GDPR Readiness

GDPR Article 30 records of processing. Built from what PostQKey finds, not what your team reports.

PostQKey scans your data estate and auto-generates a structured data inventory that maps to Article 30 requirements: data categories, processing purposes, storage locations, retention, and access.

How PostQKey output maps to Article 30 fields.

PostQKey surfaces the data, not the legal determination. Article 30 still requires your DPO to confirm purpose and legal basis. PostQKey makes the inventory automated and continuous, not the compliance decision.

GDPR Article 30 Field PostQKey Output
Data categories processed Classification results: PII, PHI, financial, confidential labels per data store
Recipients of personal data Access graph identities with a path to each data store
Purposes of processing Detected from schema names, table naming patterns, and data store metadata (requires human confirmation)
Storage locations Cloud region, provider, account ID per data store
Retention periods Data age from creation date and last_modified (policy comparison requires manual input)
Technical security measures Encryption state, access control type, public reachability per store
Third-country transfers Data stores in non-EEA regions flagged when personal data classification is present

Common GDPR exposure patterns PostQKey finds.

PostQKey surfaces factual findings about where personal data is, how it is stored, and who can reach it. Whether a specific finding constitutes a GDPR violation under Article 5, 25, or 32 is a legal determination that requires your DPO and counsel. PostQKey does not make that determination and does not claim GDPR certification of any kind. It gives your compliance team a complete, current inventory to work from.

Non-EEA storage without adequacy decision

Personal data in cloud regions outside the EEA (e.g., us-east-1) without a documented transfer mechanism. PostQKey flags personal data stores by region and classification type.

Third-party analytics receiving personal data

Connectors to external analytics platforms that receive event data containing personal identifiers. PostQKey identifies data flows where PII classification overlaps with external service integration points.

Data retained beyond documented periods

Data stores with personal data classification that are older than your documented retention periods. PostQKey flags stores by age against configurable retention thresholds.

No encryption on personal data stores

Article 32 requires appropriate technical measures including encryption. PostQKey flags stores containing personal data that lack encryption at rest.

Start your Article 30 data map.

Connect your data stores. PostQKey builds the inventory. Your DPO confirms purposes and legal basis.