Jurisdiction pathway · European Union

GDPR evidence, mapped without overclaiming.

A practical map from core GDPR duties to evidence Kestryl can support—while legal interpretation, scope, and reporting decisions remain with the organization and its counsel.

Research cutoff · August 25, 2026

Six obligations, one careful evidence boundary

Current GDPR obligation

Data minimization

Articles 5(1)(c), 25. PDI product capability: inventory candidate PII and produce scoped evidence to support review of what is adequate, relevant, and limited.

Current GDPR obligation

Retention

Article 5(1)(e). PDI product capability: identify retained data and produce evidence for policy-led retention decisions; Kestryl does not set lawful retention periods.

Current GDPR obligation

Erasure

Article 17. PDI product capability: locate candidate records and support approved structured-data actions, subject to legal holds and applicable exceptions.

Current GDPR obligation

Records & accountability

Articles 5(2), 24, 30. PDI product capability: audit rows and evidence packs can support internal accountability work; they are not statutory records by themselves.

Current GDPR obligation

Security

Article 32. PDI product capability: discovery and inventory can inform risk review. Security compliance requires wider technical and organizational measures.

Current GDPR obligation

72-hour notification

Article 33. Controllers generally notify the supervisory authority within 72 hours after becoming aware, unless the breach is unlikely to risk rights and freedoms. PDI product evidence may support investigation; it does not decide reportability.

Illustrative verified enforcement

These examples are selected from the verified dataset and are not a complete enforcement register.

Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)

Meta (Facebook)

€1.2B (largest GDPR fine ever) · May 22, 2023

Art. 46(1) — unlawful EU→US data transfers after Schrems II; ordered to suspend transfers + delete/return EU data from US

DPC decision (opens in a new tab)

Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)

TikTok

€530M (€485M Art. 46 + €45M Art. 13) · May 2, 2025

Art. 46(1) + 13(1)(f) — unlawful EEA→China data transfers + transparency; Irish High Court upheld the fine June 2026 (set aside the suspension order)

DPC press release (opens in a new tab)

Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)

Instagram (Meta)

€405M · Sep 2, 2022

Art. 6, 5(1)(a)(c), 12, 24, 25, 35 — children's data (public-by-default, contact details exposed)

DPC press release (opens in a new tab)

Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)

Meta (Facebook + Instagram behavioral ads)

€390M (€210M FB + €180M IG) · Jan 4, 2023

Art. 6(1) — no valid legal basis for behavioral advertising; cannot rely on "contract"

DPC / BBC (opens in a new tab)

Ireland — Data Protection Commission (DPC, lead supervisor for Big Tech)

WhatsApp

€225M · Sep 2, 2021

Art. 12, 13, 14 — transparency failures (info to users and non-users)

DPC press release (opens in a new tab)

How Kestryl supports readiness

Kestryl, the PDI PIIScan, can discover candidate PII in structured systems and provide OCR-based detection, inventory, and evidence for documents and scans. Approved structured-data remediation may use Mask, Vault, or Strip, subject to policy and legal holds. Source documents are not altered.

Common questions

Does Kestryl make an organization GDPR compliant?

No. Kestryl supports discovery, evidence, and approved remediation workflows. Compliance depends on legal basis, governance, security, contracts, procedures, and decisions beyond the product.

Does the GDPR always require notification within 72 hours?

Article 33 uses a 72-hour standard after controller awareness for notifying the supervisory authority, where feasible, unless the breach is unlikely to result in risk to individuals’ rights and freedoms. See official GDPR text (opens in a new tab).

Can Kestryl erase scanned documents?

No. For scanned PDFs, images, attachments, and shared drives, Kestryl provides OCR detection, inventory, and evidence only; it does not alter source documents.