Control frameworkCompliance & Audit

GDPR (Data Controller) policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Map controller duties for AI services that determine why and how personal data is processed in the European Economic Area. The template covers lawful processing, transparency, individual rights, data protection impact assessments and breach handling. Confirm all duties outside the gateway separately.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

EU

Source references

4 source references

Control areas

7 mapped control areas

Deployment options

Regulated SaaS, Sovereign region

Source frameworks, standards and obligations

EU General Data Protection Regulation (EU) 2016/679ePrivacy Directive 2002/58/ECEDPB Guidelines 07/2020 on controller and processor conceptsEDPB Guidelines 4/2019 (Article 25 Data Protection by Design and by Default)

Control areas mapped by this template

Data privacy
Consent management
Data subject rights
Incident response
Breach notification
Transparency
Data minimization

Deployment options

Regulated SaaS
Sovereign region

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.