Skip to content.
Three people sit together at a table, looking at a laptop screen and discussing something. The setting appears to be a modern office with glass walls and bright lighting.

What organizations need to know about GDPR compliance

GDPR applies across all 27 EU member states and the EEA countries Iceland, Liechtenstein and Norway. It can also apply to companies based elsewhere. For organizations based outside the EU/EEA, that can include offering goods or services to people in the EU/EEA or monitoring their behavior there.  

If GDPR applies, you need to know what personal data your organization uses, why it uses it and who it’s shared with. You also need processes for individual rights, third parties, international transfers, security and data breaches.  

This article provides an overview of GDPR compliance requirements and how to put them into practice.

What is GDPR?

The General Data Protection Regulation (GDPR) is the EU regulation governing how organizations process personal data. It has applied since May 25, 2018 and covers how personal data is collected, used, stored, shared and protected. 

Personal data identifies or could identify a living person, while processing includes actions such as collecting, storing, accessing, sharing or deleting it.

Who does GDPR apply to?

GDPR applies to organizations established in the EU/EEA and can also apply to organizations outside the EU/EEA. For organizations outside Europe, offering goods or services to people in the EU/EEA or monitoring their behavior can bring relevant processing within scope.  

Organizations based in the EU and EEA

Organizations established in the EU or EEA are subject to GDPR for processing carried out in the context of that establishment. This applies regardless of where the processing itself takes place. 

GDPR requirements can impact multinational organizations as well as companies headquartered in Europe. For example, an EU subsidiary of a U.S. parent company may process personal data that is later accessed elsewhere in the group. 

U.K. organizations under U.K. GDPR

Since January 1, 2021, the U.K. has operated its own U.K. GDPR framework alongside the Data Protection Act 2018. Your organization can be subject to both EU GDPR and U.K. GDPR if its activities bring it within both regimes. 

U.K. requirements have since been amended by the Data (Use and Access) Act 2025. This article focuses primarily on EU GDPR requirements – see our Comparing the UK GDPR and EU GDPR guide if your organization operates across both jurisdictions. 

U.S. companies subject to GDPR

U.S. companies can be required to comply with GDPR without having an office in Europe. GDPR can apply if your organization offers goods or services to people in the EU/EEA or monitors their behavior there.  

For example, a U.S. SaaS company that markets subscriptions to customers in France and Germany and processes their account data may be in scope of GDPR. Depending on its activities, a company outside the EU may also need to appoint an EU representative.

What does GDPR require?

GDPR requires your organization to have a lawful basis for each purpose for which it processes personal data as a controller. Identify and document that basis before processing starts, and state it in your privacy notice. 

The seven GDPR data protection principles are:: 

  • Lawfulness, fairness and transparency 
  • Purpose limitation 
  • Data minimization 
  • Accuracy 
  • Storage limitation 
  • Integrity and confidentiality 
  • Accountability 

Together, these principles require your organization to know why it uses personal data, limit that use to defined purposes, protect the data and keep evidence of the decisions and controls behind your approach. 

Lawful basis for processing personal data 

GDPR requires your organization to have a lawful basis for each purpose for which it processes personal data as a controller. To comply with requirements as a data controller under GDPR, you must identify and document that basis before processing starts and state it in your privacy notice. 

The six lawful bases for processing personal data under GDPR are: 

  • Consent: The person freely agrees to processing for a specific purpose, such as opting in to marketing emails. 
  • Contract: The processing is needed to fulfill a contract, such as using a customer’s address to deliver an order. 
  • Legal obligation: The processing is required by law, such as reporting payroll information to a tax authority. 
  • Vital interests: The processing is needed to protect someone’s life or physical safety, such as sharing medical information in an emergency. 
  • Public task: The processing supports an official function set out in law, such as a public authority providing a statutory service. 
  • Legitimate interests: The processing supports a genuine business or third-party interest, such as fraud prevention or IT security, provided the person’s rights do not outweigh that interest. 

