GDPR (EU General Data Protection Regulation)
Applies via international students. The 72-hour breach path is in the incident runbook, Article 28 processor terms sit in the counsel-approved DPA, Article 17 erasure maps to the student's own hard-delete cascade (with the audit-trail carve-out disclosed rather than hidden), and Article 22-equivalent disclosure covers automated crisis detection.
Controls mapped to this standard
Each control page lists the specific requirements it helps satisfy.
Data · 1
Business operations · 1
Customers · 1
Policies behind those controls
- Information security policyGovernance
- Data retention and lifecycle policyData security and privacy
- Data subject rights policyData security and privacy
- Crisis detection: limits and responsibilityData security and privacy
- Asset inventoryInfrastructure security
- Logging and monitoring policySecurity operations
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.