Compliance · EU
EU Regulation 2016/679Extraterritorial scope

GDPR

Plain-English definition

GDPR applies to processing in the context of an EU establishment and, in specified circumstances, to organizations outside the EU, including offering goods or services to people in the EU or monitoring their behavior there. It covers lawful processing, individual rights, security and conditional breach-notification duties.

A business without an EU office may be in scope. Assess Article 3 conditions rather than assuming that possession of an EU individual’s data is sufficient.

Who needs it

Organizations meeting Article 3 conditions, based on establishment, offering goods or services to people in the EU, or monitoring their behavior there.

Key requirements

A documented lawful basis for each processing activity, a Record of Processing Activities, honored data-subject rights (access, erasure, portability, objection), 72-hour breach notification, and Data Protection Impact Assessments for high-risk processing.

Cyber/privacy implications

Security controls must be mapped to specific categories of personal data and specific processing purposes, so a breach investigation has to determine not just what was accessed, but under what lawful basis it was being processed in the first place.

Assessment methodology

Data-flow mapping and Record of Processing Activities build-out, lawful-basis review per processing activity, breach-response readiness testing, and a gap analysis against Articles 5, 25, 32, and 33 specifically.

Implementation phases

01
Map

Build the Record of Processing Activities and confirm lawful basis per activity.

02
Remediate

Close technical and organizational control gaps, formalize data-subject request handling.

03
Sustain

Ongoing DPIA process for new processing activities and breach-response readiness.

Evidence & documentation requirements

Record of Processing Activities, documented lawful-basis assessments, Data Protection Impact Assessments for high-risk processing, data-processing agreements with vendors, and breach-response logs.

Common mistakes

Relying on consent as the default lawful basis when a more appropriate basis exists and would be more durable; treating a Data Processing Agreement with a vendor as sufficient without verifying the vendor's actual security controls.

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Do we need a DPO under GDPR?
Mandatory for public authorities and organizations whose core activities involve large-scale, regular, systematic monitoring, or large-scale processing of special-category data; we assess applicability during scoping.
How does this differ from Amendment 13?
The frameworks share some principles but have separate scope, obligations, regulators and enforcement mechanisms. Compliance with one does not automatically establish compliance with the other.
What's the actual breach notification deadline?
Where notification is required, notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness. An exception applies where the breach is unlikely to create a risk to individuals’ rights and freedoms. High-risk breaches can separately require notification to affected individuals.

Request a Gap Assessment

See exactly where your data processing stands against GDPR before a regulator asks.

Request a Gap Assessment →

Official source

GDPR, Articles 3, 33 and 34