Orbiq LogoOrbiq
PricingAbout
LoginPublish Your Trust Center

GDPR Compliance

Data processing agreements, subprocessor management, and breach notification under GDPR.

GDPR Articles 28, 32, 33, and 34: Why an ISMS Is Not Enough

GDPR Articles 28, 32, 33, and 34: Why an ISMS Is Not Enough

GDPR Articles 28, 32, 33, 34 require data processing agreements, security measures, and breach notification within 72 hours. An ISMS supports governance, but not operational execution.

2026-01-28 · By Anna Bley

2026-01-28

By Anna Bley

Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect

Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect

What do controllers, DPOs, and procurement teams actually expect from your subprocessor management? A practical guide beyond GDPR Article 28 minimum compliance — covering sub-processor lists, change notifications, data flow transparency, and ongoing due diligence.

2026-02-23 · By Anna Bley

2026-02-23

By Anna Bley

🪩rbiq

Your Trust Center for B2B deals.

Platform

  • Trust Center Platform
  • Vendor Assurance
  • AI Search
  • Multi-Language

Solutions

  • SaaS
  • FinTech
  • HealthTech
  • NIS2
  • DORA
  • GDPR
  • CRA

Resources

  • Docs
  • Blog
  • Free Sales Training
  • Trust Ops vs. GRC
  • About

© 2026 Orbiq. All rights reserved.

ImprintTermsPrivacySupport PolicyAcceptable Use PolicyMaster Services AgreementData Processing AgreementTrust Center