Noru

GDPR compliance software: what to look for

The obligations that actually carry weight with a supervisory authority, and how to tell which tools support them.

GDPR compliance software should hold the accountability record that Article 5(2) requires you to be able to produce: the Article 30 register, DPIAs where risk is high, lawful basis and legitimate interests assessments, processor contracts under Article 28, transfer safeguards, data subject rights handling within the one-month deadline, and breach response inside 72 hours. Most tools cover the fields. The ones worth buying can show those records were accurate at a point in time, keep them current as systems change, and keep the data itself in the EU — because a privacy tool that creates its own transfer problem is an awkward thing to explain.

What to look for

Can it demonstrate accountability, not just store records?

Ask what the tool produces if a supervisory authority asks you to show the state of your programme on a given date. Versioning, approval trails and a visible review state are the difference between records and evidence.

Does it keep the register current as systems change?

A register that depends on someone remembering to update it after each release is wrong most of the time. Establish what detects change, and what happens when a new field, vendor or hosting region appears.

How are data subject rights actually handled?

The one-month deadline runs from receipt. Look at intake, identity verification, search across every system holding personal data, redaction of third-party data, and the audit trail of what was disclosed — that is where requests overrun, not in the policy.

Where does the tool host your data?

A privacy platform hosted outside the EU means your compliance evidence is itself a third-country transfer requiring safeguards and a place in your own records. Ask about residency, subprocessors and whether a DPA and SLA come as standard.

Does it reuse security work you have already done?

The GDPR expects appropriate technical and organisational measures. If you already run ISO 27001 or SOC 2, a tool that maps those controls to the GDPR's expectations saves duplicating evidence for a second audience.

The kinds of tool on the market

Four shapes of vendor, described by category rather than by name. Which one fits depends on how fast your systems change and how much judgement you need to buy in.

Broad enterprise suites

Large, modular GRC platforms that cover most regimes through separately licensed modules, usually with a long implementation and a dedicated administrator.

Best fit: Large organisations with a compliance team big enough to own configuration, and budget that tolerates a multi-module licence.

Point tools

Focused products that do one job well — consent, DSAR intake, cookie scanning, vendor questionnaires — and integrate loosely with whatever else you run.

Best fit: Teams with one acute, well-bounded problem, who accept that the register tying everything together lives somewhere else.

Consultancies and managed services

People rather than software: an external DPO or advisory retainer that produces the documentation on your behalf, often in documents you then own.

Best fit: Organisations without in-house expertise who need judgement more than tooling, and who can accept that the output is a snapshot.

Compliance operations platforms

Systems that connect to what you already run, derive the records from live signals, and keep them current between audits rather than regenerating them before one.

Best fit: Teams whose systems change faster than documents can be maintained by hand, and who need to evidence a current state on demand.

Where Noru fits

Noru derives the Article 30 register and the data map from the systems that hold personal data, so the accountability record reflects the current state rather than the last review.

Privacy and security run from one control library, so the technical and organisational measures evidenced for ISO 27001 or SOC 2 also answer the GDPR's expectations without a second collection exercise.

Noru runs with EU data residency, encryption in transit and at rest, role-based access control and a published subprocessor list, with a DPA and SLA in every deployment — so the tool does not become a transfer you have to justify.

FAQ

Common questions

Talk to us

What should GDPR compliance software actually cover?

The accountability artefacts: the Article 30 record, DPIAs under Article 35, lawful basis and legitimate interests assessments, Article 28 processor contracts, international transfer safeguards, data subject rights workflows within the one-month deadline, and breach response within 72 hours.

Do we need GDPR software, or will documents do?

Documents are legally sufficient. They stop being workable when the number of processing activities exceeds what one person can reconcile after each release, when several entities each need their own register, or when you have to prove the record was accurate at a past date rather than today.

Does the tool itself need to be hosted in the EU?

Not strictly, but a platform hosted outside the EU makes your compliance data a third-country transfer that needs safeguards and an entry in your own records. Many EU organisations treat residency as a hard requirement precisely to avoid that circularity.

Can software make us GDPR compliant?

No. Software can keep the record current, surface gaps and evidence that controls operate. Whether processing is lawful, necessary and proportionate remains a judgement your organisation is accountable for, and the tool should record who made it rather than obscure it.

How does GDPR software relate to ISO 27001 or SOC 2?

They answer different questions. Security frameworks evidence that controls operate; the GDPR governs the lawfulness of processing personal data. Security certification supplies part of the technical and organisational measures the GDPR expects, but it is not GDPR compliance and cannot be presented as such.

See Noru against your own systems

A 45-minute walkthrough against your frameworks, your integrations and your evidence.