What Is GDPR Compliance? Requirements and Penalties

GDPR compliance means aligning data collection, processing, and security with EU law. Requirements, data subject rights, penalties, and steps to comply.
Published on
Wednesday, September 9, 2026
Updated on
September 9, 2026

GDPR compliance means an organization’s handling of EU personal data matches what the General Data Protection Regulation requires. In practice, it covers four things. There has to be a lawful reason to process the data, people have to be told clearly how it is used, real security controls have to protect it, and the organization has to prove all of that when a regulator asks.

Personal data reaches further than most organizations assume. Names and email addresses are obvious, and the definition extends to ID numbers, IP addresses, cookie identifiers, and any other detail that can be traced back to a person. Geography offers no exemption either. A company headquartered in Bengaluru or Boston falls under the regulation the moment it processes data belonging to someone in the EU.

Who Must Comply with GDPR (General Data Protection Regulation)

Nothing in the regulation asks where an organization is registered. Scope turns on three tests instead: establishment in the EU, the offering of goods or services to people in the EU, or the monitoring of their behavior.

Organizations Established in the EU

Any organization operating within an EU member state and processing personal data as part of its activities falls in scope. Headcount and revenue make no difference to whether the regulation applies, though they do affect a small number of specific obligations.

Organizations Outside the EU Serving EU Residents

An e-commerce platform in Mumbai that ships to Germany, or a SaaS provider in California billing customers in France, sits under GDPR without any physical presence in Europe. Accepting payment in euros, offering a local-language site, or naming EU countries in marketing all signal that a business is targeting people there.

Organizations Monitoring EU Individuals

Tracking, profiling, or analyzing behavior brings a company into scope on its own. Cookie-based analytics, behavioral advertising, and usage telemetry each count as monitoring when they involve people located in the EU.

Controllers and Processors

A controller decides why and how personal data gets processed, and carries the primary compliance burden. A processor handles data on the controller’s behalf under contract, following instructions while still implementing its own security measures. Cloud hosting providers, payroll bureaus, and analytics vendors are typical processors, and both parties face direct liability under the regulation.

Private companies hold no monopoly here. Government agencies, non-profits, universities, and partnerships all fall within scope the moment they handle EU personal data. A controller remains accountable for what its processors do, which is why a third-party data breach at a vendor becomes the controller’s regulatory problem as well.

Seven Core Principles of GDPR

GDPR Article 5 sets out the principles every processing activity has to satisfy. They read as abstract statements and function as testable requirements, because a regulator investigating a complaint works through them one by one.

principles of gdpr
  1. Lawfulness, fairness, and transparency. Every processing activity needs a valid legal basis, and people must be able to understand how their data is used.
  2. Purpose limitation. Data collected for one stated reason cannot be repurposed for something unrelated without informing the people involved.
  3. Data minimization. Collect what the stated purpose requires, not everything a system is technically capable of gathering.
  4. Accuracy. Personal data must stay current, and corrections have to happen without unnecessary delay.
  5. Storage limitation. Retention periods need defining in advance, and data cannot sit in a database indefinitely because nobody decided when to delete it.
  6. Integrity and confidentiality. Data requires protection against unauthorized access, accidental loss, and damage, using measures proportionate to its sensitivity.
  7. Accountability. Following the rules is not sufficient on its own. An organization has to demonstrate compliance through documentation, records, and policies.

Accountability is the principle that turns the other six principles into work. An audit examines the record of processing activities, documented risk decisions, and evidence of review. Building that evidence trail is where GDPR overlaps most heavily with information security management.

Key Requirements for GDPR Compliance

Meeting GDPR obligations requires organizations to take specific legal, technical, and organizational actions to protect personal data.

Here are the main requirements for GDPR compliance:

Establish a Lawful Basis for Processing

Every instance of personal data processing must rely on a valid legal basis defined under GDPR. This may include consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests. Organizations must clearly document the chosen legal basis.

Manage Consent Properly

When consent is used as the legal basis, it must be freely given, specific, informed, and unambiguous. Individuals must have the ability to withdraw consent as easily as they gave it.

Enable Data Subject Rights

Organizations must have procedures in place to respond to requests from individuals. This includes providing access to personal data, correcting inaccuracies, deleting data when required, and supporting portability requests within the legal timeframe.

