Screenata

Solutions / GDPR

GDPR, evidenced
rather than asserted

GDPR has no certificate and no auditor to issue one. What your enterprise customer actually asks for is a demonstrable record: which requirements apply to you, what you do about each, and proof it is operating. Screenata runs GDPR as a self-assessment program that produces exactly that, on its own or alongside any other framework you run.

See pricing
No certificate exists to buy
Self-assessment
Per framework, under 50 people
$5,988/yr
Shared control hub
NIST 800-53
Price, no sales call
Published

What running GDPR here actually looks like

A self-assessment, stated plainly

Nobody certifies GDPR. There is no equivalent of a SOC 2 report or an ISO certificate, and any vendor implying otherwise is selling you a badge. What Screenata produces is the accountability record Article 5(2) asks for: requirements scoped to your business, controls mapped to them, and signed evidence behind each one.

  • Scoped to the Articles that apply to how you actually process data
  • Every claim traceable to the evidence that supports it
  • Shareable with a customer's privacy reviewer, not with an auditor

Mapped through NIST 800-53, so the overlap collapses

Most GDPR technical requirements restate ordinary security controls, the same ones SOC 2 and ISO 27001 ask for. Screenata maps every framework to NIST 800-53 first, so a shared requirement resolves to one control and one piece of evidence no matter which framework you started with.

  • One access-control check serves GDPR Art. 32, SOC 2 CC6.1, and ISO 27001 A.8.5
  • Encryption, logging, and breach-response evidence collected once
  • Run it standalone, or add it to another framework without duplicating work

Privacy documents you still have to own

The distinctly-GDPR obligations are organizational, not technical: your record of processing, data-subject request handling, lawful basis, and processor agreements. Screenata scopes them, drafts what it can ground in your infrastructure, and tracks them to a named owner and a date. It does not pretend a scan can produce them.

  • Vendor and subprocessor inventory discovered from your codebase
  • Owners, due dates, and status tracked like any other control
  • Gaps shown as gaps rather than auto-marked compliant

Kept current between reviews

GDPR is continuous by construction, with no annual window to point at. Scheduled scans, evidence freshness, and quarterly access reviews keep the record current so a customer's privacy question has an answer on the day it arrives.

  • Evidence freshness lifecycle flags stale artifacts
  • Every agent action logged, the trail itself is the record

How a GDPR program runs here

  1. 01

    Add the framework

    Start with GDPR, or run it alongside SOC 2, HIPAA, or ISO 27001. One program either way, sharing a single evidence base.

  2. 02

    Scope what applies

    Controller or processor, EU data subjects, transfers, and processing activities determine which requirements are live.

  3. 03

    Collapse and fill

    Any security evidence you already hold maps across automatically; Vera runs collection on what is genuinely new.

Make GDPR provable, not just claimed

Book a demo and see a GDPR requirement traced to the signed evidence that proves it, and to every other framework the same control satisfies.