Any organization, anywhere in the world, that processes personal data of individuals located in the EU, whether that's employees, customers, or website visitors, regardless of the organization's own location.
A documented lawful basis for each processing activity, a Record of Processing Activities, honored data-subject rights (access, erasure, portability, objection), 72-hour breach notification, and Data Protection Impact Assessments for high-risk processing.
Security controls must be mapped to specific categories of personal data and specific processing purposes, so a breach investigation has to determine not just what was accessed, but under what lawful basis it was being processed in the first place.
Data-flow mapping and Record of Processing Activities build-out, lawful-basis review per processing activity, breach-response readiness testing, and a gap analysis against Articles 5, 25, 32, and 33 specifically.
Build the Record of Processing Activities and confirm lawful basis per activity.
Close technical and organizational control gaps, formalize data-subject request handling.
Ongoing DPIA process for new processing activities and breach-response readiness.
Record of Processing Activities, documented lawful-basis assessments, Data Protection Impact Assessments for high-risk processing, data-processing agreements with vendors, and breach-response logs.
Relying on consent as the default lawful basis when a more appropriate basis exists and would be more durable; treating a Data Processing Agreement with a vendor as sufficient without verifying the vendor's actual security controls.
See exactly where your data processing stands against GDPR before a regulator asks.
Request a Gap Assessment →