EU GDPR

Mandatory · EU

GDPR compliance that holds under regulator scrutiny.

Data protection governance for any organisation handling EU personal data — at the size, complexity, and budget of an SMB.

Overview

Seven principles, six lawful bases, eight data-subject rights.

GDPR — Regulation (EU) 2016/679 — is built on seven core principles governing every aspect of how personal data must be handled. These are not aspirational; they are legal requirements, and supervisory authorities (the CNIL in France, the BfDI in Germany, the AP in the Netherlands, the DPC in Ireland, the Garante in Italy, the AEPD in Spain) assess compliance against them directly.

Article 3 gives GDPR extraterritorial reach: it applies to any organisation that processes personal data of EU residents in connection with offering goods or services to them, or monitoring their behaviour within the EU — regardless of where the organisation is established. A US, UK, or Australian company with EU customers or visitors is subject to GDPR.

AI systems processing personal data fall under both GDPR and the EU AI Act — including the EDPB's Opinion 28/2024 on AI models and personal data. The Article 35 DPIA process integrates cleanly with the AI Act's Article 27 Fundamental Rights Impact Assessment. Our AI Governance & Security service handles the GDPR × AI Act overlap, with ISO/IEC 42001 readiness built in.

Who GDPR applies to

Effectively: anyone processing EU residents' personal data. The signals below tend to come up first.

  • Any business with EU customers or website visitors

    Sales to EU residents, EU-targeted marketing, or behavioural tracking of EU users — extraterritorial reach under Article 3.

  • Employers in the EU

    HR data, payroll, recruitment, expense management, performance reviews — all GDPR-covered processing.

  • B2B services touching personal data

    CRM, email marketing, customer support, analytics — even B2B businesses process named individuals at supplier and customer organisations.

  • Processors of personal data on behalf of others

    SaaS providers, agencies, payroll bureaus, IT outsourcers — Article 28 obligations apply, and Data Processing Agreements are mandatory.

The principles

Seven principles every processing activity must respect.

  1. 01Art. 5(1)(a)

    Lawfulness, fairness & transparency

    Processing must have a lawful basis, be fair to data subjects, and be transparent about how their data is used.

  2. 02Art. 5(1)(b)

    Purpose limitation

    Data collected for one purpose cannot be used for a different, incompatible purpose without a new lawful basis.

  3. 03Art. 5(1)(c)

    Data minimisation

    Only collect personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.

  4. 04Art. 5(1)(d)

    Accuracy

    Personal data must be accurate and kept up to date. Inaccurate data must be erased or corrected without delay.

  5. 05Art. 5(1)(e)

    Storage limitation

    Personal data must not be kept longer than necessary. Documented retention schedules are mandatory.

  6. 06Art. 5(1)(f)

    Integrity & confidentiality

    Data must be protected against unauthorised access, loss, or destruction using appropriate technical and organisational measures (Article 32).

  7. 07Art. 5(2)

    Accountability

    Organisations must be able to demonstrate compliance — not just claim it. Documentation, policies, ROPA, and records are the evidence.

Penalties & consequences

The headline numbers — and what actually triggers fines.

The headline maximum is €20 million or 4% of total worldwide annual turnover — whichever is higher — for the most serious violations (lawful basis, principles, data subject rights, international transfers). Lesser violations cap at €10 million or 2%. Failure to designate a DPO when required is itself a Tier 1 violation, independent of any breach.

For SMBs the principles that drive the most enforcement are purpose limitation (using data beyond disclosed purposes), data minimisation (collecting more than needed), and storage limitation (retaining too long). The rights that drive the most complaints are access (Subject Access Requests) and erasure (right to be forgotten). And the lawful basis most challenged by authorities is legitimate interests.

  • Tier 1 max fine

    €20M / 4%

    whichever is higher, of total worldwide annual turnover.

  • Tier 2 max fine

    €10M / 2%

    whichever is higher — for procedural and DPO-designation failures.

  • Breach notification

    72 hours

    from awareness, to your supervisory authority's portal — CNIL in France, BfDI in Germany, AP in the Netherlands, DPC in Ireland, etc.

Our approach

A six-phase GDPR compliance roadmap.

What we deliver

  • GDPR readiness assessment — gap analysis against the seven principles and core articles
  • Article 30 ROPA build — complete inventory of processing activities, lawful bases, data categories, retention, recipients
  • Privacy notices, consent mechanisms, and data subject rights procedures (8 rights with documented timelines)
  • DPIA process for high-risk processing under Article 35, with templates and review cadence
  • Breach notification process — 72-hour internal escalation, CNIL/ICO notification templates, breach register
  • Data Processing Agreements with third-party processors and sub-processors
  • Documented retention schedule applied across all data categories
  • DPO as a Service where Article 37 designation is mandatory or strategically valuable

Typical timeline

GDPR engagements run on the maturity of your starting point.

  1. 4–8 weeks

    Readiness sprint

    Gap analysis, ROPA, top-priority policy and notice work, breach process — enough to defend an inspection or satisfy a customer audit.

  2. 3–6 months

    Full compliance program

    Comprehensive policy library, all 8 data subject rights workflows, DPIA process, processor contracts, training, and ongoing review cadence.

FAQ

Common questions.

Does GDPR apply to my business if we are based outside the EU?
Yes if you offer goods or services to EU residents, or monitor their behaviour within the EU. Article 3 has extraterritorial reach. A US, UK, or Australian company with EU customers or website visitors whose behaviour it tracks is subject to GDPR — and may need to appoint an EU representative under Article 27.
What is a DPIA and when is it mandatory?
A Data Protection Impact Assessment is a structured process for identifying and mitigating the privacy risks of a processing activity before it begins. Under Article 35, a DPIA is mandatory for processing likely to result in high risk to individuals — specifically: systematic and extensive profiling, large-scale processing of special-category data (health, genetic, biometric, religious beliefs), and systematic monitoring of publicly accessible areas.
Do we need a Data Protection Officer (DPO)?
Article 37 makes a DPO mandatory for public authorities, organisations whose core activities involve large-scale systematic monitoring of individuals, and organisations that process special categories of data at scale. Even where not strictly mandatory, many SMBs appoint one voluntarily — either because clients require it, or because the role provides ongoing oversight that reduces violation risk.
What's the difference between a controller and a processor?
A data controller determines the purposes and means of processing personal data — they decide why and how data is processed. A data processor processes personal data on behalf of a controller, following the controller's instructions. Many SMBs are simultaneously both — controller for their own employee and customer data, processor for their clients' data — and must implement both sets of obligations.
How long can we keep personal data under GDPR?
There is no single prescribed retention period — it depends on the data, the purpose, and any legal obligations. Organisations must document their retention periods in a Retention Schedule and apply them consistently. Where a legal obligation requires longer retention than the original purpose would justify (e.g. tax records, employment law), the legal-obligation lawful basis governs.
What should we do if we suffer a personal data breach?
Five steps: (1) contain the breach and preserve evidence; (2) assess the risk to individuals; (3) if there is a risk, notify your supervisory authority within 72 hours of becoming aware — via your authority's portal (CNIL in France, BfDI in Germany, AP in the Netherlands, DPC in Ireland, Garante in Italy, AEPD in Spain, etc.); (4) if the breach poses a high risk to individuals, notify them directly without undue delay; (5) document everything in your breach register under Article 33(5), including breaches you decide not to report.