Skip to main content
preeco | data protection

Data Subject Requests and Incidents

Process data subject requests on time and document data breaches in a structured manner. Deadlines are automatically monitored – from the 72-hour notification obligation to the one-month deadline for data subject requests. Nine ready-to-use report templates – from the initial report to the supervisory authority to the BSI report under Sections 25 and 32 BSIG – and an unambiguous deadline status per report structure every incident.

Data Subject Requests

Handle data subject requests on time, identity-verified and traceably

Process access, deletion, rectification, and other data subject requests in a structured and timely manner. The system automatically monitors the statutory one-month deadline under Art. 12(3) GDPR. Respond to requests by email directly from the system.

  • All request types: access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and other
  • Documentation of the identity verification including the time of the request
  • Recording of rejection reasons (manifestly unfounded, excessive, identity not verified, other)
  • Automatic deadline monitoring
  • Web forms for integration on your website
  • Optional querying of the postal address in integrated web forms
  • Freely definable recipients are notified upon receipt
  • Response by email directly from the system
  • Quick-text modules for frequent responses
app.preeco.de
Handle data subject requests on time, identity-verified and traceably

Data Breaches

Data Breaches under Art. 33/34 GDPR

Capture all relevant details of a data breach in a structured manner. The system automatically monitors the 72-hour notification obligation under Art. 33 GDPR. Graphical risk mapping visualizes likelihood and severity in a risk matrix.

  • 72-hour notification obligation automatically monitored
  • Clear reporting-deadline status per report (deadline still running, reported on time, reported late, deadline not met, no deadline) – with a documented justification if a deadline is not met
  • Graphical risk mapping
  • Notification obligation assessment toward supervisory authority
  • Reporting forms for website and intranet
  • Custom report templates can be created; preview of the report before saving
  • Nine ready-to-use report templates included – initial, follow-up and final report to the supervisory authority (Art. 33 GDPR), notification to the controller (Art. 33 para. 2 GDPR), notification of the data subjects (Art. 34 GDPR) as well as the reports to the BSI (Sections 25 and 32 BSIG)
app.preeco.de
Data Breaches under Art. 33/34 GDPR

Features

All Features at a Glance

From structured capture to deadline monitoring to traceable documentation – all the tools for data subject rights and data breaches.

Linking with Processing Activities

Link requests and incidents with affected processing activities. The system automatically displays all relevant data processing systems and data fields.

Web Forms for Website and Intranet

Configurable forms for data subject requests and data breach reports. Entries are captured directly in the system.

Tasks and Workflows

Create tasks directly from requests and incidents. Responsible persons are notified and can update the processing status.

Define and Track Measures

Define measures to remediate data breaches. Assign responsible persons and monitor implementation.

Audit-Proof Documentation

All processing steps are automatically logged. Activity log, comments, and file attachments are complete and traceable. Upon approval, an immutable revision is created – two states can be compared visually and verified for integrity via stored SHA-256 checksums.

Export and Documentation

Export as PDF or DOCX with all relevant information. Directly usable for reports to supervisory authorities or internal reports.

Categories, Severity, and Lessons Learned

Classify incidents by category and severity and record the responsible Information Security Officer (ISB). Measures can be structured hierarchically and supplemented with lessons learned.

AI-Assisted Editing

Individual sections of an incident can optionally be enriched and revised with AI – for efficient, complete documentation.

FAQ

Frequently asked questions

Yes. The system captures all relevant details of a data breach in a structured way, maps likelihood and severity in a graphical risk matrix, and automatically monitors the 72-hour notification obligation under Art. 33 GDPR. Nine ready-to-use report templates cover the initial, follow-up, and final report to the supervisory authority (Art. 33), the notification to the controller (Art. 33 para. 2), the notification of affected persons (Art. 34), and the reports to the BSI (Sections 25 and 32 BSIG). Via an embeddable web form, breach notices can be captured directly from the website or intranet.

Software for breach reporting should automatically monitor the 72-hour deadline under Art. 33 GDPR, support a structured risk assessment, and document all notifications in a revision-safe way. preeco | data protection delivers all of this: structured incident capture with categories and severity, a graphical risk matrix of likelihood and severity, automatic deadline monitoring with a clear notification-deadline status per report, and nine ready-to-use report templates – from the initial report to the supervisory authority (Art. 33) via the notification of affected persons (Art. 34) through to the reports to the BSI (Sections 25 and 32 BSIG).

Get Started Now

We will show you how preeco | data protection simplifies your data subject rights management and incident handling.