Scrutineer.ai

Scrutineer · By framework

GDPR compliance software that evidences accountability

Under GDPR the burden is on you to prove accountability: you have to show which personal data you process, on what lawful basis, where it flows and how it is protected. GDPR compliance software should make that demonstrable rather than theoretical. Scrutineer maps GDPR obligations to your actual controls and ties them to your records of processing activities.

The platform tracks data flows, processor relationships and the controls protecting personal data, then flags gaps such as a processor without a data processing agreement or a transfer without a safeguard. When a regulator or a customer asks, you have organized evidence instead of a scramble. Scrutineer supports GDPR accountability and readiness; it does not provide legal advice or certify compliance.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with GDPR

Obligations mapped to controls

Scrutineer ties GDPR principles and obligations to the real controls that satisfy them, so accountability is evidenced rather than asserted.

Data flows tracked

Records of processing activities, data flows and processor relationships are tracked in one place, so you always know what data goes where.

Gaps surfaced early

Missing data processing agreements, unsafeguarded transfers and weak protections are flagged before a regulator or customer asks.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps GDPR obligations to operating controls
  • Maintains records of processing activities
  • Tracks data flows and international transfers
  • Monitors processor relationships and DPAs
  • Flags transfers without an appropriate safeguard
  • Keeps accountability evidence ready on demand
GDPR readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Obligation reference

Which GDPR obligations actually attach to a US company with no EU entity

Most GDPR guidance written for US readers stops at whether the regulation applies. The harder question is which specific obligations follow once it does, because several attach automatically and are routinely skipped. Two rows here are the ones that catch companies out most often: the Article 27 representative, which almost every in-scope US company owes and few appoint, and the Article 30 records exemption for smaller companies, which looks like relief and almost never is.

Obligation Does it attach to a US company with no EU establishment What it actually requires Where it goes wrong
Territorial scope, Article 3(2) Yes, if you offer goods or services to people in the EU or monitor their behavior. No office, entity or server in the EU is needed. The full set of obligations, not a reduced version. Targeting can be evidenced by euro pricing, EU shipping, EU language options or analytics and advertising that track EU visitors. Assuming a US-only company is out of scope because it has no EU presence. Scope follows the data subject location and your targeting, not your incorporation.
EU representative, Article 27 Yes for most in-scope companies. The derogation is narrow and ongoing SaaS processing rarely fits it. A representative established in a member state where your data subjects are, named in your privacy notice, mandated in writing and reachable by individuals and supervisory authorities. Skipping it, or assuming a data protection officer covers it. They are separate roles with separate triggers, and enforcement actions have turned on a missing representative alone.
UK representative, UK GDPR Yes, separately, if you target or monitor people in the UK and have no UK establishment. A second appointment under the UK regime, which has run independently since Brexit under the Data Protection Act 2018 with the ICO as regulator. Appointing an EU representative and stopping. One appointment does not cover both regimes, so UK exposure sits uncovered.
Data protection officer, Article 37 Only sometimes, and less often than vendors suggest. Required if you are a public authority, or your core activities involve large-scale regular and systematic monitoring, or large-scale special category or criminal conviction data. Appointing a DPO reflexively to look diligent, then discovering the role carries independence and reporting requirements you did not intend to take on.
Records of processing, Article 30 Yes, in practice, even under 250 employees. A written record of processing purposes, categories of data and recipients, transfers, retention and security measures, kept current rather than produced once. Reading Article 30(5) as a small business exemption. Its three exceptions, including processing that is not occasional, remove it for nearly every operating company.
International transfers, Chapter V Yes, for every transfer of EU personal data to the US. Either self-certification to the EU-US Data Privacy Framework with the Department of Commerce, renewed annually, or Standard Contractual Clauses supported by a documented transfer impact assessment. Running Standard Contractual Clauses you no longer need, or relying on the Framework with no fallback while the appeal in Case C-703/25 P is pending.
Breach notification, Article 33 Yes, on a 72 hour clock. Notification to the lead supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in risk, plus notification to individuals where risk is high. Starting the clock when the investigation finishes. It starts at awareness, and a late notification must be accompanied by an explanation of the delay.

Reflects the position as at August 2026. The EU-US Data Privacy Framework adequacy decision was upheld by the EU General Court on September 3, 2025 in the Latombe challenge; an appeal to the Court of Justice, Case C-703/25 P, remains pending. Scrutineer maps controls and maintains accountability evidence. It does not provide legal advice, and no software can certify GDPR compliance.

