GDPR compliance OS for EU agencies

The GDPR compliance
operating system for EU agencies.

Replace the spreadsheet, the consultant retainer, and the shared drive with one platform that keeps your records, vendors, and DSARs audit-ready — automatically.

custodia / nordlicht-agency.euAudit readinessEU-WEST · FRA1
Readiness score
82/ 10014 this quarter
Export evidence packArt. 30 register
Art. 30 register — Nordlicht GmbH12 processesCOMPLETE
DSAR · erasure request #1184day 6 of 30IN PROGRESS14 Aug
Transfer assessment — Segment (US)SCC module 2REVIEW DUE02 Aug
Cookie banner — 4 client domainsTCF v2.2LIVE
Breach log — vendor incident 004272h clock closedREPORTED

The old way of doing compliance doesn't scale.

Three failure modes we see in every agency before they switch.

01Fragmentation

Your compliance programme is eleven files and one person's memory.

Processing records in a spreadsheet, DPAs in a shared drive, assessments in a consultant’s Word template, decisions in email. Nothing reconciles, and no one can prove what was true on a given date.

Average agency: 4 tools, 0 audit trail
02Exposure

Enforcement no longer waits for a data breach.

Supervisory authorities across the EU open inquiries from complaints, cookie sweeps and vendor chains. Fines reach 4% of global turnover, and “we intended to document it” has never been a defence.

€1.2bn+ in GDPR fines issued in 2025
03Cost of manual work

DSARs and ROPA upkeep consume billable weeks.

Every request means chasing systems, exporting data, redacting third parties and hitting a statutory clock by hand. Every new vendor means re-reading the register nobody has updated since onboarding.

9–14 hours per data subject request
Platform

One system for every compliance obligation.

Eight modules that cover records, vendors, requests, consent, and breach response — connected, not siloed.

01

Records of processing

A living Art. 30 register with lawful basis, retention, recipients and transfer routes per activity. Versioned, so you can show what the record said last March.

Art. 30
02

Gap assessment

38 controls mapped to the Regulation, scored and prioritised by risk and effort. Re-run quarterly to evidence continuous improvement.

Art. 24 · 32
03

Vendor intelligence

A maintained profile for every common processor: sub-processors, hosting region, transfer mechanism, DPA link and known enforcement history.

Art. 28 · 44
04

DSAR automation

Intake form, identity verification, system-by-system collection tasks, redaction workflow and a statutory clock that escalates before day 30.

Art. 15–22
05

Cookie consent (CMP)

IAB TCF v2.2 certified banner, per-domain configuration, Google Consent Mode signals and a tamper-evident consent proof log.

ePrivacy
06

Breach management

Severity assessment against EDPB criteria, the 72-hour notification clock, notifiable-authority routing and a defensible incident record.

Art. 33 · 34
07

Audit readiness dashboard

One score per entity, one evidence pack per request. Everything a supervisory authority or an enterprise procurement team asks for, exported in a click.

Art. 5(2)
08

AI compliance advisor

Retrieval-grounded answers over the actual legal corpus, scoped to the jurisdiction you are working in and cited down to the paragraph.

RAG · cited
AI advisor

Ask a question. Get a cited answer.

Grounded in the Regulation, EDPB guidance, and national DPA decisions — scoped to the jurisdiction you're working in.

It's the first tool that answers like someone who actually read the guidance.

Regulation (EU) 2016/679 — full text99 articles · 173 recitals
EDPB guidelines, opinions & recommendations142 documents
CJEU judgments on data protectionSchrems II → 2026
National DPA guidance — IE, FR, DE, NL, ESDPC · CNIL · DSK · AP · AEPD
Published enforcement decisions & sanctions2,400+ decisions
Corpus last updated 12 July 2026
Advisor · jurisdiction IE
A client wants to run a prize draw using their newsletter list. Is consent still valid?

No. Consent obtained for newsletter delivery does not extend to a prize draw — the new purpose is incompatible with the one disclosed at collection, and the DPC treats re-purposing of marketing lists as a separate processing operation requiring fresh, specific consent.

Art. 6(4)Compatibility test for further processing
EDPB 05/2020Consent must be specific to each purpose (§ 56)
DPC IEGuidance on direct marketing, 2023 — § 4.2
Attach to ROPA entryOpen remediation taskExport as client memo
Pricing

Simple pricing, built for agencies.

One plan for growing teams, one for enterprises with custom requirements.

ProfessionalMost chosen
€79/mo, billed yearly

The complete OS for growing agencies.

Unlimited users & processing activities
Unlimited vendors & DPIAs
Cookie consent (50 domains)
AI compliance advisor (2,000 queries)
Start free trial
Enterprise
Custom

For groups running several legal entities or custom controls.

Everything in Professional
Custom data residency
SSO & custom roles
Dedicated account manager
REST APIs (Enterprise only)
Contact us
Cancel anytime20% off billed annuallyVAT calculated at checkout

Built to survive an audit.

Security and residency controls that hold up under scrutiny — from a supervisory authority or an enterprise procurement team.

ResidencyEU data residencyAll data stored and processed on AWS Dublin (eu-west-1). No transfer outside the EEA, including for support access.
AccessSSO & granular rolesSAML and OIDC single sign-on, SCIM provisioning, per-entity roles so client staff see only their own register.
AccountabilityImmutable audit loggingEvery change to a record, assessment or consent is written to an append-only log with actor, timestamp and prior value.
InfrastructureEnterprise-grade operationsEncrypted at rest and in transit, daily tested restores, ISO 27001-aligned controls, annual penetration testing.
BillingVAT handled automaticallyReverse charge and local rates applied per member state, with compliant invoices and your VAT number validated at signup.
Get started

See where your compliance programme actually stands.

A free assessment maps your gaps against the Regulation in under 15 minutes — no sales call required.

Trusted by compliance teams at EU digital agencies