Data subject rights under GDPR 

GDPR gives people specific rights over how your organization uses their personal data. Your organization must normally respond to a valid request within one month, with a possible extension of up to two further months for complex or numerous requests. 

Data subject rights include: 

  1. Right of access: People can request their personal data and information about its use. 
  2. Right to rectification: People can ask for inaccurate or incomplete information to be corrected. 
  3. Right to erasure: People can request deletion where the relevant conditions apply. 
  4. Right to restrict processing: People can ask your organization to limit certain uses of their data. 
  5. Right to data portability: People can receive certain data in a structured, machine-readable format. 
  6. Right to object: People can object to processing in specified circumstances, including direct marketing. 
  7. Rights related to automated decisions: People have protections around certain significant decisions made solely through automated processing.

Data protection by design and default 

Data protection by design means considering privacy when you develop a system, product or process. Data protection by default means limiting the data collected, access given and processing performed to what the purpose requires. 

This could mean removing unnecessary form fields, restricting system access or setting appropriate retention rules from the start. Higher-risk processing may also require a Data Protection Impact Assessment (DPIA) before processing begins.  

GDPR data breach notification requirements 

If a personal data breach is likely to result in a risk to people’s rights and freedoms, your organization must notify the relevant supervisory authority within 72 hours of becoming aware of it. If the breach is likely to result in a high risk, your organization must also inform affected people without undue delay, unless an exception applies. 

A personal data breach can involve loss, destruction, alteration, unauthorized disclosure or unauthorized access. Not every security incident requires notification, so your organization needs a process for assessing the data affected and the likely consequences.

Why GDPR is important

Data breaches and reputational backlash were the top reported compliance issues of 2025 and 2026, according to our 2026 and 2025 State of Risk & Compliance survey data.

How to achieve GDPR compliance

These 13 GDPR compliances steps outline the main areas your organization should review to achieve GDPR compliance. The detail within each area will depend on your processing activities, your role and the level of risk involved. 

Step 1: Determine whether GDPR applies to your organization

Confirm whether your organization has an EU/EEA establishment, offers goods or services to people there or monitors their behavior. 

Revisit the assessment when you introduce a new product, system or process that uses personal data  

Step 2: Map your processing activities, classify your role and record them in your ROPA

Map each processing activity by purpose, including the personal data involved, why you use it, which systems process it, who receives it and where it goes. 

For each activity, determine whether your organization acts as a controller, processor or joint controller. Record the required information in your Record of Processing Activities (ROPA) and keep it current as your processing changes. 

Step 3: Work through the controller checklist

For each activity where your organization acts as a controller, check that the main requirements are covered before moving into the detailed processes below. 

Confirm that you have: 

  • Documented a lawful basis for each activity and completed an LIA when using legitimate interests 
  • Identified any additional condition for special category or criminal offense data 
  • Kept privacy notices current and managed consent where used 
  • Set up a process for data subject rights requests 
  • Established and tested a data breach response plan 
  • Screened for privacy risk, completed DPIAs where required and applied data protection by design and default 
  • Reviewed third parties and put appropriate agreements in place before sharing personal data 
  • Met relevant cookie and marketing requirements under GDOR and ePrivacy rules, including consent and opt-outs

Make sure your privacy notices explain what your organization does with personal data in clear language. 

They should reflect the purpose, lawful basis, recipients, international transfers, retention periods and relevant rights. 

Where consent is used, make sure people have a genuine choice, keep evidence of that consent and make withdrawal straightforward. 

Step 5: Determine risk level and conduct DPIAs

Screen your current processing activities for high risk, and repeat the screening for new or significantly changed processing. Carry out a Data Protection Impact Assessment (DPIA) where processing is likely to result in a high risk to people’s rights and freedoms. 

The DPIA should document the processing, why it is necessary, the risks involved and the safeguards used to reduce them. 

Step 6: Set rules for working with other organizations

Identify whether each third party acts as your processor, another controller or a joint controller. 

Before appointing a processor, review its privacy and security controls, where it handles data, which subprocessors it uses and whether it can support your GDPR obligations. 

