Every GDPR obligation,
on autopilot.
RoPA, DPIAs, data subject requests, retention and breach response run as one continuous process instead of twelve separate projects. Documentation stays current, so you are audit-ready by default rather than by scramble.
Over €7 billion in fines,
and accelerating.
Penalties are handed down every week, across every sector, and the most frequent finding is also the most avoidable one.
Largest single fine to date
Issued by Ireland's DPC in 2023 for unlawful transfers of EU personal data to the US without adequate safeguards.
Cross-border transfers, 2025
Also issued by Ireland's DPC, for moving EU user data outside the EEA without adequate safeguards. Transfers remain a primary enforcement target.
Most common finding
Insufficient technical and organisational measures under Article 32. Fines in this category rose 40% year on year in 2025.
Four stages. One
continuous programme.
GDPR is not a checklist of unrelated tasks. Whisperly runs it as a lifecycle, where each stage feeds the next and every output is evidence.
Document
Establish what you process and why. Records for controller and processor roles, generated by AI and kept current as systems change.
Assess
Judge the risk in what you process, and in who processes it for you. Assessments drafted with scoring and mitigations attached.
Respond
The obligations that arrive with a clock attached. Every request and incident routed, tracked and answered inside its legal window.
Prove
Accountability is the obligation everyone forgets until an auditor asks. Every action logged, time-stamped and exportable on demand.
GDPR is never one team's job.
Legal writes the notice, engineering holds the data, procurement signs the DPA, HR owns the employee records. Whisperly gives each of them their piece with an owner and a due date, and shows you the whole board.
Two tiers, both material.
Fines scale with the severity of the violation, and authorities can also order processing to stop entirely.
Where you are
registered doesn't matter.
The GDPR follows the data subject, not the company. If you process the personal data of people in the EU, it applies to you.
Data controllers
You decide the purposes and means of processing, and carry full accountability for lawfulness, rights and breach notification.
Data processors
You process on a controller's behalf, and still owe security measures, your own records, breach reporting and DPA terms.
Non-EU organisations
Offering goods or services to EU residents, or monitoring their behaviour, brings you in scope and usually requires an Article 27 representative.
Public authorities
A DPO is mandatory, DPIAs are required for high-risk processing, and transparency obligations toward citizens are stricter.
A practical guide to
GDPR obligations.
The seven principles in Article 5 are what regulators actually test against. Here is what each one asks of you in practice, and where it usually goes wrong.
Lawfulness, fairness and transparency
Every activity needs one of the six lawful bases recorded against it, and people must be told what you do with their data in language they can follow.
Purpose limitation
Collect data for a stated purpose and use it only for that purpose. A new use needs its own basis and, usually, its own notice.
Data minimisation
Hold only what the purpose genuinely requires. Every extra field is extra liability in a breach and extra work in a subject access request.
Accuracy
Keep records correct and current, and give people a working route to have errors put right without arguing their case twice.
Storage limitation
Set a retention period for each category of data and actually delete when it expires. A schedule nobody executes is worse than none at all.
Integrity and confidentiality
Technical and organisational measures proportionate to the risk, documented per activity. This is the single most fined obligation in the regulation.
Accountability
The principle that makes the other six enforceable: you must be able to demonstrate compliance, not merely assert it. In practice that means records, assessments, approvals and dates you can produce on request. It is the obligation Whisperly exists to remove the work from.
Frequently asked questions
Audit-ready by default.
See your entire GDPR programme running in one platform, with the evidence already in place.