Implement Appropriate Security Measures

Technical and organizational safeguards must protect personal data against unauthorized access, alteration, or loss. Security controls should match the sensitivity and risk level of the processed data.

Appoint a Data Protection Officer (DPO) When Required

Certain organizations must designate a Data Protection Officer. This applies when core activities involve large-scale monitoring or processing of sensitive data. The DPO oversees compliance and acts as a contact point for supervisory authorities.

Conduct Data Protection Impact Assessments (DPIA)

When processing activities pose a high risk to individuals’ rights and freedoms, organizations must perform a formal risk assessment. A DPIA evaluates potential impact and defines mitigation measures before processing begins.

Report Data Breaches Within 72 Hours

Organizations must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to pose a risk to individuals. In certain cases, affected individuals must be informed as well.

Key GDPR Compliance Requirements

Where the principles set direction, the requirements below are what an organization actually has to implement. Each one maps to a specific article of the regulation.

Establish a Lawful Basis for Processing

Article 6 provides six lawful bases: consent, contractual necessity, legal obligation, vital interests, public task, and legitimate interests. Each processing activity needs one basis documented before processing starts. Legitimate interests requires an additional balancing assessment weighing the organization’s purpose against the individual’s rights.

Manage Consent Correctly

Where consent is the basis, it has to be freely given, specific, informed, and unambiguous, which rules out pre-ticked boxes and bundled agreements. Withdrawing consent must be as easy as giving it. One move regulators treat harshly is switching quietly to a different legal basis in order to keep processing data after someone has withdrawn consent. Cookie consent follows the same standard, with the ePrivacy Directive adding a separate requirement to obtain consent before placing non-essential cookies on a device.

Implement Security Measures Under Article 32

Security obligations scale with risk rather than with company size. Article 32 names encryption and pseudonymization explicitly, alongside the ability to restore availability after an incident and a process for regularly testing the effectiveness of controls. Regular testing is the clause organizations overlook most, and it is why periodic security assessment sits inside the compliance program rather than beside it.

Appoint a Data Protection Officer When Required

Article 37 makes a DPO mandatory in three situations, and only in those three. The first is where the organization is a public authority. The second is where core activities involve regular and systematic monitoring of individuals on a large scale. The third is where core activities involve large-scale processing of special category data such as health, biometric, or criminal conviction records. Consider a fifty-person health technology startup processing patient records. Headcount is irrelevant here, because large-scale is judged on data volume and sensitivity rather than company size.

Conduct Data Protection Impact Assessments

High-risk processing requires a DPIA before the activity goes live. Large-scale profiling, biometric identification, and systematic monitoring of public areas all qualify. Picture a retail chain deploying facial-recognition cameras across its stores to measure footfall: that is biometric processing at scale, and the assessment belongs before rollout rather than after a complaint. The methodology overlaps closely with a security threat assessment, though a DPIA measures risk to individuals rather than risk to the business.

Build in Privacy by Design and by Default

Article 25 requires data protection to be built into systems at the design stage rather than added afterwards. Privacy by default goes further: the out-of-the-box configuration must be the most privacy-protective one, so a new user account arrives with optional data sharing switched off until someone turns it on. Retrofitting these controls into a live product costs far more than designing them in, which is the practical reason the article exists.

Report Breaches Within 72 Hours

Article 33 gives an organization 72 hours from becoming aware of a personal data breach to notify its supervisory authority, unless the breach is unlikely to result in risk to individuals. Article 34 adds a separate duty to inform affected people directly where the risk to them is high. The clock starts at awareness, not at confirmation, so detection speed determines whether the deadline is realistic at all.

A second obligation sits inside the same article and gets missed regularly. Article 33(5) requires organizations to document every personal data breach internally, including ones that never met the notification threshold, along with the reasoning behind that decision. Regulators ask to see this register during investigations.

GDPR Documentation and Contractual Obligations

Three paperwork requirements decide most audits, and organizations outside the EU miss them at a higher rate than any technical control. None of them involves security tooling, and all three are named obligations with their own articles.

