GDPR Article 28, continuously

Know every sub-processor.
Object in time.

Vigil28 automatically tracks every SaaS vendor's sub-processor chain, alerts you before right-to-object deadlines expire, and produces audit-ready evidence on demand.

  • EU-hosted
  • GDPR-native
  • Built for DPOs

Everything Article 28 demands, automated

No spreadsheets. No missed sub-processor notifications.

Vendor inventory

A single register of every SaaS vendor you share personal data with.

Daily monitoring

Every vendor's sub-processor page is checked daily for changes.

Deadline alerts

Right-to-object windows are tracked — you are warned before they expire, not after.

Audit-ready exports

One-click PDF/CSV evidence of continuous compliance for auditors and customers.

EU hosting by default

Data stays in the EU. No CLOUD Act exposure from US-hosted tooling.

Chain-of-processors view

See the full sub-processor chain per vendor, including non-adequate jurisdictions.

How it works

  1. 1. Add your vendors

    Import your SaaS list or start from scratch in minutes.

  2. 2. We watch the chains

    Sub-processor pages are monitored daily; every change is captured with a timestamp.

  3. 3. Act with evidence

    Alerts arrive before objection deadlines. Exports prove your diligence on demand.

Prove continuous compliance

Early access is open for EU SaaS companies and DPO consultants.

Contact us