Frameworks
Available connected to your dataGDPR — General Data Protection Regulation (EU) 2016/679
Regulatory privacy requirements for organisations handling personal data in the EU/EEA and related contexts.
Overview
NOVA provides a structured GDPR readiness record for obligations, applicability decisions, evidence, risks and privacy governance.
Who this is for
- Organisations handling EU/EEA personal data
- Teams maintaining records of processing and privacy evidence
Governance areas
Accountability
Record ownership, decisions, policies and review evidence for privacy obligations.
Data subject rights
Track rights handling, requests, decisions and response evidence.
Processing governance
Maintain processing, retention, transfer and processor records.
How NOVA supports this framework
- Map privacy requirements to evidence and policies
- Keep applicability and human review decisions visible
- Connect data inventory and incident records where available
Controls and evidence focus
- Records of processing activities
- Privacy notices and DPIA evidence
- Data subject request and breach registers
Cross-framework reuse
Privacy and security evidence can be reused where it genuinely satisfies both GDPR obligations and security controls.
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
Pricing
Plans that cover GDPR
Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.
Launch
AUD $99 /month
A first certification or attestation programme run properly from the start.
- One activated framework
- Control ownership and review cadence
- Evidence mapping and reviewer validation
- Policy versioning and approval
Growth
Most chosenAUD $249 /month
Multiple frameworks on one shared control set, with reuse across requirements.
- Multiple activated frameworks
- Cross-framework control and evidence reuse
- Risk register with treatment and acceptance
- GitHub evidence connector
Professional
AUD $499 /month
Assurance-grade operation with external review workflows included.
- Everything in Growth
- Auditor Portal with scoped engagement access
- Trust Centre publication
- Asset register and classification
Enterprise
On request
Quoted per organisation against scope, users and assurance requirements.
- Everything in Business
- Scope defined per organisation
- Commercial terms agreed with Eredox
- Structured onboarding programme
Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.
Getting started
How to start with GDPR
Four steps from an empty workspace to a reviewable readiness position.
- Step 1
Activate the framework
Create the workspace and activate GDPR so its requirements load into your control set.
- Step 2
Assign control ownership
Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.
- Step 3
Map and validate evidence
Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.
- Step 4
Review readiness
Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
Talk to us
Ask about GDPR — General Data Protection Regulation (EU) 2016/679
Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.
NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.