GRC Oversight

GDPR

The General Data Protection Regulation is the EU's comprehensive data protection law. It sets obligations for controllers and processors handling the personal data of individuals in the EU.

Governed by European Union (Regulation 2016/679)
What it is

What GDPR is, in plain terms

The General Data Protection Regulation is the European Union's comprehensive data protection law, applying to any organization that processes the personal data of people in the EU regardless of where the organization is based. It is built on principles such as lawfulness, purpose limitation, data minimization, and accountability, grants individuals strong rights over their data, and carries significant enforcement powers.

Typical effort & timeline

GDPR is an ongoing legal obligation rather than a certification with a deadline. Work focuses on establishing lawful bases, honoring data-subject rights, maintaining records of processing, and running DPIAs where required.

Who needs it

Is this framework for you?

  • Any organization offering goods or services to, or monitoring, people in the EU.
  • Controllers who determine why and how personal data is processed.
  • Processors who handle personal data on behalf of controllers.
About the framework

Key facts about GDPR

  • Built on principles including lawfulness, purpose limitation, data minimization, and accountability.
  • Grants data subjects rights such as access, rectification, erasure, and portability.
  • Requires records of processing activities and, in some cases, Data Protection Impact Assessments.
  • Includes obligations for breach notification and, where applicable, a Data Protection Officer.

Public information about the framework itself. We don't claim certifications, assessment status, or authorizations for our own product.

With this platform

How we help with GDPR

  • Maintain records of processing activities and accountability documentation.
  • Track data protection controls against tests and evidence.
  • Document DPIAs and data-subject-request handling processes.
  • Reuse evidence shared with ISO 27701 and other privacy work.
Step by step

Get and stay compliant

How the platform supports your GDPR program, from first scope to ongoing monitoring.

Map your data

Maintain records of processing activities so you know what personal data you hold and why.

Establish lawful bases

Document the lawful basis and consent handling for each processing activity.

Operationalize rights

Build and document processes for access, rectification, erasure, and portability requests.

Run DPIAs & respond

Document DPIAs for higher-risk processing and keep breach-notification processes ready.

Representative areas

What GDPR covers

Public, high-level control or requirement areas, for orientation, not a complete control list.

Lawful basis & consent
Data subject rights
Records of processing
Data protection impact assessments
Breach notification
International transfers
Do it once

Reuse evidence across frameworks

GDPR shares controls with frameworks you may already run. A passing test can satisfy requirements in more than one place, so adding the next framework means reusing work, not repeating it.

FAQ

Common questions about GDPR

Yes. It applies to any organization processing the personal data of individuals in the EU, regardless of where the organization is located.

A Data Protection Impact Assessment evaluates and documents the risks of processing that is likely to result in high risk to individuals' rights.

ISO 27701 provides a certifiable privacy management system that maps to GDPR obligations and supports demonstrable accountability.

Get audit-ready for GDPR

Get a guided demo, or start by scanning any domain for free.