Custom software that puts your GDPR obligations into practice within your own systems landscape: a record of processing activities, DPIA workflow, data subject rights, consent management, retention, the breach procedure and the DPO dashboard that brings it all together. Not a policy CMS or training portal, but a platform that makes Article 30, Article 35 and Articles 12 to 22 work in practice.
Record of processing activitiesDPIA toolingData subject rightsDPO dashboard
The GDPR (Regulation 2016/679, supplemented in the Netherlands by the Dutch GDPR Implementation Act) consists of roughly one hundred articles that together demand one thing: organisations must be able to demonstrate control over the personal data they process. What happens to that data, on what legal basis, for how long, with whom it is shared, with what security, and how the data subject can exercise their rights. That is not one document or one tool, but a set of interrelated processes.
A GDPR compliance platform is the software layer that supports those processes. It covers the record of processing activities under Article 30, the DPIA methodology under Article 35, the consent mechanism under Articles 6 and 7, the handling of access, rectification and erasure requests under Articles 12 to 22, the breach procedure under Articles 33 and 34, and the retention rules that follow from Article 5. All of it is integrated with your own systems (HR, CRM, ERP, marketing platform, ticketing), so that a question from a data subject or an auditor can be answered within a workable timeframe.
We do not replace widely available off-the-shelf products such as OneTrust, TrustArc, Securiti.ai or DataGrail where they do the job. We build custom solutions when you need deeper integration, when your sector has additional requirements, or when your DPO or privacy officer runs up against the limits of a commodity tool in practice. This fits within broader projects around ISO 27001 compliant software, DORA compliance software, and is a logical building block in an enterprise software project.
Three types of GDPR platform we build.
Most projects start in one of these three forms. In the first conversation we advise which approach best suits the scale of your processing, the number of systems to connect and the maturity of your privacy organisation.
Compact project · fixed sprint budget
Processing register and data subject rights portal
A compact platform in which your record of processing activities (Article 30) is maintained by process owners rather than by a single privacy officer in an Excel file. Linked to it is a data subject rights workflow: a data subject submits a request, it moves through a ticket flow with SLA monitoring, and the handling is recorded for the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Suited to organisations that have only recently begun serious GDPR operations.
The compact package, extended with DPIA tooling (Article 35): a structured assessment workflow with risk scoring, purpose limitation check, necessity analysis and controls, linked to an organisation-specific risk framework. Plus consent management at processing level with granular withdrawal, and a third-party register (Article 28) in which processors, sub-processors, data processing agreements and international transfers are traceable. Suited to organisations with an active DPO and several business units.
DPIA flowConsent per processingProcessor registerRisk scoring
Larger project · fixed sprint budget
End-to-end privacy platform with deep integrations
The full platform connected to your core systems — HR system, CRM, marketing stack, ERP, ticketing, data warehouse, email archive — so that an erasure or access request is searched automatically across ten or more sources. Includes breach management with the 72-hour notification timer towards the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), anonymisation and pseudonymisation tooling, a retention engine, Schrems II tracking and the DPO cockpit, in which your privacy officer oversees the entire organisation. Suited to healthcare providers, financial institutions, media companies and large retailers.
10+ system integrationsBreach timerAnonymisationRetention engineSchrems II
What you receive at the end of a project.
A production-ready GDPR compliance platform, in your own environment, integrated with your own systems, with the documentation your DPO and auditor expect.
Record of processing activities under Article 30For each processing activity: purpose, legal basis, categories of data subjects, categories of personal data, recipients, retention period, international transfers and the associated security measures. Maintainable by process owners themselves, not only by your DPO.
DPIA tooling based on Article 35Structured assessment flow with necessity and proportionality testing, risk register, control measures and residual risk scoring. Linked to an organisation-specific risk framework, not a one-size-fits-all checklist.
Data subject rights portal (Articles 12 to 22)Request flow for access, rectification, erasure, data portability, objection and restriction. Automated searching across connected source systems, structured case building, audit trail, SLA monitoring and standardised response templates reviewed by legal counsel.
Processing-level consent managementGranular consent per processing purpose, withdrawal flow, explicit age verification where relevant, and an audit log of what was accepted, when, and under which version of the privacy notice. Standard integration with your cookie banner (CMP under TCF 2.2) and your marketing stack.
Third-party register under Article 28Every processor and sub-processor with contract version, purpose limitation, data categories, processing location, certifications, SCC status and transfer mechanism. Workflow for new processing agreements and periodic review.
Breach management with 72-hour timerIncident flow with severity classification, data subject impact analysis, DPA notification template (Article 33), data subject notification template (Article 34), lessons-learned archive, and the statutory timer that visibly counts down from the moment of discovery.
