Give your privacy programme
an operational backbone.
01GRC isn't a DPO tool — it's where the processes that underpin GDPR live and stay current: your records of processing, your data map, retention, processor relationships, security of processing, and the evidence that ties it all together. Your DPO sets the direction, 01GRC keeps the operational record honest and audit-ready.
The operational record, kept honest.
Every claim here maps to a shipped feature. 01GRC facilitates the processes that support GDPR compliance — it does not replace your DPO, your privacy counsel, or a dedicated data-subject-rights platform.
One living data map
Records of processing, retention and transfers are produced from the same processing map your teams keep current — not a separate spreadsheet that drifts.
Article 30 on demand
Generate a Records of Processing Activities register as PDF or XLSX, built directly from your data-flow inventory.
Security of processing, proven
An information-security backbone with control testing, asset classification and immutable evidence supports your Article 32 measures.
Accountability built in
Activity logging on every entity, versioned policies and notices, and immutable sign-offs make the record of what you did and when defensible.
Honest about the boundary
We are explicit about what the platform does and does not do — because your DPO and your regulator will be.
The operational processes that support GDPR.
Where GDPR asks for a maintained record or a repeatable process, 01GRC gives you a working feature — each one mapped to its article.
What 01GRC is — and is not.
We are explicit about the boundary, because your DPO and your regulator will be.
01GRC is the operational system of record that supports your privacy programme. It does not replace your DPO, your privacy counsel, or a dedicated data-subject-rights platform.
Strengths that make GDPR easier.
Business-first model
Department → Process → Asset → Data Flow → Vendor, with dependency mapping and derived process/vendor criticality, so a breach's blast radius is visible.
Immutable evidence
Activity logs, snapshotted sign-offs, encrypted and virus-scanned attachments, soft deletes by default.
Role-based access & multi-tenancy
Granular permissions, organisation-scoped data, MFA, session controls, IP blocklisting.
Deploy anywhere
Self-contained with no external dependencies — deploy on-premises, in your private cloud, or fully air-gapped.
One record, every privacy stakeholder.
DPO / Privacy lead
A maintained Article 30 register, data map and processor inventory, plus the evidence trail to demonstrate accountability.
Security / IT
Security of processing (Article 32) managed and tested alongside the rest of the ISMS.
Risk & Compliance
GDPR gap analysis, privacy / governance reviews, and corrective actions in one place.
01GRC facilitates the operational processes that support GDPR compliance — records of processing (Article 30), data mapping, retention, international-transfer visibility, processor oversight (Article 28), security of processing (Article 32), breach handling, training and accountability evidence. It is not a dedicated DPO console and does not provide data-subject-rights automation, consent management, DPIA workflows, or statutory breach notification. Responsibility for GDPR compliance, and for the legal assessments it requires, remains with your organisation and its DPO.
One platform, every standard you answer to.
GDPR is one of several frameworks built in — and you can add your own. More framework guides are on the way.
- ISO/IEC 27001:2022
- ISO/IEC 27701
- DORA
- GDPR
- NIS2
- CIS Controls v8.1
- Add your own
See your privacy programme
the way it should look.
Book a personalised walkthrough — we'll demo your records of processing, data map, processor oversight and security of processing on data shaped like yours.