Governance. Risk. Compliance. Cybersecurity.
Controls & Requirements

Controls & Requirements — GDPR

GDPR requires a defined, evidenced and continuously monitored control set. MAST maintains a unified control catalogue that maps each requirement to your existing controls — eliminating duplication.

  • ISO/IEC 27001 Certified
  • ISO/IEC 27701 Certified
  • ISO 9001 Certified

Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation

Control domains

  • Lawful basis and purpose limitation
  • Data subject rights
  • Security of processing and breach notification
  • International data transfers
  • Records of processing and accountability
  • Data protection impact assessments
GDPR control coverage by domain

Horizontal bar chart titled "GDPR control coverage by domain". Values: Lawful basis and purpose limitation 70%, Data subject rights 83%, Security of processing and breach no 96%, International data transfers 79%, Records of processing and accountabi 92%, Data protection impact assessments 75%.

  • Lawful basis and purpose limitation
    70%
  • Data subject rights
    83%
  • Security of processing and breach no
    96%
  • International data transfers
    79%
  • Records of processing and accountabi
    92%
  • Data protection impact assessments
    75%

How we document each control

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result
Control record fields

Checklist titled "Control record fields" with 6 items, every item marked complete: Statement of control and intent; Owner, executor and reviewer (RACI); Frequency, trigger and operating window; Evidence type, location and retention; Linked risks and KRIs; Audit history and last test result.

  • Statement of control and intent
  • Owner, executor and reviewer (RACI)
  • Frequency, trigger and operating window
  • Evidence type, location and retention
  • Linked risks and KRIs
  • Audit history and last test result

Mapping to adjacent frameworks

Our catalogue maps each control to ISO 27001, ISO 27701, SOC 2, NIST CSF, PCI DSS, CBUAE, SAMA, NCA ECC and ADHICS v2. One implementation, many audits.