Records that show how personal data was protected
Find, protect and document personal data, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| Art. 5(1)(f) | Integrity and confidentiality. | DLP response actions. → |
| Art. 5(2) | Accountability. | Signed, chained logs. → |
| Art. 30 | Records of processing. | DLP discovery inventory. → |
| Art. 32(1)(b) | Ongoing confidentiality and integrity. | Monitoring and classified events. → |
| Art. 33(5) | Breaches documented. | Case records. → |
Inventory
Find personal data before you record it
ARRTECH DLP discovery scans endpoints, file servers and SQL databases, inventories what it finds by classification and labels files by rule. IBANs are checked by algorithm, not only matched by pattern.
Security
Keep personal data from leaving
Each ARRTECH DLP rule blocks, allows and logs, asks a manager, asks the user for a justification, encrypts, quarantines or notifies.
Breaches
Document every breach
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report.
Accountability
Show a record that proves itself
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Residency
Keep the evidence on your servers
ARRTECH SIEM runs in your deployment, so the logs and case records stay where you keep them.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
Art. 33(1)
Notice to the supervisory authority. You file it.
Art. 35
Data protection impact assessment. That is your organization’s own work.
Art. 15 to 17
Data subject requests. No ARRTECH product handles them.
Art. 28
Processor terms, where ARRTECH processes personal data for you. Confirm them with us.
By rule
Naming a clause is not a claim of certification.
Art. 5(1)(f)
Process personal data with appropriate security. ARRTECH: DLP rules block, ask a manager, encrypt, quarantine or notify.
Art. 5(2)
Be able to demonstrate compliance. ARRTECH: every write hashed, signed and chained, with signed exports.
Art. 30
Maintain a record of processing activities. ARRTECH: DLP discovery inventories where personal data sits. The record itself is yours.
Art. 32(1)(b)
Ensure ongoing confidentiality, integrity and availability of systems. ARRTECH: classified events and a silent-source alert.
Art. 33(5)
Document any personal data breach, its effects and the remedy. ARRTECH: case records with type, severity and history.
Questions
Does GDPR certify products?
No. Article 42 certifies processing operations, and certification does not reduce the controller’s responsibility.
Is DLP monitoring of staff itself processing?
Yes. It needs its own lawful basis.
Does DLP find EU national identifiers?
ARRTECH does not claim classifiers for EU national identifiers.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Sources
Guide
What is GDPR?
The EU regulation on the protection of personal data, binding on controllers and processors.
What does Article 30 ask?
A written record of processing activities, kept by controllers and processors.
What does Article 33 ask?
Notice of a personal data breach to the supervisory authority, where feasible within 72 hours, and a record of every breach.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.