AuditXYZ

Compliance Framework

General Data Protection Regulation (EU) 2016/679 (GDPR)

The GDPR is the world's most influential data protection law, setting the standard for how organizations collect, process, and protect personal data of individuals in the EU and EEA. This guide covers lawful bases, data subject rights, breach notification, and practical compliance steps.

$10,000–$250,0003–12 months2016 (enforced May 25, 2018)
Issuing BodyEuropean Parliament and Council of the European Union
First Published2016-04-27
Latest Version2016 (enforced May 25, 2018)
Typical Cost$10,000–$250,000
Typical Timeline3–12 months
Audit RequiredNo
Audit FrequencyNo mandatory external audit, but Data Protection Impact Assessments (DPIAs) required for high-risk processing. Supervisory authorities may conduct audits at any time.
Geographyeu, eea, global

GDPR: The Complete Guide

The General Data Protection Regulation is the European Union's landmark privacy law that has reshaped how organizations worldwide handle personal data. Enacted in 2016 and enforced since May 25, 2018, the GDPR applies to any organization that processes the personal data of individuals located in the EU or EEA, regardless of where the organization itself is based. No other privacy law has generated as much global compliance investment, regulatory precedent, or downstream legislative influence.

What the GDPR Is and Who Enforces It

The GDPR is a directly applicable EU regulation — not a directive requiring national transposition — which means its core text carries equal legal weight across all 27 EU member states plus the EEA countries of Norway, Iceland, and Liechtenstein. It was adopted by the European Parliament and Council and replaced the 1995 Data Protection Directive.

Enforcement falls to national supervisory authorities (SAs) in each member state: the Irish Data Protection Commission, the French CNIL, the German state-level DPAs, and their counterparts in every EU country. For organizations with cross-border processing, the "one-stop-shop" mechanism designates the SA in the country of main establishment as the lead authority, coordinating with other SAs through the European Data Protection Board (EDPB).

Territorial and Material Scope

The GDPR's extraterritorial reach is one of its defining features. It applies to:

  • Controllers and processors established in the EU, regardless of where processing takes place.
  • Controllers and processors outside the EU that offer goods or services to individuals in the EU, or that monitor the behavior of individuals in the EU.

A SaaS company in Singapore serving European customers, a US healthcare firm with EU patient data, and a Brazilian e-commerce platform targeting German shoppers all fall within scope. The regulation covers processing of personal data of natural persons — not legal entities — and applies to automated and some manual processing activities.

Six Lawful Bases for Processing

The GDPR establishes six lawful bases under Article 6. Organizations must identify and document one before processing begins:

  1. Consent — Freely given, specific, informed, and unambiguous indication of agreement. Must be as easy to withdraw as to give.
  2. Contract — Processing is necessary to perform a contract with the data subject or to take pre-contractual steps.
  3. Legal obligation — Processing is required to comply with a legal requirement on the controller.
  4. Vital interests — Processing is necessary to protect someone's life.
  5. Public task — Processing is necessary for a task carried out in the public interest or in the exercise of official authority.
  6. Legitimate interests — Processing is necessary for the legitimate interests of the controller or a third party, unless those interests are overridden by the data subject's rights.

Legitimate interests is the most flexible basis but requires a balancing test — a documented assessment of whether the controller's interest outweighs the individual's expectations and rights.

Data Subject Rights

Articles 15 through 22 grant individuals extensive rights that controllers must operationalize with 30-day response processes:

  • Right to access (Art. 15) — Individuals may request confirmation of processing and a copy of their personal data.
  • Right to rectification (Art. 16) — Individuals may require correction of inaccurate data.
  • Right to erasure (Art. 17) — The "right to be forgotten" applies when data is no longer necessary, consent is withdrawn, or processing is unlawful.
  • Right to restriction (Art. 18) — Individuals may request a pause on processing in defined circumstances.
  • Right to portability (Art. 20) — Data provided by the individual must be provided in a machine-readable format for transfer to another controller.
  • Right to object (Art. 21) — Applies particularly to processing based on legitimate interests or direct marketing.
  • Rights related to automated decisions (Art. 22) — Individuals may object to decisions made solely by automated means that produce significant effects.

