Over €7 billion in GDPR fines since 2018. Penalties up to €20M or 4% of global revenue.Get compliant now →

    Every GDPR obligation, on autopilot.

    RoPA, DPIAs, data subject requests, retention and breach response run as one continuous process instead of twelve separate projects. Documentation stays current, so you are audit-ready by default rather than by scramble.

    app.whisperly.ai / data-privacy
    Back
    Employee HR Data Management
    Approved
    SM
    Created by
    Sarah Mitchell
    1
    Overview
    Controller info
    2
    Processing
    Data activities
    3
    Data Subjects
    Categories
    4
    Recipients
    Transfers
    Basic information
    Provide the name and organizational unit for the processing activity.
    Name *
    Employee HR Data Management
    Responsible organizational unit *
    Lexelerate

    Over €7 billion in fines, and accelerating.

    Penalties are handed down every week, across every sector, and the most frequent finding is also the most avoidable one.

    €1.2B

    Largest single fine to date

    Issued by Ireland's DPC in 2023 for unlawful transfers of EU personal data to the US without adequate safeguards.

    €530M

    Cross-border transfers, 2025

    Also issued by Ireland's DPC, for moving EU user data outside the EEA without adequate safeguards. Transfers remain a primary enforcement target.

    29%

    Most common finding

    Insufficient technical and organisational measures under Article 32. Fines in this category rose 40% year on year in 2025.

    Four stages. One continuous programme.

    GDPR is not a checklist of unrelated tasks. Whisperly runs it as a lifecycle, where each stage feeds the next and every output is evidence.

    01

    Document

    Establish what you process and why. Records for controller and processor roles, generated by AI and kept current as systems change.

    Records of processingArt. 30
    Policies and privacy noticesArt. 13, 14
    Consent recordsArt. 7
    Automate your RoPA →
    02

    Assess

    Judge the risk in what you process, and in who processes it for you. Assessments drafted with scoring and mitigations attached.

    Impact assessmentsArt. 35
    Security measures, synced to RoPAArt. 32
    Vendor and sub-processor riskArt. 28
    Automate your DPIAs →
    03

    Respond

    The obligations that arrive with a clock attached. Every request and incident routed, tracked and answered inside its legal window.

    Data subject requestsArt. 15 to 22
    Breach notificationArt. 33, 34
    Retention and deletion alertsArt. 17
    Automate your DSARs →
    04

    Prove

    Accountability is the obligation everyone forgets until an auditor asks. Every action logged, time-stamped and exportable on demand.

    Live compliance trackerArt. 5(2)
    Evidence packs and audit trailArt. 24
    Public Trust CenterTransparency
    Launch your Trust Center →

    GDPR is never one team's job.

    Legal writes the notice, engineering holds the data, procurement signs the DPA, HR owns the employee records. Whisperly gives each of them their piece with an owner and a due date, and shows you the whole board.

    Kanban task boards
    Every obligation becomes a card with an owner, a due date and a visible state.
    Deadline notifications
    Alerts for DSAR windows, retention expiry and policy review cycles, before they lapse.
    Role-based access
    DPOs, counsel and department heads each see their scope, with a full activity log behind it.
    GDPR Compliance Board
    5 active
    To do · 3
    Update cookie policy
    Legal · Due 3 Mar
    Vendor DPA review
    Procurement · Due 5 Mar
    Q1 DPIA, CRM system
    DPO · Due 10 Mar
    In progress · 2
    RoPA update, marketing
    Marketing · Started 20 Feb
    Deletion, expired leads
    Sales Ops · Due 28 Feb
    Done · 3
    Privacy notice v3.2
    Completed 18 Feb
    DSAR #247 fulfilled
    Completed 15 Feb
    TOMs sync, Art. 32
    Completed 12 Feb
    Retention alert12 records expire in 3 days. Sales Ops notified.

    Two tiers, both material.

    Fines scale with the severity of the violation, and authorities can also order processing to stop entirely.

    €20M
    or 4% of global annual turnover, whichever is higher
    Tier 2, severe violations
    Processing without a lawful basis
    Violations of data subject rights
    Unlawful cross-border transfers
    Failure to obtain valid consent
    Breaching the processing principles
    €10M
    or 2% of global annual turnover, whichever is higher
    Tier 1, administrative violations
    Failure to appoint a DPO when required
    Inadequate record-keeping
    Not conducting required DPIAs
    Insufficient security measures
    Breach notification failures
    Not sure whether you need a DPO or an EU representative?
    Two free checkers walk you through the Article 37 and Article 27 tests in a couple of minutes.

    Where you are registered doesn't matter.

    The GDPR follows the data subject, not the company. If you process the personal data of people in the EU, it applies to you.

    Data controllers

    You decide the purposes and means of processing, and carry full accountability for lawfulness, rights and breach notification.

    Data processors

    You process on a controller's behalf, and still owe security measures, your own records, breach reporting and DPA terms.

    Non-EU organisations

    Offering goods or services to EU residents, or monitoring their behaviour, brings you in scope and usually requires an Article 27 representative.

    Public authorities

    A DPO is mandatory, DPIAs are required for high-risk processing, and transparency obligations toward citizens are stricter.

    A practical guide to GDPR obligations.

    The seven principles in Article 5 are what regulators actually test against. Here is what each one asks of you in practice, and where it usually goes wrong.

    01

    Lawfulness, fairness and transparency

    Every activity needs one of the six lawful bases recorded against it, and people must be told what you do with their data in language they can follow.

    Common failure: relying on consent where legitimate interests apply, without ever documenting the balancing test.
    02

    Purpose limitation

    Collect data for a stated purpose and use it only for that purpose. A new use needs its own basis and, usually, its own notice.

    Common failure: support data quietly reused to train a model or run a marketing campaign.
    03

    Data minimisation

    Hold only what the purpose genuinely requires. Every extra field is extra liability in a breach and extra work in a subject access request.

    Common failure: onboarding forms that collect fields nobody in the business ever reads.
    04

    Accuracy

    Keep records correct and current, and give people a working route to have errors put right without arguing their case twice.

    Common failure: a correction applied in the CRM but never propagated to the systems fed from it.
    05

    Storage limitation

    Set a retention period for each category of data and actually delete when it expires. A schedule nobody executes is worse than none at all.

    Common failure: a documented policy of 24 months, with data from 2017 still sitting in backups.
    06

    Integrity and confidentiality

    Technical and organisational measures proportionate to the risk, documented per activity. This is the single most fined obligation in the regulation.

    Common failure: strong controls in production, and a spreadsheet export on someone's laptop.
    07

    Accountability

    The principle that makes the other six enforceable: you must be able to demonstrate compliance, not merely assert it. In practice that means records, assessments, approvals and dates you can produce on request. It is the obligation Whisperly exists to remove the work from.

    Read the full guidebook

    Frequently asked questions

    It replaces the spreadsheets and shared drives that most privacy programmes still run on. Whisperly maintains your records of processing, drafts DPIAs with risk scoring, routes and tracks data subject requests to their deadline, manages consent and retention, handles breach notification workflows, and keeps an exportable audit trail of every action, so an inspection is a matter of producing evidence rather than creating it.

    Audit-ready by default.

    See your entire GDPR programme running in one platform, with the evidence already in place.