Quick answer

The General Data Protection Regulation protects EU personal data. It applies to any organization processing data about people in the EU, regardless of where the organization sits, and it requires a lawful basis for processing, documented records, data subject rights handling, breach notification within 72 hours, and appropriate security. Sanctions reach 20 million EUR or 4 percent of global annual turnover. Transfers to the US are workable under the EU-US Data Privacy Framework, but they need to be documented and justified.

The obligations that generate actual work

GDPR compliance in practice comes down to a recurring set of artifacts and processes:

  • Records of processing (Article 30): a maintained register of what personal data you process, why, where, and with whom. This is the document authorities ask for first.
  • Lawful bases and consent: every processing purpose needs a documented basis; consent, where used, must be provable.
  • Data subject rights: access, deletion, portability, and objection requests need a tracked process with deadlines.
  • Processor management: DPAs with every vendor touching personal data, plus transfer mechanisms (like the Data Privacy Framework) for non-EU vendors documented per transfer.
  • Breach notification: 72 hours to the supervisory authority (IMY in Sweden) when a breach risks individuals' rights, with an internal record of every incident, reported or not.
  • Security of processing (Article 32): measures appropriate to risk, which in practice means the same controls your security frameworks already require.

GDPR is not a one-time project

The 2018 compliance projects produced binders that are now badly out of date, and drift is where fines start: a new SaaS tool enters use without a DPA, a data flow changes without the register updating, a breach response misses the deadline because the process was never rehearsed. GDPR work is maintenance work, which is why it belongs in the same continuously monitored program as your security controls. See how OptiTech operationalizes it.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.