Retention engine and data minimisation controlsRetention rules per dataset and per processing activity, automatic deletion or anonymisation jobs, periodic data minimisation reports and an exception flow for statutory retention obligations. Particularly useful for HR data, where data minimisation and transparency must go hand in hand.
Anonymisation and pseudonymisation toolingAutomatic PII detection in new datasets, configurable anonymisation strategies (k-anonymity, generalisation, suppression, tokenisation) and a pseudonymisation vault for reversible cases. Usable by data teams in BI and AI projects.
International transfers (Articles 44 to 49)Tracking of data flows outside the EEA, with SCC status, Trans-Atlantic Data Privacy Framework status, evidence of EU data residency and the transfer impact assessment arising from Schrems II. Alerts when a supplier changes region.
DPO cockpitA single dashboard in which your Data Protection Officer or privacy officer can see the organisation's position: open data subject requests, ongoing DPIAs, expired processor agreements, open breach incidents, retention overruns and the status of international transfers.
Privacy-by-design tooling for your development teamsAn API scanner that checks new endpoints for PII, automatic detection of personal data in datasets, and build-time checks that prevent a new feature from processing personal data without a registered legal basis. This makes Article 25 genuinely operational.
Codebase, documentation and operations runbookFull source code in a Git repository, architecture overview, integration documentation per source system and operational runbooks for your IT partner or in-house IT. Plus an optional maintenance contract covering monitoring, patch management, regulatory updates and ongoing development.
When a custom GDPR platform is the right choice.
Four patterns we see among organisations that approach us about a custom privacy platform. If you recognise one of them, we would be glad to talk further.
Depth of integration
Off-the-shelf tools don't integrate deeply enough
You have OneTrust, TrustArc or a similar tool, but a right-to-erasure request still requires manual searching across ten or more internal systems. The commodity tool covers the governance layer, but not the operational handling of your own data. This wears down the DPO and lengthens turnaround times.
Sector requirements
Additional regime on top of the GDPR
You fall under a sector overlay: NEN 7510 for healthcare, DNB and Wft requirements for the financial sector, BIO for government, or the GDPR link arising from the AI Act for your AI systems. A single architecture must cover several frameworks at once, with a common evidence source and no separate spreadsheets per regime.
Scale and volume
Large volumes of personal data and many processes
You are a media group, retailer, marketing agency, recruiter or platform organisation holding personal data on hundreds of thousands or millions of data subjects. The volumes make a spreadsheet-based approach unmanageable; data subject rights requests arrive weekly and must be handled automatically across multiple systems.
Incident context
Following a fine, complaint or audit finding
The Dutch Data Protection Authority has investigated a complaint, imposed a fine or reported an audit finding. Or a major business customer has determined during due diligence that your operational privacy controls cannot be sufficiently verified. There is now both internal and external pressure to invest structurally in tooling, not just in policy.
Not yet sure about a large project?
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
A conversation in which we understand which processing you carry out, which systems are involved, how your privacy organisation is currently structured (DPO, privacy officers, legal, security) and which off-the-shelf tools are already in use. We also map the additional regimes — NEN 7510, the AI Act, DNB requirements, BIO — and determine which platform approach is appropriate.
2
Discovery and architecture
A workshop with your DPO, security officer and the business owners of your core systems. We run a data mapping session (which personal data lives where, on what legal basis, and with what retention), document the priority processing activities, and choose architectural patterns that connect scalably to your source systems. The outcome is a data architecture, an initial platform architecture and a sprint plan that tackles the riskiest integrations first.
3
Build in sprints, with legal review running alongside
We work in two-weekly sprints. Your DPO and legal adviser take part in reviewing the processes the tool supports: a DPIA template must be legally sound, a DSAR response template must hold up legally, and a processing register field must align with the way your supervisory authority reasons about it. We build, they test, and the iteration in between makes the platform usable.
4
Rollout, training and ongoing management
Phased rollout: first the processing register goes live, then the DSAR flow, then DPIA, then breach management, then the deeper integrations, so your organisation grows along with the tool. Two training sessions for your DPO and privacy officers, a short video explainer for process owners, and a DPO cockpit overview for your board. From go-live we provide monitoring, patch management, dependency updates and the changes that follow from new Dutch DPA guidance or EDPB guidelines.
Frequently asked questions about a GDPR compliance platform.
The questions DPOs, privacy officers and compliance managers ask us before a project begins.
What is the difference between GDPR and ISO 27001 in this context?
The GDPR is a legal framework for the protection of personal data and covers legal bases, data subject rights, purpose limitation, data minimisation and the organisation of privacy governance. ISO 27001 is an international standard for an Information Security Management System and covers information security more broadly: not only personal data, and not specifically focused on the legal rights of data subjects. They overlap on security controls (access, encryption, logging, breach response) but are not interchangeable. An ISO 27001 certificate does not automatically cover the GDPR, and vice versa. We are happy to build one architecture that incorporates the requirements of both frameworks; see also our page on ISO 27001 compliant software.