Data Protection Officer

Organizations must appoint a Data Protection Officer under Article 37 when they are a public authority, carry out large-scale systematic monitoring of individuals, or process special category or criminal offense data on a large scale. The DPO must be expert in data protection law, must have access to senior management, and cannot be dismissed or penalized for performing their tasks. The DPO's contact details must be published and registered with the relevant supervisory authority.

Data Protection Impact Assessments

When a type of processing is likely to result in a high risk to individuals, a DPIA under Article 35 is mandatory before processing commences. High-risk scenarios include systematic profiling, large-scale processing of special categories, and systematic monitoring of publicly accessible areas. The DPIA must describe the processing, assess necessity and proportionality, and identify measures to address the risks. Where risks remain high after mitigation, prior consultation with the supervisory authority is required.

Breach Notification

Article 33 requires controllers to notify their lead supervisory authority within 72 hours of becoming aware of a personal data breach — unless the breach is unlikely to result in a risk to individuals. Notification must describe the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken. Where the breach is likely to result in a high risk to individuals, affected data subjects must also be notified directly under Article 34.

Cross-Border Transfer Rules

Transfers of personal data to countries outside the EU/EEA are restricted unless an adequate level of protection is ensured. Mechanisms include:

  • Adequacy decisions — The European Commission has recognized countries including the UK, Japan, South Korea, Israel, and Switzerland as adequate (with the UK under a time-limited arrangement that expired in 2025 and was renewed).
  • Standard Contractual Clauses (SCCs) — The 2021 updated SCCs are the most widely used mechanism for commercial data transfers.
  • Binding Corporate Rules (BCRs) — Internal rules for multinational groups, approved by a supervisory authority.
  • Certification mechanisms and codes of conduct — Emerging tools for demonstrating transfer adequacy.

Following the Schrems II ruling (2020), organizations relying on SCCs must also conduct transfer impact assessments to verify that the recipient country's laws do not undermine the protection SCCs provide.

Enforcement and Penalties

Penalties reach up to €20 million or 4% of annual global turnover, whichever is higher, for the most serious violations. Less serious infringements attract fines of up to €10 million or 2% of global turnover.

Since enforcement began, EU supervisory authorities have imposed billions of euros in cumulative fines. Notable 2024-2026 enforcement context:

  • Meta received a €1.2 billion fine from the Irish DPC in 2023 for unlawful SCCs-based data transfers to the United States — the largest GDPR penalty to date.
  • X (formerly Twitter) was fined €450 million by the Irish DPC in 2024 for transparency failures.
  • The EDPB's coordinated enforcement actions on AI and large-scale data processing continued into 2025-2026, targeting generative AI companies' use of personal data without adequate lawful basis.

Regulators are increasingly focused on AI data practices, consent management failures, and cross-border transfer compliance.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
AssessmentData mapping, gap analysis, legal basis audit4-8 weeks
DesignPrivacy notices, consent flows, DSAR workflows4-8 weeks
ImplementationTechnical controls, vendor DPAs, DPO appointment6-12 weeks
OngoingDPIA program, breach response, trainingContinuous

Key compliance steps:

  1. Data mapping — Inventory all personal data flows and processing activities in a Record of Processing Activities (RoPA).
  2. Legal basis identification — Document the lawful basis for each processing activity before processing begins.
  3. Privacy notices — Update notices to meet GDPR transparency requirements under Articles 13 and 14.
  4. Rights mechanisms — Implement intake, verification, and response workflows for all data subject rights.
  5. Vendor management — Execute Data Processing Agreements (DPAs) under Article 28 with all processors.
  6. Breach response — Establish a documented 72-hour breach notification procedure including escalation paths.
  7. Training — Educate staff on data protection obligations, incident reporting, and handling of requests.
  8. DPIA program — Embed pre-processing risk assessment for high-risk activities.

