Compliance · EU
EU Regulation 2016/679Extraterritorial scope

GDPR

Plain-English definition

The General Data Protection Regulation applies to any organization, regardless of where it's based, that processes personal data belonging to individuals in the EU. It requires a documented lawful basis for every processing activity, defined data-subject rights, and breach notification to the relevant supervisory authority within 72 hours of becoming aware of a breach.

Extraterritorial scope means a company with no EU office can still be squarely in scope, the same principle underlying Israel's Amendment 13.

Who needs it

Any organization, anywhere in the world, that processes personal data of individuals located in the EU, whether that's employees, customers, or website visitors, regardless of the organization's own location.

Key requirements

A documented lawful basis for each processing activity, a Record of Processing Activities, honored data-subject rights (access, erasure, portability, objection), 72-hour breach notification, and Data Protection Impact Assessments for high-risk processing.

Cyber/privacy implications

Security controls must be mapped to specific categories of personal data and specific processing purposes, so a breach investigation has to determine not just what was accessed, but under what lawful basis it was being processed in the first place.

Assessment methodology

Data-flow mapping and Record of Processing Activities build-out, lawful-basis review per processing activity, breach-response readiness testing, and a gap analysis against Articles 5, 25, 32, and 33 specifically.

Implementation phases

01
Map

Build the Record of Processing Activities and confirm lawful basis per activity.

02
Remediate

Close technical and organizational control gaps, formalize data-subject request handling.

03
Sustain

Ongoing DPIA process for new processing activities and breach-response readiness.

Evidence & documentation requirements

Record of Processing Activities, documented lawful-basis assessments, Data Protection Impact Assessments for high-risk processing, data-processing agreements with vendors, and breach-response logs.

Common mistakes

Relying on consent as the default lawful basis when a more appropriate basis exists and would be more durable; treating a Data Processing Agreement with a vendor as sufficient without verifying the vendor's actual security controls.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Do we need a DPO under GDPR?
Mandatory for public authorities and organizations whose core activities involve large-scale, regular, systematic monitoring, or large-scale processing of special-category data; we assess applicability during scoping.
How does this differ from Amendment 13?
Overlapping principles and both use extraterritorial scope, but distinct notification timelines, regulators, and enforcement mechanisms; satisfying one doesn't automatically satisfy the other.
What's the actual breach notification deadline?
72 hours from becoming aware of the breach to notifying the relevant supervisory authority, with individual notification required separately if the breach poses a high risk to those individuals.

Request a Gap Assessment

See exactly where your data processing stands against GDPR before a regulator asks.

Request a Gap Assessment →