All frameworks
GDPRegulation (EU) 2016/679 · in force 25 May 2018

GDPR compliance

Europe's benchmark personal-data law.

The EU General Data Protection Regulation (Regulation (EU) 2016/679), in force since 25 May 2018, is the world's most influential personal-data law — enforced by each member state's supervisory authority (its DPA) and coordinated by the European Data Protection Board (EDPB). It runs on the accountability of controllers and processors: a lawful basis for every processing activity, the seven data-protection principles, enforceable rights for individuals, records of processing, strong security, data-protection impact assessments, breach notification within 72 hours, and safeguarded international transfers.

Start from the basics

The standard

EU General Data Protection Regulation (Regulation (EU) 2016/679)

Who needs it

Any organisation — inside or outside the EU — that processes the personal data of people in the EU or EEA, or offers them goods or services or monitors their behaviour. That means most SaaS, e-commerce, fintech, health, ad-tech and B2B companies with European users, customers or employees, whether acting as a controller, a processor, or both.

€20M / 4%

Max fine (or 2% / €10M tier)

The basics

What is GDPR?

GDPR is a regulation you comply with, not a certificate you earn. It governs the processing of the personal data of people in the EU and EEA, and it turns on a set of core building blocks: the seven principles in Article 5 (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and — the one that ties it together — accountability), the six lawful bases in Article 6, and a strong bill of data-subject rights in Articles 15–22 (access, rectification, erasure, restriction, portability and objection).

It draws a sharp line between the controller (who decides why and how personal data is processed) and the processor (who processes on the controller's documented instructions), and it places concrete obligations on both: a Record of Processing Activities (Article 30), appropriate technical and organisational security measures (Article 32), a data-protection impact assessment for high-risk processing (Article 35), and a Data Protection Officer where Articles 37–39 require one. A personal-data breach must be notified to the supervisory authority within 72 hours (Article 33) and, where the risk to individuals is high, to the affected individuals too (Article 34).

It applies extraterritorially under Article 3 — to any organisation offering goods or services to, or monitoring the behaviour of, people in the EU, wherever that organisation is established. Transfers of personal data outside the EU are only allowed under the safeguards in Articles 44–49, most commonly an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) backed by a transfer impact assessment.

Why it matters

What GDPR does for your business

The fines are the benchmark

GDPR set the standard other laws copy: up to €20M or 4% of total worldwide annual turnover, whichever is higher, for the most serious breaches — with a lower tier of €10M or 2% for administrative failings. Regulators have handed down penalties in the hundreds of millions.

It's a market-access requirement

"Are you GDPR compliant?" is one of the first questions on any European security or procurement review. Being able to answer it — with a lawful basis, a RoPA, DPAs and a breach process — is a condition of selling into the EU.

It reaches you wherever you are

Article 3's extraterritorial scope means a company with no EU office is still bound the moment it targets or monitors people in the EU. There is no opting out by geography.

What it covers

Principles & lawful basis

The seven Article 5 principles (including accountability) and a valid Article 6 lawful basis — consent, contract, legal obligation, vital interests, public task or legitimate interests — for every processing activity.

Data-subject rights

Access, rectification, erasure, restriction, portability and objection (Articles 15–22), answered without undue delay and within one month.

Records, security & DPIAs

A Record of Processing Activities (Article 30), appropriate security measures (Article 32), and a data-protection impact assessment for high-risk processing (Article 35), with a DPO where Articles 37–39 require one.

Breach & transfers

72-hour breach notification to the supervisory authority (Article 33) and to individuals at high risk (Article 34), plus safeguarded international transfers via adequacy or SCCs (Articles 44–49).

The hard way

Done by hand, GDPR means keeping a Record of Processing current across every system, drafting privacy notices and consent flows per product, tracking one-month rights SLAs in spreadsheets, running DPIAs on new processing, chasing processor DPAs and SCCs, and being ready to file a 72-hour breach report the moment something goes wrong — all while proving it to auditors and customers. That is exactly the repetitive, deadline-driven work software should run for you.

The easier way, with Compliance One

  • Provisions the privacy programme GDPR expects: Records of Processing (controller and processor), a lawful-basis and consent register, privacy-notice templates, and a data-subject-request queue with the one-month SLA tracked automatically.
  • Runs the 72-hour breach workflow off a pre-seeded supervisory-authority contact — a risk assessment, dual authority and data-subject notifications, and a retained breach record.
  • Handles DPIAs for high-risk processing, a DPO register, processor DPAs, and a cross-border transfer register with SCCs and transfer impact assessments.
  • Cross-maps GDPR article-by-article to your ISO 27701 (PIMS) controls and to ISO 27001 security controls, so the evidence you already collect counts here too — GDPR becomes evidencing a regulation on top of a certifiable system, not a fresh project.

Do it once, reuse it everywhere. Evidence you collect for GDPR is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is there a GDPR certificate?
No — GDPR is a law you comply with, not a scheme you pass. Article 42 allows for approved certifications that can help demonstrate compliance, but there is no single "GDPR certificate". The recognised route is to run a certifiable privacy management system: ISO 27701, which maps to the GDPR article-by-article. Compliance One keeps that evidence audit-ready.
Does GDPR apply to us if we're outside the EU?
Yes, if you offer goods or services to, or monitor the behaviour of, people in the EU or EEA. Article 3 gives GDPR extraterritorial reach regardless of where you're incorporated or where your servers sit — and you may also need to appoint an EU representative under Article 27.
What's the difference between a controller and a processor?
A controller decides why and how personal data is processed (your own employee and customer data); a processor handles it on a controller's documented instructions (a SaaS handling its customers' data). It decides which obligations fall on you, and Compliance One tracks both roles, including the Article 28 data processing agreements between them.
We already have ISO 27701 or ISO 27001 — does that help?
Enormously. ISO 27701 is mapped to the GDPR article-by-article, and its security controls ride on ISO 27001:2022. Compliance One cross-maps all three, so much of your existing privacy and security evidence carries straight over to GDPR.

Ready to tackle GDPR?

See exactly how Compliance One maps GDPR to your environment in a 30-minute walkthrough — and how much of it we handle for you.