Grotabyte
Contact SalesBook a Demo

Compliance / GDPR & DORA

Compliance framework

GDPR, DORA & EU Data Obligations

European obligations pull in two directions at once. GDPR says keep personal data no longer than you need it and erase it when someone asks; sectoral rules say keep certain records for years regardless. An archive that cannot hold both positions at the same time will fail one of them.

Applies to: Any organisation processing the personal data of people in the EU or UK, wherever it is established. DORA applies additionally to EU financial entities and the ICT providers serving them.

At a glance

RegulationGDPR (EU 2016/679); DORA (EU 2022/2554)
Applies toProcessors of EU/UK personal data; EU financial entities
Key dutyStorage limitation, Art. 17 erasure, ICT register
DORA in force17 January 2025

What GDPR & DORA requires

Storage limitation, not indefinite retention

GDPR requires personal data be kept in identifiable form no longer than necessary for the purpose. In practice that means a defined retention schedule per record category and a disposal step that actually runs.

Erasure, and the grounds to refuse it

Article 17 gives a right to erasure, subject to exceptions — including where processing is necessary for compliance with a legal obligation. A refusal is defensible only if the basis is recorded at the time.

DORA: know your ICT dependencies

DORA applied in full from 17 January 2025 with no transition period. Financial entities maintain a register of information on their contractual arrangements with ICT third-party providers, maintained at entity, sub-consolidated and consolidated level and reported to competent authorities.

Evidence of the controls, not assertions

Both regimes expect demonstrable controls: who accessed what, when, and under whose authority — the sort of record that has to be generated as work happens rather than assembled afterwards.

How Grotabyte helps with GDPR & DORA

Article 17 erasure under dual control
Erasure is implemented with dual control, so no single administrator can erase unilaterally. Where a record is under legal hold the erasure is refused, and the refusal is ledgered with the legal basis for it — which is what makes the refusal defensible later.
Retention that expresses the conflict
Ten retention templates, six citing the statute behind them. The longest applicable rule wins, so a record caught by both a privacy schedule and a recordkeeping obligation is held to the obligation, visibly and by policy rather than by exception.
Certified destruction when the period ends
Destruction runs in four layers, and the certificate queries the index at the moment it is issued — so it describes what was destroyed rather than what was scheduled for destruction.
Data residency you choose
On-premise, cloud, or run by us, from the same build. For organisations that need EU-resident storage or need records never to leave the building, deployment is a configuration rather than a different product.

Frequently asked questions

Does Grotabyte support full GDPR and DSAR workflows?

Article 17 erasure is implemented, with dual control and ledgered refusals. Grotabyte does not claim end-to-end DSAR handling across every article of the regulation — the archive supports the erasure and retention obligations directly, and supplies the search and export a wider DSAR process depends on.

What happens when an erasure request hits a record under legal hold?

The erasure is refused, and the refusal is written to the hash-chained ledger together with the legal basis relied on. That record is the point: when the decision is questioned months later, the reasoning exists in evidence rather than in someone's memory.

Can we keep European records inside Europe?

Yes. The same build runs on-premise, in cloud storage you nominate, or operated by us, and each customer's material sits in storage dedicated to them. Where records may not leave the building, an on-premise deployment runs against your own filesystem, NAS or SAN with record keys that never leave the machine.

Does an archive help with DORA?

Partly, and it is worth being precise. DORA's register of information is about your ICT contractual arrangements, which is a governance exercise rather than an archiving one. Where the archive contributes is the evidence layer beneath it: an auditable record of access, retention and destruction, and an operational history you can produce when a competent authority asks how a control actually behaved.

Related

Financial services archiving →GDPRDefensible deletionRetention policy

Meet GDPR & DORA with confidence

See how Grotabyte captures, preserves, and produces your records to satisfy GDPR & DORA and the other regulations that govern your organization.

Book a demoAll compliance frameworks

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.