GDPR Compliance

The GDPR tool that flags your obligations at pre-assessment

The business describes its project, Vailor flags the GDPR obligations to address, and the EBIOS RM risk analysis documents the measures you choose, with data stored in France as SaaS or an installation on your premises.

What GDPR is and why it is unavoidable

Since 2018, the General Data Protection Regulation has governed the processing of personal data of European Union residents. It requires organizations to keep records of processing activities, run data protection impact assessments (DPIAs) for high-risk processing, uphold data subject rights and notify breaches. Non-compliance with GDPR can lead to fines of up to 4% of annual worldwide turnover, making it a major governance issue.

How Vailor structures your GDPR compliance

Vailor steps in where GDPR compliance is often decided: when projects start. The business starts its pre-assessment in self-service, and GDPR obligations, like AI Act ones, are flagged at that stage. Security then qualifies the project and runs the risk analysis in EBIOS RM or as a flash assessment: the AI reads the project documents and prefills fields from excerpts, your experts validate. The measures you choose feed the risk register and the action plan, which documents your accountability. Vailor does not replace your record of processing activities: it covers the risk and security side of it.

Why data control matters for your GDPR tool

Entrusting analyses that describe your personal data processing to a tool hosted outside Europe would be a contradiction. As SaaS, data is stored in France (AWS Paris region) and AI processing runs on AWS Bedrock in EU regions. Vailor also installs on your premises (Docker), with the AI model of your choice, including a self-hosted one. Your data is never used to train models. When the AI relies on your documents, it quotes the passage, and Vailor checks word for word that it is there. Every decision is traced, so you can justify your choices to the DPO and to the supervisory authority.

A GDPR platform built for DPOs and CISOs

Obligations flagged early

From the pre-assessment onward, Vailor flags the GDPR and AI Act obligations that apply to the project.

AI prefill

The AI reads the project documents and prefills the analysis from excerpts, your experts validate.

EBIOS RM risk analysis

Assess the risks of a project that processes personal data with EBIOS RM or a flash assessment.

Data stored in France

As SaaS, data stored in France (AWS Paris region), or installed on your premises. Your data never trains any model.

The benefits of the Vailor GDPR tool

GDPR obligations spotted at the pre-assessment of every project
An EBIOS RM or flash risk analysis, prefilled by AI from your documents
Measures linked to risks and tracked in the action plan
PDF, Word and PowerPoint exports for the DPO and management
Full traceability to demonstrate your accountability
Data stored in France as SaaS, or installed on your premises

Frequently asked questions about GDPR compliance

Is GDPR certifiable in the way ISO 27001 is?

No. The GDPR is a directly applicable regulation: you comply with it, you do not hold a certificate for it. Article 42 does provide for certification mechanisms, seals and marks, issued against criteria approved by a supervisory authority or by the European Data Protection Board, but they cover defined processing operations, never the organisation as a whole. For a certificate at organisation level, the recognised route is ISO/IEC 27701, the privacy information management standard that works alongside ISO/IEC 27001: useful evidence of maturity, but not proof of GDPR compliance.

Who must appoint a data protection officer?

Article 37 of the GDPR makes a DPO mandatory in three cases: public authorities and bodies, organisations whose core activities involve regular and systematic monitoring of individuals on a large scale, and organisations whose core activities involve large-scale processing of special category data or data on criminal convictions. The 250-employee threshold people often quote has nothing to do with the DPO: it frames a partial exemption from the record-keeping duty, which falls away as soon as processing is not occasional, as with payroll or HR.

When is a DPIA mandatory?

Whenever processing is likely to result in a high risk to the rights and freedoms of individuals. The GDPR names three situations that always trigger one: systematic and extensive automated evaluation of personal aspects used as the basis for decisions with legal effects, large-scale processing of special category or criminal data, and systematic monitoring of a publicly accessible area on a large scale. Each supervisory authority publishes its own list of operations requiring a DPIA, and some, the CNIL among them, also list operations exempt from it.

How do GDPR and the AI Act overlap?

They are two separate regimes. The GDPR protects personal data and grants rights to individuals; the EU Artificial Intelligence Act classifies AI systems by risk level, including where no personal data is processed at all. They meet on an AI system that handles personal data: lawful basis, minimisation and the DPIA still follow from the GDPR, while the AI Act adds training data governance, technical documentation and human oversight, plus a fundamental rights impact assessment for certain deployers of high-risk systems.

Does the GDPR apply to a company established outside the EU?

Yes, as soon as the processing targets people located in the Union. Article 3 sets two alternative tests: offering goods or services to those people, whether paid for or free, or monitoring their behaviour within the Union. A controller with no EU establishment must then designate a representative in the Union in writing, subject to limited exemptions. Where the servers sit does not change whether the regulation applies: it matters instead for how transfers outside the EU must be framed.

What must a compliant record of processing activities contain?

Article 30 sets the minimum content for a controller's record: the identity and contact details of the controller and, where applicable, of the data protection officer, the purposes pursued, the categories of data subjects and of personal data, the categories of recipients, transfers to third countries and the safeguards attached to them, then, where possible, the envisaged time limits for erasure and a general description of the technical and organisational security measures. The record is kept per processing activity rather than per application, and must be made available to the supervisory authority on request.

Why use GDPR software rather than a spreadsheet?

A spreadsheet gives you a snapshot, never a history. Every processing activity added, every change of processor, every revised retention period creates a parallel version, and the link between an activity, its DPIA, its risks and its measures ends up lost. Dedicated software holds that link, keeps a trace of the decisions taken and flags what is due for review. In Vailor, a project's GDPR obligations are flagged at pre-assessment, and the audit trail stays readable by the DPO and by the supervisory authority alike.

Drive your GDPR compliance with Vailor

Book 30 minutes with us: we listen to your context and tell you concretely how Vailor fits into your GDPR program.

Book a demo