Put a Data Processing Agreement in place when another organization processes personal data on your behalf. Where both organizations act as controllers, document how the data will be shared and how GDPR responsibilities will be handled. 

Step 7: Put safeguards in place for international data transfers

Identify where personal data is stored, processed or accessed outside the EU/EEA. 

For each restricted transfer, determine which mechanism applies. Depending on the destination and recipient, this could include an adequacy decision, the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. 

For transfers that rely on safeguards such as Standard Contractual Clauses, complete a Transfer Impact Assessment (TIA) and put any additional safeguards it identifies in place. Record the transfer and safeguard in your ROPA and privacy notice. 

Step 8: Minimize personal data and set retention periods

Collect only the personal data needed for each purpose. 

Set a retention period or clear retention criteria for each processing activity and record it. Make sure deletion takes place across systems, archives, shared drives, backups and processor-held copies where relevant. 

Where you no longer need identifiable data, delete it or consider whether it can be properly anonymized. 

Step 9: Build processes for data subject rights requests

Create a consistent process for recognizing rights requests through any channel, logging them and responding within the required timeframe. Your process should cover: 

  1. Recognizing the request 
  2. Logging the date received 
  3. Verifying identity where needed 
  4. Identifying the right involved 
  5. Locating relevant data 
  6. Coordinating with processors and internal teams 
  7. Applying relevant limits or exemptions 
  8. Responding securely 
  9. Recording the outcome

Step 10: Set up appropriate security measures

Use technical and organizational controls that match the risk of your processing, and test those controls regularly. 

Depending on your environment, these may include: 

  • Role-based access 
  • Multifactor authentication 
  • Encryption 
  • Security patching 
  • Endpoint protection 
  • Backups and restoration testing 
  • Access logging 
  • Secure disposal 
  • Employee security training

Step 11: Establish a data breach response plan

Create a clear process for identifying, containing, assessing and responding to personal data breaches. Maintain a breach register and test whether your team can make the required decisions within the 72-hour notification window. 

Define who: 

  • Receives internal reports 
  • Investigates and contains the incident 
  • Assesses the risk to affected people 
  • Decides whether regulator notification is required 
  • Communicates with affected people 
  • Records the decision

Step 12: Adopt a data protection policy and train staff

Maintain a data protection policy that explains how your organization handles personal data and connects employees to the procedures they need to follow. 

Your policy should direct employees to processes for rights requests, breach reporting, security and approved use of systems and third parties. 

Provide GDPR training during onboarding and refresh it regularly. Give additional training to teams with specific responsibilities, such as HR, Marketing, IT, Customer Service and Procurement. 

Step 13: Decide whether your organization needs a DPO and appoint one properly

Determine whether your organization needs a Data Protection Officer (DPO), and document the assessment even if one is not required. If you appoint a DPO, make sure the role has sufficient independence and resources. 

A DPO is mandatory where: 

  • Your organization is a public authority or body, except a court acting judicially 
  • Your core activities involve regular and systematic monitoring on a large scale 
  • Your core activities involve large-scale processing of special category or criminal offense data

GDPR compliance checklist

A GDPR compliance checklist can help you assess whether the foundations of your program are in place in broad steps. For each item, you should also be able to produce current evidence showing how the requirement is handled. 

This GDPR compliance checklist offers a broad summary of the areas you need to cover in your approach.  

  • Confirm whether EU GDPR applies to the organization 
  • Assess UK GDPR separately where relevant 
  • Map personal data and processing activities 
  • Classify controller, processor and joint controller roles by activity 
  • Establish and maintain a relevant ROPA 
  • Document the lawful basis for each controller processing purpose 
  • Identify additional conditions for special category data where required 
  • Maintain accurate privacy notices 
  • Record and manage consent where consent is used 
  • Apply data protection by design and default 
  • Screen processing for privacy risk 
  • Complete DPIAs where required 
  • Review third-party privacy and security controls 
  • Put required agreements with processors and joint controllers in place 
  • Identify international data transfers and document the safeguards used 
  • Confirm data minimization 
  • Set and enforce data retention periods 
  • Establish a process for data subject rights requests 
  • Implement appropriate technical and organizational security measures 
  • Establish and test a personal data breach response plan 
  • Maintain a breach register 
  • Maintain relevant data protection policies 
  • Provide GDPR training to relevant employees 
  • Determine whether a DPO is required  
  • Assign owners and review dates for ongoing controls

Download the GDPR checklist

How to maintain GDPR compliance over time

Your GDPR compliance program needs to change as your processing changes. You should review your documentation and controls when you introduce new systems, vendors, products or uses of personal data. 