The GDPR is the model against which most modern privacy laws are measured. Brazil's LGPD shares approximately 80% structural overlap, extending the GDPR model with ten legal bases and the ANPD as regulator. Switzerland's FADP achieves 85% alignment and adds distinctive personal criminal liability for responsible individuals. California's CCPA/CPRA shares roughly 55-65% conceptual overlap but uses a different structure — opt-out rather than opt-in as default, and revenue/volume thresholds rather than a broad territorial scope. India's DPDPA is consent-centric and shares approximately 55% conceptual overlap, with a distinct approach to cross-border transfers using a negative-list model rather than adequacy.

Organizations that achieve strong GDPR compliance have a significant head start on most other global privacy frameworks. The incremental investment to extend into LGPD, FADP, or PIPEDA is substantially lower than building from scratch.

How Privacy Automation Helps

GDPR's operational requirements — data mapping, DSR response, consent management, breach reporting — are well-suited to automation. TruePrivacy is an AI-powered privacy operations platform that addresses the core mechanics of GDPR compliance. Its AI-powered data discovery scans 128-plus sources to build a data inventory automatically, replacing manual spreadsheet-driven mapping exercises. Its DSR automation routes and fulfills subject access requests, erasure requests, and portability requests within GDPR's 30-day window.

TruePrivacy covers 12-plus frameworks including GDPR, CCPA, LGPD, DPDPA, and EU AI Act obligations. Pricing starts at $5,000 per year with 24-hour onboarding — a fraction of the cost of traditional compliance consulting. AuditXYZ rates TruePrivacy at 88/100 for mid-market privacy programs. It is a younger platform and may not be the right fit for organizations with 300-plus jurisdiction requirements or deeply custom enterprise workflows. See the full comparison of privacy management tools or the TruePrivacy vs OneTrust comparison.

Frequently Asked Questions

Does the GDPR apply to my company if we are based outside the EU? Yes, if you offer goods or services to individuals in the EU or monitor their behavior — for example, through analytics tracking or behavioral advertising — you are within scope under Article 3(2), regardless of where your company is incorporated or operates.

What is the difference between a controller and a processor? A controller determines the purposes and means of processing. A processor handles personal data only on behalf of a controller under a written contract (a DPA). Both bear legal responsibilities under the GDPR, but controllers carry the primary compliance burden and must ensure processors provide sufficient guarantees.

Is consent always required under the GDPR? No. Consent is one of six lawful bases. Many processing activities lawfully rest on contractual necessity, legitimate interests, or legal obligation without requiring any consent at all. Consent is most appropriate when individuals have a genuine free choice and when no other basis applies.

What counts as a personal data breach? A breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Not every breach requires reporting — only those likely to result in a risk to individuals. Where the risk is high, both the supervisory authority and affected individuals must be notified.

How long do we have to respond to a Subject Access Request? Controllers must respond without undue delay and within one month of receiving the request. This period may be extended by a further two months where requests are complex or numerous, but the requester must be informed within the first month of the extension and the reason for it.

What does the EU AI Act mean for GDPR compliance? The EU AI Act, which entered phased enforcement from August 2024, creates obligations that intersect significantly with GDPR. High-risk AI systems that process personal data require both an AI Act conformity assessment and GDPR compliance. Prohibited practices such as real-time remote biometric identification in public spaces are also directly addressed by GDPR's special category rules. Organizations should align both frameworks in their AI governance programs.

Compliance with GDPR is not a one-time project. Organizations must continuously monitor processing activities, update records, and adapt to evolving regulatory guidance from supervisory authorities and the EDPB.

Request a GDPR consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

LGPDHigh80%
ISO 27701Medium75%
CCPAMedium55%

Related frameworks

Get matched with a GDPR auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools