Free GDPR compliance tool. Map controller/processor roles, calculate retention periods, select legal bases, and generate Article 30 records.
The General Data Protection Regulation (GDPR) requires organizations to define clear data processing roles and implement retention policies that limit how long personal data is stored. Role mapping identifies whether each entity in your data processing chain is a Controller (determines purposes and means of processing), Processor (processes data on behalf of a Controller), or Joint Controller — each role carrying distinct legal obligations.
Retention mapping ensures that personal data is not kept longer than necessary for its stated purpose, a core principle of GDPR known as storage limitation (Article 5(1)(e)). Together, role and retention mapping form the operational backbone of GDPR compliance, answering two critical questions: who is responsible for this data, and how long can we keep it?
| Role | Definition | Key Obligations | Example |
|---|---|---|---|
| Controller | Determines purposes and means of processing | Lawful basis, data subject rights, breach notification (72h), DPIA | Company using CRM to manage customer relationships |
| Processor | Processes personal data on behalf of Controller | Follow Controller instructions, security measures, breach notification to Controller | Cloud hosting provider storing customer database |
| Joint Controller | Two+ entities jointly determine purposes | Transparent arrangement defining responsibilities, single point of contact for data subjects | Two companies running a joint marketing campaign |
| Sub-Processor | Processor engaged by another Processor | Same obligations as Processor, Controller must approve engagement | CDN provider used by the cloud host |
| Data Category | Typical Retention | Legal Basis |
|---|---|---|
| Customer transaction records | 6-7 years | Tax and accounting law |
| Employee records | Duration of employment + 6 years | Employment law, limitation periods |
| Marketing consent records | Until consent is withdrawn | GDPR Article 7 |
| Website analytics | 26 months (GA default) | Legitimate interest |
| CCTV footage | 30 days | Legitimate interest |
| Job application data | 6-12 months after decision | Legitimate interest for legal claims |
| Medical records | Varies by jurisdiction (often 10+ years) | Legal obligation |
A data controller determines the purposes and means of processing personal data (decides why and how data is processed). A data processor processes data on behalf of the controller (follows the controller's instructions). Joint controllers occur when two or more entities jointly determine processing purposes. Each role has different obligations under GDPR.
Article 30 of GDPR requires controllers and processors to maintain written records of processing activities. Records must include: purposes of processing, categories of data subjects and data, recipients, international transfers, retention periods, and security measures. This tool generates Article 30 compliant records.
Retention periods depend on: legal requirements (tax records: 7 years, medical records: varies by jurisdiction), contractual obligations, legitimate business need, and data minimization principle. Under GDPR, data must not be kept longer than necessary for its purpose. This tool calculates retention periods based on data type and jurisdiction.
GDPR Article 6 defines six legal bases: Consent (freely given, specific, informed), Contract (necessary for contract performance), Legal Obligation (required by law), Vital Interests (protecting life), Public Task (official authority or public interest), and Legitimate Interests (balanced against data subject rights). Each processing activity must have a valid legal basis.
A DPIA is required under GDPR Article 35 when processing is likely to result in high risk to individuals. This includes systematic profiling, large-scale processing of special categories, and public area monitoring. The DPIA must describe processing, assess necessity and proportionality, identify risks, and define mitigation measures. This tool includes a DPIA necessity checker.
Assess GDPR compliance for your website including privacy policy, cookie consent, and data processing practices
Generate a customized privacy policy for your website or app. Supports GDPR, CCPA, COPPA compliance with tailored sections for your data practices.
Design comprehensive data classification policies with government (TS/S/C/U) or commercial (Restricted/Confidential/Internal/Public) schemas. Define handling rules for storage, transmission, disposal, and access with compliance overlays for HIPAA, PCI-DSS, GDPR, and CMMC.