Data protection
GDPR compliance: what it requires and how to keep it continuous
In short
The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU law governing how organizations process personal data. It has applied since 25 May 2018 and reaches any organization — inside or outside the EU — that processes the personal data of people in the EU/EEA. It requires a lawful basis for processing, transparency, data-subject rights, security of processing, and accountability you can demonstrate.
Last reviewed: August 2026
Who it applies to
The GDPR applies to controllers and processors that handle personal data of individuals in the EU/EEA, regardless of where the organization itself is located. A US SaaS company with EU users is in scope. Obligations scale with risk: routine processing needs records and safeguards; large-scale or sensitive processing can trigger a Data Protection Impact Assessment and a Data Protection Officer.
Core requirements
- A lawful basis for every processing activity (Art. 6), and extra conditions for special-category data (Art. 9)
- Records of processing activities (Art. 30)
- Transparency and privacy notices (Art. 13–14)
- Honouring data-subject rights — access, erasure, portability, objection (Art. 15–22)
- Security of processing appropriate to the risk (Art. 32)
- Data Protection Impact Assessments for high-risk processing (Art. 35)
- Data processing agreements with processors (Art. 28)
- Breach notification to the supervisory authority within 72 hours (Art. 33)
Typical compliance challenges
- Keeping the Article 30 record of processing current as tools and vendors change
- Screening new projects for when a DPIA is actually required
- Meeting the 72-hour breach-notification clock under pressure
- Managing data-subject requests within the one-month deadline
- Tracking processor agreements and international transfer safeguards
How organizations traditionally handle it
Many teams run GDPR out of spreadsheets and shared drives — a processing register that goes stale, DPIAs done ad hoc, and breach handling improvised. External counsel is brought in for incidents. This works until a data-subject request, an audit, or a breach exposes how little of it is current.
What can reasonably be automated
- Maintaining the record of processing as a living register
- Guided DPIA screening that flags high-risk processing
- Registers and workflows for breaches and data-subject requests, with the clock built in
- Tracking processor agreements and subprocessors
- Linking GDPR’s security requirement to your existing ISO 27001 controls
Evidence and documentation
- Record of processing activities (RoPA)
- DPIAs and the screening decisions behind them
- Breach register and notification records
- Data-subject request log with response times
- Data processing agreements and transfer mechanisms
- Privacy notices and consent records where relevant
Continuous verification
GDPR’s accountability principle (Art. 5(2)) means you must be able to demonstrate compliance at any moment — not reconstruct it after a complaint. Treating the register, DPIAs and processor list as live records that update as the business changes is what keeps accountability real.
How Isodora supports GDPR
Isodora’s GDPR module turns data-protection obligations into living registers with the deadlines built in.
Article 30 processing register
A living record of processing activities that updates as your tools and vendors change.
Guided DPIA screening
A structured flow that flags when a Data Protection Impact Assessment is required, and documents the decision.
Breach & DSR registers
Registers for breaches, data-subject requests and processor agreements — with reminders against the statutory clocks.
Shared security evidence
GDPR’s security-of-processing requirement reuses the controls you already run for ISO 27001.
Isodora helps you operationalize GDPR obligations. It is not legal advice; assessments such as lawful basis and DPIA outcomes remain your organization’s responsibility.
Frequently asked questions
- Who needs to comply with GDPR?
- Any organization that processes the personal data of people in the EU/EEA, whether as a controller or a processor, and regardless of where the organization is based. A company outside the EU offering goods or services to EU residents is in scope.
- How quickly must a data breach be reported under GDPR?
- A personal-data breach that is likely to risk individuals’ rights must be reported to the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33). Affected individuals must be told if the risk is high.
- What is a DPIA and when is it required?
- A Data Protection Impact Assessment analyses the privacy risks of a processing activity. It is required when processing is likely to result in a high risk to individuals — for example large-scale profiling, systematic monitoring, or large-scale special-category data (Article 35).
- What are the fines for GDPR non-compliance?
- The most serious breaches can be fined up to €20 million or 4% of total worldwide annual turnover, whichever is higher. Less severe breaches carry a lower tier of up to €10 million or 2%.