Do you replace OneTrust or TrustArc?
Almost never for the broad range of privacy governance functions. OneTrust, TrustArc, Securiti.ai and DataGrail cover much of the market well, with an active roadmap around new regulation. We build custom solutions when you run into the limits of those tools: deep integration with your own source systems for automated DSAR handling, sector-specific overlays (healthcare, financial services, government), or a DPIA flow that must align closely with your organisation's specific risk framework. In some cases a commodity tool runs the register and we build the operational layer around it. We give that advice in the first conversation, being honest about what you are better off buying.
How does the platform support data minimisation and transparency in HR data?
HR is one of the most sensitive processing areas under the GDPR: application data, assessment data, sickness records, salary details and sometimes special category data (medical, racial, religious). In practice, data minimisation means the HR system only keeps the fields operationally needed for the stated purposes, and that expired data is automatically deleted or anonymised. Transparency means that an employee can, on request, immediately see what data is held about them, on what legal basis, for how long and with whom it is shared. The platform integrates with your HR system (AFAS, Visma, Workday, Personio or another), applies retention rules per dataset, gives employees a transparency portal, and gives HR the tooling to delete applicant data in time, a frequently cited Dutch DPA (AP) finding.
How often do AP fines or complaints occur, and how does the platform help?
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) publishes hundreds of investigations and fines each year, with significant amounts for matters such as unlawful profiling, inadequate security of personal data, incorrect legal basis for marketing and retaining applicant data for too long. The platform helps in two ways: proactively, by making GDPR obligations enforceable in day-to-day operations (no processing without a legal basis, no marketing without a withdrawal option, no data kept beyond the retention period), and reactively, by allowing you to present a clean file in the event of a complaint or audit, in which all DPIAs, breach notifications, processor agreements and data subject rights handling are easy to find. Burden of proof is a large part of the discussion with the Dutch Data Protection Authority.
What does the platform do about the overlap between the AI Act and the GDPR?
The AI Act sets requirements for AI systems that in many cases process personal data, and the GDPR applies here too. For high-risk AI systems under the AI Act, a fundamental rights impact assessment is mandatory, which in practice is often combined with the DPIA under Article 35 of the GDPR. The platform supports that combined assessment flow: AI-specific risks (bias, explainability, training data provenance) are measured in the same tool as privacy risks. For organisations developing or procuring AI systems, this is a more efficient route than keeping two separate processes running.
What determines the cost of a GDPR compliance platform?
Four things: the scope (only the register and data subject rights, or the full platform with DPIA, breach handling, retention and integrations), the number of source systems we need to integrate with, the additional regimes (NEN 7510, AI Act, DNB, BIO) and the maturity of your privacy organisation. An organisation where the DPO is active and the policy is in place moves faster than one where the DPO has just been appointed and the policy is being written in parallel. We outline the range in the first conversation and always work with fixed sprint prices, so you won't face any surprises.
Do you also build for healthcare, finance, marketing and government?
Yes. In healthcare, the platform almost always runs alongside the requirements of NEN 7510 (patient logging, authorisation, purpose limitation). We build one architecture that covers both the GDPR and NEN 7510 at the same time. In the financial sector, it overlaps with our projects on DORA compliance software and KYC and AML compliance software, as operational resilience and customer data management are closely intertwined with the GDPR. For marketing and media companies, the emphasis lies on consent management, profiling controls and granular retention. For government, it aligns with BIO and with reporting to the Dutch Data Protection Authority. For organisations that also report on ESG and sustainability obligations, we sometimes build a combined governance platform with our CSRD/ESG reporting software.
What do you do in the event of a data breach after go-live?
The management contract covers operational support for incidents. The platform itself contains the breach flow with the 72-hour timer, severity classification and notification templates for the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, article 33) and for data subjects (article 34). We support the technical triage, impact analysis and communication. Lessons learned feed back into your DPIAs, your record of processing activities and, where necessary, the control measures of the connected systems, so the same scenario does not happen twice.
Talk to us about your GDPR compliance platform.
A free, no-obligation half-hour introductory call. We listen to which processing activities you carry out, which standard tools are already running, what your DPO and privacy organisation look like today and which additional regimes apply, and we give direction you can use straight away, even if we don't end up working together.
From idea to app in one day. Validate your idea first with a working prototype.Discover OneDayBuild →
Cookies on appfront.nl
Appfront uses cookies and similar technologies to keep the website working properly, for analytics and for marketing. You choose what you allow. Read more in our privacy policy.