1. Records of Processing Activities (Article 30)

A RoPA is a written inventory of every processing activity: what data is held, why, who receives it, where it goes, and how long it is kept. Supervisory authorities can demand it and expect it promptly, which makes it the single fastest way an organization demonstrates that it understands its own data. Organizations with fewer than 250 employees are exempt under Article 30(5), but only where processing is occasional, poses no risk to individuals, and involves no special category data. Those three conditions rule out most businesses in practice.

2. Data Processing Agreements (Article 28)

Any controller using a processor must have a written contract in place before data changes hands. Article 28 sets out what the agreement has to specify. That covers the subject matter and duration of processing, its nature and purpose, and the categories of data and data subjects involved. The agreement must set out the processor’s obligations around security, sub-processors, deletion, and audit rights.

3. EU Representative (Article 27)

Organizations outside the EU that fall under GDPR must appoint a representative established in a member state where their data subjects are located. The representative is designated in writing, named in privacy notices, and acts as the contact point for supervisory authorities and individuals exercising their rights. This is the obligation non-EU companies overlook most consistently, because it applies even to businesses with no European staff, office, or infrastructure. The exemption is narrow, covering only occasional processing that carries no risk and involves no special category data.

Eight Data Subject Rights Under GDPR

Individuals hold eight enforceable rights over their personal data, and organizations have one month to respond to most requests, extendable by two further months for complex cases.

Right What the individual can do
Right to be informed Learn what data is collected, why, and who receives it, at the point of collection
Right of access Confirm what data is held and obtain a copy of it
Right to rectification Have inaccurate or incomplete data corrected
Right to erasure Request deletion once data is no longer necessary or consent is withdrawn
Right to restrict processing Temporarily limit how data is used while a dispute is resolved
Right to data portability Receive their data in a structured, machine-readable format
Right to object Stop processing based on legitimate interests, and stop direct marketing outright
Rights around automated decisions Avoid decisions made solely by automated processing where these have legal or similarly significant effects

Objections to direct marketing work differently from the others, because no balancing test applies. When someone objects, processing for that purpose stops, with no assessment of competing interests and no exceptions.

International Data Transfers Under GDPR

Moving personal data outside the EU requires a legal transfer mechanism, and this is the area that has produced the largest penalties on record. Chapter V of the regulation permits transfers only where the destination offers protection essentially equivalent to EU standards.

Most organizations rely on one of three mechanisms. An adequacy decision, where the European Commission has ruled a country’s protection sufficient, allows transfers without further safeguards. Standard Contractual Clauses are pre-approved contract terms that impose EU-level obligations on the receiving party. Binding Corporate Rules govern transfers inside a multinational group and require approval from a supervisory authority.

Transfers to the United States run through the EU-US Data Privacy Framework, adopted in July 2023 after two earlier arrangements were struck down by the Court of Justice. Organizations relying on it need to verify that the US recipient is actively certified, because the framework covers only participating companies rather than the country as a whole.

GDPR Penalties and Enforcement

Article 83 splits penalties into two tiers according to the seriousness of the violation. The lower tier reaches €10 million or 2% of global annual turnover, whichever is higher, and covers failures such as inadequate records or weak security. The upper tier reaches €20 million or 4% of global turnover, and applies to unlawful processing, ignoring data subject rights, and breaching transfer rules.

Regulators now issue penalties as a matter of routine rather than as rare headline events. The DLA Piper GDPR Fines and Data Breach Survey published in January 2026 put cumulative fines at approximately €7.1 billion since May 2018, with €1.2 billion issued during 2025 alone. Ireland’s Data Protection Commission accounts for €4.04 billion of that total, largely because major US technology companies base their European headquarters there.

That same survey recorded a 22% annual rise in notified data breaches, averaging 443 notifications per day across Europe and passing 400 per day for the first time since 2018. Breach volume, not just fine value, is what has changed.

The largest penalty on record remains the €1.2 billion fine issued against Meta by the Irish Data Protection Commission in May 2023 for unlawfully transferring EU user data to the United States. Fines are not the only instrument available, either. Supervisory authorities can issue warnings, order changes to processing, ban an activity outright, or require data to be deleted. Penalty severity turns on how long a violation persisted, whether it was deliberate, how many people were affected, and what the organization did to remediate.

Steps to Achieve GDPR Compliance

Compliance programs follow much the same sequence regardless of company size, because each step depends on the one before it.

