Privacy
Available nowGDPR · 2016/679
The EU General Data Protection Regulation sets the obligations for handling the personal data of people in the EU. Keel models every provision of the Regulation that binds a controller or processor, at its own numbered-paragraph level rather than collapsing each Article into a single line: 110 scored requirements in total, covering Chapters II–V together with Article 89(1)’s safeguards for research and archiving. Provisions addressed to Member States, the Commission, supervisory authorities and the Board, together with Chapter VIII’s remedies and penalties, are cited but not scored, because they place no duty on a controller or processor.
See exactly what is scored and what is not: every exclusion, by Article and paragraph
110
requirements tracked
Premium
Access
Add-on from $39/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below, all 110 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 110 requirements
- In Keel’s scored scope
- 110 leaf requirements
What Keel scores here, and what it does not
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs GDPR?
- Any company processing the personal data of people in the EU
- SaaS vendors asked to sign a Data Processing Agreement (DPA)
- Teams that need lawful basis, data-subject rights, and breach readiness in place
What Keel does
How Keel helps with GDPR
- Every controller and processor duty in the Regulation as a scored control: principles and lawful basis, data-subject rights, accountability, processor contracting, records, security, breach handling, DPIAs, the DPO and international transfers
- Paragraph-level tracking, so Article 30(1)’s controller register and 30(2)’s processor register are the separate duties they really are
- Crosswalk to your security framework so Article 32 work is not duplicated
- Readiness scored across that whole scope, rather than a hand-picked subset of the articles
Collect once, comply everywhere
GDPR shares canonical controls with PIPEDA, SOC 2 and ISO/IEC 27001 and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding GDPR rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- PCI DSS shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- FedRAMP Consolidated Rules shares canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- COPPA shares canonical controls
- Google Play Families shares canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category shares canonical controls
- PIPEDA shares canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials shares canonical controls
- ISO/IEC 42001 no shared canonical controls
- NIST AI Risk Management Framework shares canonical controls
- EU AI Act no shared canonical controls
- ESG Essentials shares canonical controls
- US Employment Law - Federal Baseline shares canonical controls
A framework is lit when at least one canonical control satisfies both GDPR and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 23 of 26 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks