Frameworks

What is GDPR?

The GDPR (General Data Protection Regulation) is the European Union’s data-protection law. It governs how organizations process the personal data of people in the EU and EEA, grants individuals strong rights over their data, and requires breach notification, generally within 72 hours.

Definition

The GDPR is a European Union regulation that sets rules for processing the personal data of individuals in the EU and EEA, giving those individuals defined rights and imposing obligations, and significant potential penalties, on the organizations that handle their data.

Background

GDPR applies broadly: to organizations established in the EU, and to those elsewhere that offer goods or services to, or monitor, people in the EU/EEA. It is built on principles such as lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality. Every act of processing needs a lawful basis (for example consent or legitimate interests). Individuals have rights including access, rectification, erasure, restriction, portability, and objection. Personal-data breaches generally must be reported to the supervisory authority within 72 hours, and serious violations can draw large fines.

Why it matters

If you handle data about people in the EU, GDPR very likely applies regardless of where you are based. Beyond avoiding penalties, a real privacy program is increasingly a condition of doing business with European customers and a signal of trustworthiness everywhere.

Step by step

  1. Map your personal data: what you hold, why, where it lives, and who you share it with.
  2. Establish a lawful basis for each processing activity.
  3. Honor data-subject rights with a defined request process.
  4. Put contracts in place with processors and document international transfers.
  5. Apply data minimization, retention limits, and appropriate security.
  6. Stand up a 72-hour breach-notification process and keep records of processing.

Examples

  • A SaaS company maps its data flows, documents a lawful basis for each, and builds a workflow to handle access and erasure requests.
  • A vendor signs data-processing agreements with its sub-processors and documents where EU data is transferred.

Common mistakes

  • Assuming GDPR does not apply because the company is outside the EU, even though it serves EU users.
  • Relying on consent for everything when another lawful basis fits better.
  • Having no defined, timely process for data-subject requests or breach notification.

FAQ

Who does GDPR apply to?

Organizations established in the EU, and organizations elsewhere that offer goods or services to, or monitor the behavior of, people in the EU/EEA. Location of the company is not the deciding factor.

What is the 72-hour rule?

A personal-data breach that poses a risk to individuals generally must be reported to the relevant supervisory authority within 72 hours of becoming aware of it, with affected individuals notified when the risk is high.

Related

GDPR in Keel → What is data classification? → What is vendor risk management? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free