GDPR
GDPR evidence — without building a second system.
Already running a management system for ISO 27001? PRISM maps GDPR TOMs onto it instead of demanding a parallel structure. The standard catalogue is set up on request at short notice — controls you already maintain are immediately reusable.
Why now
- • Data processing agreement or customer audit requiring up-to-date TOMs?
- • Records of Processing Activities not maintained for months?
- • Supervisory authority or customer asking for evidence that currently exists only scattered across systems?
Organisations already running a management system have done most of the work — processes, roles, document control — already. GDPR evidence then comes as an addition, not a new project.
What PRISM brings to GDPR compliance
- TOM catalogue (Technical and Organisational Measures per Art. 32 GDPR) as structured controls — mapped onto your existing management system
- Gap analysis engine running today for ISO 27001, ISO 9001, C5, SOC 2, NIS 2 and TISAX — your GDPR catalogue is set up on request at short notice
- Multi-framework crosswalk: controls already fulfilled for ISO 27001 automatically reused for GDPR TOMs
- Records of Processing Activities (RoPA) maintained directly in the platform
- AI assessment of your privacy policies and procedures against GDPR requirements
- Internal audit, management review and continuous improvement directly in the platform
No management system yet? Start with ISO 27001 — GDPR TOMs can be mapped later.
Technical and Organisational Measures
Art. 32 GDPR — TOMs demonstrable, not just documented.
PRISM assesses your existing controls against the requirements of Art. 32 GDPR and shows specifically which measures are missing, which are sufficient, and which auditors would consider inadequate. No guesswork — structured evidence.
Who is this for?
Yes, if
- Already running ISO 27001 (with PRISM or elsewhere)
- DPO or IT management without a dedicated GDPR tool
- Trigger: customer audit, data processing agreement or supervisory authority inquiry
- Goal: demonstrable TOMs and RoPA without a parallel structure
Not the right fit
- No management system yet (build ISO 27001 first)
- Looking for legal GDPR advice as the sole goal (not covered)
- Enterprise with a dedicated data protection management tool
Many organisations with GDPR obligations also need NIS 2 — with the integrated crosswalk you fulfil both requirements without duplicate work.
Frequently asked questions about GDPR
- What are TOMs and why do they matter?
- TOMs (Technical and Organisational Measures) under Art. 32 GDPR describe how a controller or processor ensures an appropriate level of protection for personal data. Without documented, up-to-date TOMs, organisations risk fines, fail data processing agreement checks, or cannot pass customer audits.
- What does a complete Records of Processing Activities (RoPA) contain?
- The RoPA under Art. 30 GDPR must include for each processing activity: purposes of processing, categories of data subjects and data, recipients, any third-country transfers, retention periods, and security measures. PRISM ISO allows the RoPA to be maintained directly in the platform — structured, current and exportable.
- How does PRISM ISO help with GDPR?
- PRISM ISO structures GDPR TOMs as executable controls and maps them onto your existing management system. Organisations already running ISO 27001 have fulfilled around 70% of GDPR TOMs — PRISM ISO shows the exact degree of overlap and what is still missing. RoPA, data protection impact assessments and Art. 32 evidence are created directly in the platform.
- What does a GDPR infringement cost?
- Fines under GDPR Art. 83 can reach up to €20 million or 4% of global annual turnover — depending on the severity of the infringement. In addition, data subjects may claim compensation, reputational damage can be significant, and supervisory authorities may impose temporary processing bans.
- Do I need to introduce separate software for GDPR?
- No. PRISM ISO is not a standalone data protection tool — it extends your existing management system with GDPR-specific controls and evidence. Organisations without a management system typically start with ISO 27001 and then map GDPR requirements onto it. This avoids a second system that needs to be maintained in parallel.
Software only — or with consultant and auditor?
Three tiers, one goal: your GDPR evidence. From licence-only to a fixed-price package including an auditor.
So geht PRISM vor
Von der Lücke bis zum laufenden Betrieb.
Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.
Wo stehen Sie heute?
PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der DSGVO. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.
Was unsere Kunden sagen
„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."
Johannes Beier
IT-Leiter · B2B Medical
Security Health CheckTrusted by
Show us your existing system.
In the initial call we clarify specifically what is missing for GDPR and how quickly your catalogue can be set up.