Compliance — GDPR
72-hour GDPR breach notification — tracked from the moment of detection
GDPR Article 33 gives organisations 72 hours to notify their supervisory authority after becoming aware of a personal data breach. ManySignal detects breaches, starts the countdown automatically, and pre-populates the notification. All EU customer data stays in AWS EU regions.
GDPR — what Article 32 and 33 require in plain language
Article 32 — Security of Processing
Controllers and processors must implement 'appropriate technical and organisational measures' including encryption (Art. 32(1)(a)), ongoing confidentiality (32(1)(b)), availability and resilience (32(1)(c)), and regular testing of security measures (32(1)(d)). ManySignal provides evidence of continuous monitoring as the operational component of these measures.
Article 33 — 72-hour Breach Notification
On becoming aware of a personal data breach, the controller must notify their lead supervisory authority without undue delay and within 72 hours. The notification must include: the nature of the breach, categories of data affected, approximate number of individuals, likely consequences, and measures taken. ManySignal detects, classifies, and packages all of this information automatically.
Control mapping — GDPR to ManySignal capabilities
| GDPR Article | Requirement | ManySignal Capability |
|---|---|---|
| Art. 25 | Data Protection by Design and by Default | Access minimisation monitoring — alerts when systems access data beyond documented processing purposes |
| Art. 30 | Records of Processing Activities | Data flow mapping evidence — access logs document which systems and identities process which data categories |
| Art. 32(1)(b) | Ongoing Confidentiality and Integrity | Continuous encryption-in-transit and access control monitoring — evidence of ongoing technical security measures |
| Art. 32(1)(d) | Testing and Evaluation of Security Measures | Automated continuous testing evidence — anomaly detection rate, coverage, and alert disposition over time |
| Art. 33 | Notification of Breach to Supervisory Authority (72 hours) | Breach detection with 72-hour countdown — incident management tracks discovery time, affected data, and notification status |
| Art. 34 | Communication of Breach to Data Subjects | Affected individual count and contact information compiled from incident data for subject notification |
| Art. 35 | Data Protection Impact Assessment (DPIA) | Risk indicator data — threat intelligence and access anomaly data informs DPIA risk rating maintenance |
| Art. 44-49 | International Data Transfers | Cross-border data flow monitoring — alerts on data transfer to systems outside approved geographic boundaries |
72-hour notification workflow
- T+0
Detection
ManySignal detects the breach indicator — unauthorised access, data exfiltration, credential compromise. Discovery timestamp recorded automatically.
- T+0
72-hour countdown starts
Case management system starts the 72-hour countdown. Analyst receives immediate notification with breach classification and preliminary scope.
- T+4 hrs
Preliminary assessment
Triage agent completes initial evidence collection — affected data categories, affected system scope, and preliminary individual count.
- T+24 hrs
Supervisor notification draft
Pre-populated Art. 33 notification form available for review — nature of breach, likely consequences, and measures taken (including containment actions).
- T+72 hrs
Supervisory authority notification deadline
System sends escalation alert if notification not yet submitted. Lead DPA's reporting portal URL and submission instructions included in the case record.
DPA and certification status
ManySignal's GDPR Article 28 Data Processing Agreement is available at /legal/dpa. ManySignal's lead supervisory authority is the Data Protection Commission (DPC, Ireland). SOC 2 Type II available under NDA at trust@manysignal.com. ISO 27001:2022 certification in progress.
GDPR compliance — auditor questions
Does ManySignal process personal data as a Data Controller or Data Processor under GDPR?
ManySignal acts as a Data Processor (Article 4(8) GDPR) when processing personal data contained in customer telemetry — employee authentication logs, identity events, access records. The customer is the Data Controller. ManySignal's Data Processing Agreement (DPA, available at /legal/dpa) specifies the processing purposes, data categories, retention periods, and sub-processor list as required by Article 28.
How does ManySignal support the 72-hour breach notification requirement (Article 33)?
When ManySignal detects a personal data breach, the case management system records the discovery timestamp and starts the 72-hour countdown. The incident record tracks: affected data categories (special categories under Art. 9 are flagged separately), approximate number of affected data subjects, and the likely consequences of the breach. The notification draft is pre-populated with the information required by Article 33(3) for submission to the relevant supervisory authority.
Where does ManySignal store EU customer data?
EU customer data is stored and processed exclusively in AWS EU-WEST-1 (Ireland) or EU-WEST-2 (Frankfurt) — customer's choice at deployment. No EU personal data is transferred to AWS US regions under default deployment. Any support access by non-EU ManySignal staff is subject to SCCs and documented in the DPA. Full data residency details are at /regions/european-union.
Which supervisory authorities should EU customers notify in the event of a breach?
For GDPR, each member state has a Data Protection Authority (DPA). The lead supervisory authority is determined by the location of the controller's main establishment. Key EU DPAs include: CNIL (France), BfDI/LfDI (Germany, per Land), DPC (Ireland), Garante (Italy), AEPD (Spain), UODO (Poland), and DPA (Netherlands). ManySignal's incident management can track the applicable DPA per customer deployment configuration.
Does ManySignal support GDPR data subject rights (access, erasure, portability)?
ManySignal's role is monitoring — it monitors access to systems that hold personal data, but does not hold the source personal data itself. For GDPR data subject requests, ManySignal provides access log evidence (which systems processed which data about which individuals, when) that supports the customer's response to DSARs. The platform does not directly process DSARs for individuals whose data appears in customer log files.
Start GDPR-compliant monitoring in the EU
Execute the DPA, deploy in AWS Ireland or Frankfurt, and have 72-hour breach notification tracking active from day one.