Good questions

Questions about GDPR

No. Scrutineer is decision-support that maps obligations to controls, tracks processing activities and organizes accountability evidence. For legal interpretation of GDPR as it applies to your business, you should consult qualified counsel or your data protection officer.
It maintains your records of processing activities and the data flows behind them, linking each processing activity to its lawful basis, the systems involved and the controls protecting the data, so your data map stays current as systems change.
Yes, if you offer goods or services to people in the EU or monitor their behavior, GDPR applies regardless of where your company is based. Many US SaaS companies fall in scope through EU customers or website visitors, which is why enterprise buyers increasingly ask US vendors for GDPR accountability evidence.
No law mandates specific software, but GDPR requires you to demonstrate accountability: documented processing records, lawful bases, safeguarded transfers and protective controls. Maintaining that demonstrably by hand rarely survives growth. Software keeps the records, data flows and evidence current so you can actually produce them when a regulator or customer asks.
Yes, under Article 3(2), if you offer goods or services to people in the EU or monitor their behavior. No EU entity, office or server is needed. Accepting EU customers, pricing in euros, shipping to the EU or tracking EU visitors for analytics or advertising can all bring you in scope, and the obligations that follow are the full set, not a reduced version.
Usually yes, and this is the single most commonly missed obligation. Article 27 requires a non-EU controller in scope to appoint a representative established in a member state where its data subjects are, named in the privacy notice and available to individuals and regulators. The derogation is narrow: occasional processing, no large-scale special category data, and unlikely to result in risk. Ongoing SaaS processing rarely qualifies.
They are separate roles with separate triggers and one does not satisfy the other. The Article 27 representative is a local contact point for a company with no EU establishment, and is typically an outsourced service. The Article 37 data protection officer is an internal advisory role required only when you are a public authority, or your core activities involve large-scale regular systematic monitoring or large-scale special category data.
If you target or monitor people in the UK and have no UK establishment, yes. Since Brexit the UK runs its own regime under the UK GDPR and Data Protection Act 2018, with its own regulator in the ICO and its own representative requirement. Companies that appointed an EU representative and stopped there frequently have an uncovered UK exposure, because one appointment does not cover both.
Almost certainly not. Article 30(5) looks like a small business exemption but carries three exceptions, and any one of them removes it: processing likely to result in a risk to rights and freedoms, processing that is not occasional, or processing of special category or criminal conviction data. Routine, ongoing customer data processing is not occasional, so most companies below 250 employees still keep full records.
Two mainstream routes. Self-certify to the EU-US Data Privacy Framework with the US Department of Commerce, which lets EU data flow to you on the basis of an adequacy decision and must be renewed annually. Or use Standard Contractual Clauses backed by a documented transfer impact assessment. The DPF is usually less work if you qualify, and many US companies still run SCCs they no longer need.
Yes, as at August 2026. The EU General Court dismissed the Latombe challenge on September 3, 2025 and upheld the adequacy decision. That ruling is under appeal to the Court of Justice as Case C-703/25 P, which remains pending, and privacy groups have signaled further challenges. Certified organizations can continue relying on it, and prudent programs keep Standard Contractual Clauses documented as a fallback.
Seventy-two hours from the moment you become aware of a personal data breach, to the lead supervisory authority, unless the breach is unlikely to result in a risk to individuals. If notification is late you must explain the delay. Where the risk to individuals is high you must also tell the affected people without undue delay. The clock runs from awareness, not from completing your investigation.
Two tiers. Administrative fines reach up to 10 million euros or 2 percent of total worldwide annual turnover for the preceding financial year for obligations such as records and security, and up to 20 million euros or 4 percent for breaches of the core principles, lawful basis, data subject rights and transfer rules. In each tier the higher of the two figures applies, and turnover is measured group-wide.
It covers most of the work and leaves real gaps. The data inventory, rights workflows and processor contracts carry over directly. What GDPR does not give you is the US-specific machinery: sale and share opt-outs, universal opt-out signal recognition, the California notice at collection, and the sector exemptions that decide whether a US state law reaches you at all. Treat the two as one control set with US-specific additions.
Not in the way vendors imply. Article 42 allows approved certification mechanisms and a small number exist, but no widely recognized general GDPR certificate is issued and nobody is simply GDPR certified. Compliance is a continuing state you demonstrate through documented practice. ISO 27701 is a useful voluntary privacy management standard, and holding it is evidence of diligence rather than proof of GDPR compliance.

Keep reading

Guides that go deeper on GDPR and privacy evidence

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification