Six obligations, one careful evidence boundary
Data minimization
Articles 5(1)(c), 25. PDI product capability: inventory candidate PII and produce scoped evidence to support review of what is adequate, relevant, and limited.
Retention
Article 5(1)(e). PDI product capability: identify retained data and produce evidence for policy-led retention decisions; Kestryl does not set lawful retention periods.
Erasure
Article 17. PDI product capability: locate candidate records and support approved structured-data actions, subject to legal holds and applicable exceptions.
Records & accountability
Articles 5(2), 24, 30. PDI product capability: audit rows and evidence packs can support internal accountability work; they are not statutory records by themselves.
Security
Article 32. PDI product capability: discovery and inventory can inform risk review. Security compliance requires wider technical and organizational measures.
72-hour notification
Article 33. Controllers generally notify the supervisory authority within 72 hours after becoming aware, unless the breach is unlikely to risk rights and freedoms. PDI product evidence may support investigation; it does not decide reportability.
Illustrative verified enforcement
These examples are selected from the verified dataset and are not a complete enforcement register.
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
Meta (Facebook)
€1.2B (largest GDPR fine ever) · May 22, 2023
Art. 46(1) — unlawful EU→US data transfers after Schrems II; ordered to suspend transfers + delete/return EU data from US
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
TikTok
€530M (€485M Art. 46 + €45M Art. 13) · May 2, 2025
Art. 46(1) + 13(1)(f) — unlawful EEA→China data transfers + transparency; Irish High Court upheld the fine June 2026 (set aside the suspension order)
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
Instagram (Meta)
€405M · Sep 2, 2022
Art. 6, 5(1)(a)(c), 12, 24, 25, 35 — children's data (public-by-default, contact details exposed)
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
Meta (Facebook + Instagram behavioral ads)
€390M (€210M FB + €180M IG) · Jan 4, 2023
Art. 6(1) — no valid legal basis for behavioral advertising; cannot rely on "contract"
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
TikTok (children's data)
€345M · Sep 1, 2023
Children's data processing
Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)
€225M · Sep 2, 2021
Art. 12, 13, 14 — transparency failures (info to users and non-users)
How Kestryl supports readiness
Kestryl, the PDI PIIScan, can discover candidate PII in structured systems and provide OCR-based detection, inventory, and evidence for documents and scans. Approved structured-data remediation may use Mask, Vault, or Strip, subject to policy and legal holds. Source documents are not altered.
Common questions
Does Kestryl make an organization GDPR compliant?
No. Kestryl supports discovery, evidence, and approved remediation workflows. Compliance depends on legal basis, governance, security, contracts, procedures, and decisions beyond the product.
Does the GDPR always require notification within 72 hours?
Article 33 uses a 72-hour standard after controller awareness for notifying the supervisory authority, where feasible, unless the breach is unlikely to result in risk to individuals’ rights and freedoms. See official GDPR text (opens in a new tab).
Can Kestryl erase scanned documents?
No. For scanned PDFs, images, attachments, and shared drives, Kestryl provides OCR detection, inventory, and evidence only; it does not alter source documents.
Educational information, not legal advice. Confirm applicability, exceptions, current guidance, and decisions with qualified counsel and the relevant supervisory authority.