GDPR
Who needs it
Any organization, anywhere in the world, that processes personal data of individuals located in the EU, whether that's employees, customers, or website visitors, regardless of the organization's own location.
Key requirements
A documented lawful basis for each processing activity, a Record of Processing Activities, honored data-subject rights (access, erasure, portability, objection), 72-hour breach notification, and Data Protection Impact Assessments for high-risk processing.
Cyber/privacy implications
Security controls must be mapped to specific categories of personal data and specific processing purposes, so a breach investigation has to determine not just what was accessed, but under what lawful basis it was being processed in the first place.
Assessment methodology
Data-flow mapping and Record of Processing Activities build-out, lawful-basis review per processing activity, breach-response readiness testing, and a gap analysis against Articles 5, 25, 32, and 33 specifically.
Implementation phases
Map
Build the Record of Processing Activities and confirm lawful basis per activity.
Remediate
Close technical and organizational control gaps, formalize data-subject request handling.
Sustain
Ongoing DPIA process for new processing activities and breach-response readiness.
Evidence & documentation requirements
Record of Processing Activities, documented lawful-basis assessments, Data Protection Impact Assessments for high-risk processing, data-processing agreements with vendors, and breach-response logs.
Common mistakes
Relying on consent as the default lawful basis when a more appropriate basis exists and would be more durable; treating a Data Processing Agreement with a vendor as sufficient without verifying the vendor's actual security controls.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your data processing stands against GDPR before a regulator asks.
Request a Gap Assessment →