleven frameworks. Twenty-one land on Thailand PDPA, eight on SOC 2, four on ISO 27001. Article 32 security evidence is the security evidence those frameworks already ask for, so the demonstrable-accountability file builds itself as the agents work.
The documents GDPR asks for.
GDPR is a documentation regime: accountability has to be shown on paper, not asserted. These are the ten documents the regulation expects a controller to hold and what each one has to cover. The agents collect the Article 32 security evidence that sits behind them; the wording stays with your DPO or counsel.
Data Protection Policy
The top-level policy covering the Article 5 principles and the accountability duty behind them.
Privacy Notice
The Article 13 and 14 information given to people whose data you collect, directly or otherwise.
Consent Management Policy
How consent is requested, demonstrated and withdrawn under Articles 7 and 8.
Data Subject Rights Procedure
How access, rectification, erasure, restriction, portability and objection requests are answered.
Records of Processing Activities
The Article 30 register of what you process, why, and on what lawful basis.
Data Protection Impact Assessment Procedure
When an Article 35 assessment is triggered, what it must contain and when to consult.
Personal Data Breach Response Plan
The 72-hour notification path to the supervisory authority and to data subjects.
International Transfer Policy
Adequacy, safeguards and derogations for personal data leaving the EEA under Articles 44 to 49.
Data Retention & Erasure Policy
Storage limitation in practice: how long each category is kept, and how it goes.
Processor Management Policy
Article 28 requirements for the processors you appoint and the contracts with them.
Before you start.
- Can you be certified against GDPR?
- No. There is no GDPR certificate. What the regulation asks for is demonstrable accountability, so Zero2Do keeps the controls, the records and the notices current and produces the file that shows it.
- We already run ISO 27001. How much of this is covered?
- Four GDPR controls map onto ISO 27001 controls, and twenty-one onto Thailand PDPA. Article 32 is where the overlap is densest: the security evidence transfers, while the rights, records and transfer articles remain GDPR-specific work.
- Does Zero2Do give legal advice?
- No. The agents prepare documents and evidence against the seeded articles; your counsel or DPO decides what applies to your processing and approves what ships.
From zero to audit-ready in 30 days
Connect your systems and the GDPR controls start filling in on the first heartbeat.
- 01
Connect
Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.
- 02
Agents run
On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.
- 03
Approve
You review what the agents produced and answer the few questions only you can answer.