GDPR compliance means applying the Regulation’s principles and specific duties to real processing, making defensible decisions, and retaining evidence that controls work. It is an ongoing accountability programme—not a certificate, policy pack or one-time checklist.
Does the GDPR apply?
The GDPR applies to processing in the context of an EU establishment, regardless of where processing occurs. It can also apply to a controller or processor without an EU establishment where relevant processing concerns offering goods or services to people in the EU or monitoring their behaviour in the EU. Article 3 analysis depends on the activity and facts; a website merely being accessible in the EU is not, by itself, the whole test.
Identify each legal entity’s role. Controllers determine purposes and means; processors act on documented controller instructions; joint controllers jointly determine purposes and means. Contract labels do not override actual roles.
The seven principles
Article 5 requires:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability for compliance with the other principles.
Translate these into product defaults, approval workflows, access controls, retention logic and monitoring. A principle that appears only in a policy is not yet operational.
Choose a lawful basis by purpose
Article 6 provides six bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Choose before processing and document the actual purpose and necessity. Consent is not inherently “stronger” than another basis and should not be used when people lack a genuine choice.
Special-category data under Article 9 normally requires both an Article 6 basis and an applicable Article 9 condition. Criminal-conviction data is subject to Article 10. Member State law can materially affect employment, health and other processing.
Inform people and support rights
Articles 12–14 require concise, transparent, intelligible information. Depending on the circumstances, notices address identity and contacts, purposes, lawful bases, legitimate interests, recipients, transfers, retention, rights, complaint routes, sources and automated decisions.
Build procedures for access, rectification, erasure, restriction, portability, objection, and qualifying automated decision-making. Respond without undue delay and generally within one month. Article 12 permits a two-month extension where necessary because of complexity and number, but the person must be informed within the first month with reasons. Rights have conditions and exceptions; log the legal reasoning for decisions.
Build accountable records and governance
A practical programme includes:
- processing inventory and Article 30 records where required;
- lawful-basis, retention and transparency mapping;
- contracts and oversight for processors under Article 28;
- privacy-by-design review for new or changed processing;
- DPO and Article 27 representative assessments;
- training appropriate to actual roles;
- issue, decision and remediation logs; and
- risk-based monitoring with senior-management reporting.
The Article 30 exemption for organisations with fewer than 250 persons is limited; it does not cover non-occasional processing or the risk and sensitive-data cases specified in Article 30(5).
DPIAs and security
Complete a DPIA before processing likely to result in high risk, particularly the Article 35 examples and activities on relevant supervisory-authority lists. Describe processing and purposes, assess necessity and proportionality, evaluate risks to individuals, and identify measures. If high residual risk remains, Article 36 may require prior consultation.
Article 32 requires security appropriate to risk, considering factors such as state of the art, implementation cost, nature and context of processing, and risks to people. No single framework or certification automatically proves GDPR compliance.
For personal-data breaches, keep an internal record. Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware unless the breach is unlikely to risk individuals’ rights and freedoms. Communicate to affected people without undue delay where high risk is likely, subject to Article 34’s exceptions.
International transfers
For Chapter V transfers, verify an applicable adequacy decision or use appropriate safeguards such as SCCs or BCRs, with an assessment of effectiveness and supplementary measures where needed. Article 49 derogations are conditional and generally unsuitable as routine architecture.
Enforcement and fines
Supervisory authorities have corrective powers in Article 58. Article 83 sets two administrative-fine tiers: up to €10 million or 2% of total worldwide annual turnover for the preceding financial year for certain infringements, and up to €20 million or 4% for specified more serious infringements, whichever is higher for an undertaking. These are statutory maxima, not automatic prices for an infringement; authorities consider the Article 83 factors and applicable procedure.
A workable implementation sequence
- Determine scope, entities and roles.
- Build and validate the processing inventory.
- Correct high-risk unlawful processing and urgent security gaps.
- Align lawful bases, notices, rights procedures and retention.
- Review processors, sharing and transfers.
- complete required DPIAs and role assessments.
- establish monitoring, evidence and change control.
Our data protection services help implement this programme. For an independent baseline and prioritised roadmap, see our GDPR audit service.
Sources and review
- Regulation (EU) 2016/679, official text
- European Commission: information for businesses and organisations
- EDPB Guidelines 3/2018 on territorial scope
Reviewed on 8 August 2026. Fine levels are described as maxima, and rights, breach deadlines and territorial scope include the conditions that determine whether they apply.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.