Compliance / GDPR & DORA
Compliance frameworkGDPR, DORA & EU Data Obligations
European obligations pull in two directions at once. GDPR says keep personal data no longer than you need it and erase it when someone asks; sectoral rules say keep certain records for years regardless. An archive that cannot hold both positions at the same time will fail one of them.
Applies to: Any organisation processing the personal data of people in the EU or UK, wherever it is established. DORA applies additionally to EU financial entities and the ICT providers serving them.
At a glance
| Regulation | GDPR (EU 2016/679); DORA (EU 2022/2554) |
|---|---|
| Applies to | Processors of EU/UK personal data; EU financial entities |
| Key duty | Storage limitation, Art. 17 erasure, ICT register |
| DORA in force | 17 January 2025 |
What GDPR & DORA requires
Storage limitation, not indefinite retention
GDPR requires personal data be kept in identifiable form no longer than necessary for the purpose. In practice that means a defined retention schedule per record category and a disposal step that actually runs.
Erasure, and the grounds to refuse it
Article 17 gives a right to erasure, subject to exceptions — including where processing is necessary for compliance with a legal obligation. A refusal is defensible only if the basis is recorded at the time.
DORA: know your ICT dependencies
DORA applied in full from 17 January 2025 with no transition period. Financial entities maintain a register of information on their contractual arrangements with ICT third-party providers, maintained at entity, sub-consolidated and consolidated level and reported to competent authorities.
Evidence of the controls, not assertions
Both regimes expect demonstrable controls: who accessed what, when, and under whose authority — the sort of record that has to be generated as work happens rather than assembled afterwards.
How Grotabyte helps with GDPR & DORA
Frequently asked questions
Does Grotabyte support full GDPR and DSAR workflows?
Article 17 erasure is implemented, with dual control and ledgered refusals. Grotabyte does not claim end-to-end DSAR handling across every article of the regulation — the archive supports the erasure and retention obligations directly, and supplies the search and export a wider DSAR process depends on.
What happens when an erasure request hits a record under legal hold?
The erasure is refused, and the refusal is written to the hash-chained ledger together with the legal basis relied on. That record is the point: when the decision is questioned months later, the reasoning exists in evidence rather than in someone's memory.
Can we keep European records inside Europe?
Yes. The same build runs on-premise, in cloud storage you nominate, or operated by us, and each customer's material sits in storage dedicated to them. Where records may not leave the building, an on-premise deployment runs against your own filesystem, NAS or SAN with record keys that never leave the machine.
Does an archive help with DORA?
Partly, and it is worth being precise. DORA's register of information is about your ICT contractual arrangements, which is a governance exercise rather than an archiving one. Where the archive contributes is the evidence layer beneath it: an auditable record of access, retention and destruction, and an operational history you can produce when a competent authority asks how a control actually behaved.
Meet GDPR & DORA with confidence
See how Grotabyte captures, preserves, and produces your records to satisfy GDPR & DORA and the other regulations that govern your organization.