SECaaS.IT

GDPR

GDPR evidence — without building a second system.

Already running a management system for ISO 27001? PRISM maps GDPR TOMs onto it instead of demanding a parallel structure. The standard catalogue is set up on request at short notice — controls you already maintain are immediately reusable.

Why now

  • • Data processing agreement or customer audit requiring up-to-date TOMs?
  • • Records of Processing Activities not maintained for months?
  • • Supervisory authority or customer asking for evidence that currently exists only scattered across systems?

Organisations already running a management system have done most of the work — processes, roles, document control — already. GDPR evidence then comes as an addition, not a new project.

What PRISM brings to GDPR compliance

No management system yet? Start with ISO 27001 — GDPR TOMs can be mapped later.

Technical and Organisational Measures

Art. 32 GDPR — TOMs demonstrable, not just documented.

PRISM assesses your existing controls against the requirements of Art. 32 GDPR and shows specifically which measures are missing, which are sufficient, and which auditors would consider inadequate. No guesswork — structured evidence.

TOM Art. 32 RoPA in PRISM ISO 27001 crosswalk
PRISM ISO — GDPR TOM Assessment

Who is this for?

Yes, if

  • Already running ISO 27001 (with PRISM or elsewhere)
  • DPO or IT management without a dedicated GDPR tool
  • Trigger: customer audit, data processing agreement or supervisory authority inquiry
  • Goal: demonstrable TOMs and RoPA without a parallel structure

Not the right fit

  • No management system yet (build ISO 27001 first)
  • Looking for legal GDPR advice as the sole goal (not covered)
  • Enterprise with a dedicated data protection management tool

Many organisations with GDPR obligations also need NIS 2 — with the integrated crosswalk you fulfil both requirements without duplicate work.

Frequently asked questions about GDPR

What are TOMs and why do they matter?
TOMs (Technical and Organisational Measures) under Art. 32 GDPR describe how a controller or processor ensures an appropriate level of protection for personal data. Without documented, up-to-date TOMs, organisations risk fines, fail data processing agreement checks, or cannot pass customer audits.
What does a complete Records of Processing Activities (RoPA) contain?
The RoPA under Art. 30 GDPR must include for each processing activity: purposes of processing, categories of data subjects and data, recipients, any third-country transfers, retention periods, and security measures. PRISM ISO allows the RoPA to be maintained directly in the platform — structured, current and exportable.
How does PRISM ISO help with GDPR?
PRISM ISO structures GDPR TOMs as executable controls and maps them onto your existing management system. Organisations already running ISO 27001 have fulfilled around 70% of GDPR TOMs — PRISM ISO shows the exact degree of overlap and what is still missing. RoPA, data protection impact assessments and Art. 32 evidence are created directly in the platform.
What does a GDPR infringement cost?
Fines under GDPR Art. 83 can reach up to €20 million or 4% of global annual turnover — depending on the severity of the infringement. In addition, data subjects may claim compensation, reputational damage can be significant, and supervisory authorities may impose temporary processing bans.
Do I need to introduce separate software for GDPR?
No. PRISM ISO is not a standalone data protection tool — it extends your existing management system with GDPR-specific controls and evidence. Organisations without a management system typically start with ISO 27001 and then map GDPR requirements onto it. This avoids a second system that needs to be maintained in parallel.

Software only — or with consultant and auditor?

Three tiers, one goal: your GDPR evidence. From licence-only to a fixed-price package including an auditor.

Compare packages →

So geht PRISM vor

Von der Lücke bis zum laufenden Betrieb.

Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.

Wo stehen Sie heute?
Was muss sich ändern?
Was können Sie dem Auditor zeigen?
Was passiert nach dem Audit?

Wo stehen Sie heute?

PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der DSGVO. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.

Was muss sich ändern?

Aus der Analyse entstehen priorisierte Maßnahmen mit Verantwortlichen, Fristen und Fortschrittsanzeige. Was kritisch ist, steht oben. Verantwortlichkeiten sind klar zugewiesen — kein Aufgaben-Ping-Pong.

Was können Sie dem Auditor zeigen?

Richtlinien, Kontrollen und Evidenz werden norm-konform verwaltet und auf Audit-Bereitschaft geprüft. Das Evidenz-Paket entsteht auf Knopfdruck — mit revisionssicherer Änderungshistorie.

Was passiert nach dem Audit?

PRISM läuft nicht bis zum Zertifikat — danach erst richtig. Wiederkehrende Aufgaben, Monitoring, Vorfallmanagement und DSGVO-Überwachungsaudits bleiben in der Plattform. Das ISMS bleibt lebendig.

Was unsere Kunden sagen

„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."

Johannes Beier

IT-Leiter · B2B Medical

Security Health Check

Alle Fallstudien lesen →

Trusted by

  • Logo GIZ
  • Logo varisano Kliniken
  • Logo Kath. St. Paulus Gesellschaft
  • Logo Planfox
  • Logo iS2
  • Logo CareSocial
  • Logo EuroTax Consulting
  • Logo nubedian
  • Logo Ypsilon
  • Logo BFMT
  • Logo Haub + Partner
  • Logo DYNAMED
  • Logo B2B Medical

Show us your existing system.

In the initial call we clarify specifically what is missing for GDPR and how quickly your catalogue can be set up.