Privacy · Artificial intelligence · Security

Digital compliance for privacy, artificial intelligence and security.

A dedicated environment for organising compliance documentation, processes, controls and responsibilities.

The product

A single platform to manage the full compliance lifecycle

GDPR Suite brings documentation, processes and controls into one coherent environment to oversee obligations relating to data protection and adjacent regulations, with a multi-organisation architecture and data isolation for each organisation.

01

Integrated compliance

Documentation, processes and controls organised in one environment, with relationships and dependencies across modules.

02

Security by design

Access control, encryption and traceability built into the architecture, not added afterwards.

03

Document automation

Generation of documentation from structured templates, with versioning and multiple formats.

04

Organisational control over data

The organisation retains control over its data and over the configuration of external integrations.

Supported regulatory areas

Built for a complex regulatory landscape

The platform supports the organisation of obligations relating to the main European and national regulations and directives. Tooling support does not in itself constitute a guarantee of compliance, which remains an assessment for the organisation to make.

GDPR Reg. (EU) 2016/679
AI Act Reg. (EU) 2024/1689
DSA Reg. (EU) 2022/2065
Data Act Reg. (EU) 2023/2854
NIS2 Dir. (EU) 2022/2555
CRA Reg. (EU) 2024/2847
DORA Reg. (EU) 2022/2554
DMA Reg. (EU) 2022/1925
Italian Privacy Code Lgs. Decree 196/2003
ePrivacy Dir. 2002/58/EC
Core features

Modules for every area of compliance

Records of processing

Processing activities, notices, consents and legal bases.

Data subject rights

Request management with a public form and deadline tracking.

Processors

Article 28 agreements and processor register.

Impact assessments

DPIA, LIA and TIA with guided workflows.

Risk analysis

A control catalogue across multiple security frameworks.

AI Act

Classification, assessment and governance of AI systems.

Data breach

Handling of incidents and related notification obligations.

Litigation

Case files, briefs and versioning for proceedings.

Cookies

Audit, registry and gap analysis.

Training

Events, invitations and certificates for staff.

Obligations register

Organisation of obligations across multiple regulations.

Documents and knowledge base

Document repository and regulatory knowledge base.

Architecture and security

Security built into the architecture

Access control

Profiles and roles with least-privilege, enforced across the platform.

Encryption

Encryption of data at rest and of communication channels.

Audit trail

Append-only record of operations, resistant to tampering.

Multi-organisation isolation

Separation of data across different organisations.

Dedicated deployment

Installation in a dedicated environment, self-hosted or private cloud.

Optional integrations

External services optional and configurable by the organisation.

142 risk controls in the analysis catalogue
Privacy by design

Data processing under the organisation's control

The platform is designed to minimise external dependencies and keep organisational control over data and over the configuration of integrations.

Dedicated environment

Self-hosted or private-cloud deployment, according to the organisation's needs.

Optional artificial intelligence

Assistance features based on multiple providers, cloud or local, with granular activation.

Traceability of decisions

Operations are recorded so that the decisions taken can be demonstrated.

Dedicated instances

A reserved instance for each organisation

GDPR Suite is delivered in dedicated, isolated instances, each reserved for the enabled organisation and reachable on its own subdomain. Access is restricted to authorised users.

User experience

Accessible from any device

GDPR Suite is a responsive web app, usable on desktop, tablet and smartphone, to consult and manage activities on the go.

The project

GDPR Suite is an independent software project by Nicola Fabiano. It is developed as a standalone platform for organising compliance and is continuously evolving to stay aligned with the European regulatory framework.

Contact

Request information

For information about the project and dedicated instances, write to email us.