GDPR checkFictional example
Can we share data with this supplier?
Missing: a choice to delete or get back the data, and evidence of security measures.
Selected checks, not a full GDPR assessment or approval to share data.
Baselex checks your documents against regulatory requirements, flags gaps and shows the evidence. Your experts make the final decision.Check documents against regulations. See the gaps and evidence. Your experts decide.

Documents are scattered. Requirements need checking. Your experts spend time chasing evidence before they can make the call.
For assessment preparation within an agreed scope. Your team still reviews the findings and makes the final decision.For assessment preparation in an agreed scope. Your experts make the final decision.
GDPR checkFictional example
Missing: a choice to delete or get back the data, and evidence of security measures.
Selected checks, not a full GDPR assessment or approval to share data.
A customer-support provider processing personal data on our behalf.A supplier processing data on our behalf.
Review pending. A required contract clause is missing, and security safeguards still need to be verified.Missing clause and security evidence.
Requirements checked Open a finding to follow its evidence trailTap a finding
The agreement must limit processing to documented instructions, subject to applicable legal exceptions.
Clause 3.2 · Processing instructions · page 4
“The Provider will process Customer Data only on documented instructions from the Customer, except where required by applicable law.”
The clause limits processing to documented instructions and includes the applicable-law exception.
The agreement must provide for deletion or return of personal data at the customer’s choice when the service ends, and deletion of copies unless EU or Member State law requires storage.
Section 12 · Termination and retention · pages 14 and 15
“The Provider may retain service records in line with its retention policy.”
The section gives the customer no choice to delete or return personal data and does not address existing copies.
The provider must offer sufficient guarantees and use security measures appropriate to the risks of the processing.
Security safeguards · no file supplied
No security policy, control summary or certification was available to check.
This requirement cannot yet be verified because the supporting security evidence is missing.
Add the missing clause and obtain the security evidence. Agents recheck the findings; any required human approval still applies.Request the clause and security evidence. Your team reviews the updated findings before deciding.
Real GDPR requirements; fictional documents and findings. Selected processor checks, not a full GDPR assessment or approval to share data.Fictional example. Selected processor checks, not a full GDPR assessment or approval to share data. Read the EDPB guidance (opens in a new tab).
Available for demos and pilots.
Every review starts with an agreed scope.
Define the question, requirements and documents to include.
Baselex checks the evidence and flags gaps or conflicting information.
Your team reviews the findings, follows up where needed and decides.
Tell us what you're checking. We'll discuss the scope and show how Baselex could support your team.See the findings and evidence your team would receive.
Request a demo