  1. Map personal data across the organization. Record what is collected, where it is stored, who can access it, and which third parties receive it. Nothing later in the sequence works without this inventory.
  2. Assign a lawful basis to every processing activity and document the reasoning, including the balancing assessment where legitimate interests applies.
  3. Turn the data map into a record of processing activities under Article 30, and keep it current as systems and vendors change rather than refreshing it annually.
  4. Put a data processing agreement in place with every vendor that touches personal data, and appoint an EU representative if the organization has no establishment in the EU.
  5. Rewrite privacy notices in plain language to cover what Articles 13 and 14 require. That means the controller’s identity and contact details, the purposes and legal basis, recipients, transfer safeguards, retention periods, and the full set of rights.
  6. Strengthen technical controls to meet Article 32, covering access restriction, encryption, pseudonymization where practical, and a documented testing schedule.
  7. Build workflows for data subject requests so access, correction, deletion, and portability requests follow a defined process within the one-month deadline.
  8. Appoint a DPO where the three mandatory conditions apply, and record the assessment even when the conclusion is that no DPO is required.
  9. Prepare a breach response plan covering detection, severity assessment, the 72-hour notification window, and the separate duty to inform affected individuals.
  10. Review and audit on a fixed schedule, because processing activities, vendors, and retention needs all change faster than documentation does.

Detecting Data Exposure That Triggers GDPR Obligations

Article 33 starts its 72-hour clock when an organization becomes aware of a breach, which makes detection speed a compliance variable rather than only a security one. Data that has already left the environment stays invisible to internal monitoring. CloudSEK XVigil covers that gap, tracking deep and dark web sources, leaked-data marketplaces, and paste sites for information tied to a specific organization.

Early discovery changes what an organization can report and when. Finding leaked credentials or an exposed database before it reaches a criminal forum buys a security team time. Scope can be assessed, the exposure contained, and notification filed inside the window rather than after it. Broader digital risk protection extends the same visibility to publicly exposed assets and misconfigured systems.

None of this delivers GDPR compliance on its own. Lawful basis documentation, privacy notices, DPIAs, consent management, and records of processing remain legal and governance work. External monitoring supports the security obligations under Article 32 and the detection half of Article 33, which is a specific contribution rather than a compliance solution.

Frequently Asked Questions

Does GDPR still apply to UK companies after Brexit?

Yes, in two ways. The UK GDPR governs domestic processing, and EU GDPR still applies to any UK company offering goods or services to people in the EU.

How long can personal data be retained under GDPR?

GDPR sets no fixed period. Organizations define retention themselves based on the processing purpose, then document the justification and delete the data once that purpose ends.

Does GDPR cover B2B contact data?

Yes. A named work email such as [email protected] identifies a person and counts as personal data. Generic addresses like [email protected] fall outside the definition.

Are small businesses exempt from any GDPR obligations?

Only one. Organizations under 250 employees can skip full records of processing activities, unless processing is regular, poses a risk to individuals, or involves special category data.

What happens if an organization refuses to pay a GDPR fine?

Supervisory authorities enforce fines through national courts, with cross-border cooperation available. They can suspend processing entirely, which hurts operations more than the fine itself.

Does GDPR apply to data collected before May 2018?

Yes. The regulation covers all personal data an organization holds, regardless of collection date. Consent gathered under the old rules had to be revalidated if it did not meet GDPR standards.

Final Thoughts: Treating GDPR Compliance as an Operating Discipline

Organizations that treat GDPR as a documentation exercise tend to discover the gap during an incident. Policies describe an environment that has since changed, retention schedules cover systems nobody uses, and the data map omits the vendor onboarded last quarter.

Programs that hold up share a few habits. The data inventory gets updated when systems change rather than annually. Retention periods are enforced by automation instead of intention. Breach detection is fast enough that 72 hours is a realistic window rather than an aspiration. Regulators have made the direction clear. With €1.2 billion in fines during 2025 and breach notifications rising 22% year over year, treating compliance as a periodic project has become the more expensive option.

Related Posts
What is Pastebin? Uses, Risks, and How It Works
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
What is Personally Identifiable Information (PII)?
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.
What Is the National Vulnerability Database (NVD)?
The National Vulnerability Database (NVD) is NIST's public repository of CVE data with severity scores. How the NVD works and its 2026 triage shift.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.