GDPR Article 30 records of processing. Built from what PostQKey finds, not what your team reports.
PostQKey scans your data estate and auto-generates a structured data inventory that maps to Article 30 requirements: data categories, processing purposes, storage locations, retention, and access.
How PostQKey output maps to Article 30 fields.
PostQKey surfaces the data, not the legal determination. Article 30 still requires your DPO to confirm purpose and legal basis. PostQKey makes the inventory automated and continuous, not the compliance decision.
| GDPR Article 30 Field | PostQKey Output |
|---|---|
| Data categories processed | Classification results: PII, PHI, financial, confidential labels per data store |
| Recipients of personal data | Access graph identities with a path to each data store |
| Purposes of processing | Detected from schema names, table naming patterns, and data store metadata (requires human confirmation) |
| Storage locations | Cloud region, provider, account ID per data store |
| Retention periods | Data age from creation date and last_modified (policy comparison requires manual input) |
| Technical security measures | Encryption state, access control type, public reachability per store |
| Third-country transfers | Data stores in non-EEA regions flagged when personal data classification is present |
Common GDPR exposure patterns PostQKey finds.
PostQKey surfaces factual findings about where personal data is, how it is stored, and who can reach it. Whether a specific finding constitutes a GDPR violation under Article 5, 25, or 32 is a legal determination that requires your DPO and counsel. PostQKey does not make that determination and does not claim GDPR certification of any kind. It gives your compliance team a complete, current inventory to work from.
Personal data in cloud regions outside the EEA (e.g., us-east-1) without a documented transfer mechanism. PostQKey flags personal data stores by region and classification type.
Connectors to external analytics platforms that receive event data containing personal identifiers. PostQKey identifies data flows where PII classification overlaps with external service integration points.
Data stores with personal data classification that are older than your documented retention periods. PostQKey flags stores by age against configurable retention thresholds.
Article 32 requires appropriate technical measures including encryption. PostQKey flags stores containing personal data that lack encryption at rest.
Start your Article 30 data map.
Connect your data stores. PostQKey builds the inventory. Your DPO confirms purposes and legal basis.