Conduct regular data protection audits 

Review your key GDPR records at least annually and whenever your processing changes. Record gaps, assign an owner and track corrective actions through to completion. 

Check that: 

  • Your ROPA, privacy notices and consent records still reflect current processing 
  • Retention periods remain appropriate 
  • Vendor, subprocessor and transfer information is current 
  • DPIAs still reflect higher-risk processing 
  • Security controls and your DPO assessment remain appropriate  

Train employees on GDPR obligations 

Refresh GDPR training regularly and when your policies, systems or requirements change. Provide role-specific training where responsibilities differ, and keep completion records. 

Training should cover: 

  • Secure handling of personal data 
  • Recognizing and routing rights requests 
  • Reporting suspected personal data breaches 
  • When to involve your privacy or compliance team 
  • Using approved systems and vendors 

Monitor regulatory updates and operational changes 

Monitor relevant regulatory guidance and reassess your program when legal or operational changes affect how your organization processes personal data. 

Review your approach when your organization: 

  • Introduces a new processing purpose or technology 
  • Adds or changes a vendor or subprocessor 
  • Changes where personal data is stored or accessed 
  • Expands into a new market 
  • Experiences a breach or significant processing change

How NAVEX supports GDPR compliance

Keeping GDPR compliance current requires coordination across the people and processes that handle personal data. NAVEX One GRC Platform brings related compliance activity together, helping your organization manage policies, employee training, incidents and third-party oversight with clearer ownership and records.

Frequently asked questions

  • What does GDPR stand for?

    GDPR stands for General Data Protection Regulation. It is the EU regulation governing how organizations process and protect personal data. 

    It has applied since May 25, 2018.

  • Does GDPR apply to U.S. companies?

    Yes. GDPR can apply to U.S. companies that offer goods or services to people in the EU or monitor their behavior there. 

    A U.S. company does not need a European office for those tests to apply. Assess where the organization operates, which markets it targets and whether it monitors people in the EU.

  • What are the penalties for GDPR non-compliance?

    GDPR gives supervisory authorities several enforcement options, including warnings, reprimands, restrictions on processing and administrative fines. 

    For the most serious infringements, fines can reach €20 million or 4% of annual worldwide turnover of the previous financial year, whichever is higher. The response depends on factors including the nature, gravity and duration of the infringement.

  • What is the difference between EU GDPR and UK GDPR?

    EU GDPR and UK GDPR are separate legal frameworks. An organization operating across the EU and UK may need to comply with both. 

    Their core structures remain similar, but UK law has been amended by the Data (Use and Access) Act 2025. Organizations handling UK personal data should use current UK guidance and assess the two regimes separately. 

    See our UK GDPR vs. EU GDPR guide for more detail.

  • How long does it take to become GDPR compliant?

    There is no single implementation timeline that fits every organization. The work required depends on your processing, systems, vendors, international transfers and the controls already in place. 

    Start by mapping processing and identifying the highest-priority gaps. From there, assign owners and work through the remaining GDPR compliance steps based on risk and operational need.

  • What is a Data Protection Officer and do I need one?

    A Data Protection Officer (DPO) advises on data protection obligations, monitors compliance and supports areas such as DPIAs. Not every organization is required to appoint one. 

    A DPO is required for certain public authorities and where core activities involve large-scale regular and systemic monitoring of individuals or large-scale processing of protected data. 

    Document your assessment even if a DPO is not required and review it when processing changes.