GDPR compliance means handling the personal data of people in the European Union in line with the General Data Protection Regulation, which has applied since 25 May 2018. It is not a certificate you earn once. GDPR compliance is an ongoing state you have to be able to prove on any given day, using records rather than good intentions.
The regulation applies to far more organisations than many expect. If you offer goods or services to people in the EU, or monitor their behaviour, GDPR compliance applies even when your company has no EU office. A software firm in Bangalore with EU users, a Dubai consultancy with EU clients, and a US retailer shipping to Germany all fall inside its reach.
The good news: most of what GDPR asks for is orderly record keeping and clear decisions. If your information security management system already tracks assets, risks and incidents, you are closer to GDPR compliance than you think.
Who GDPR Compliance Applies To
Two roles carry duties under the regulation, and each organisation must know which one it holds for every activity.
A controller decides why and how personal data is processed. A processor handles that data on the controller's instructions. A payroll provider is usually a processor. The employer is the controller. Many companies are both, depending on the data set.
Controllers carry the heavier load: lawful basis, transparency notices, rights handling and breach reporting. Processors still have direct duties, including security measures, keeping their own processing records, using approved sub-processors and telling the controller about breaches without delay.
Organisations outside the EU that fall under the regulation usually need a representative inside the EU as a point of contact for regulators and individuals.
The Seven Principles of GDPR Compliance
Article 5 sets the foundation. Every other requirement traces back to one of these.

- Lawfulness, fairness and transparency
- Purpose limitation - collect for a stated purpose, do not drift
- Data minimisation - only what the purpose needs
- Accuracy - keep records correct and current
- Storage limitation - keep it no longer than needed
- Integrity and confidentiality - protect it properly
- Accountability - be able to demonstrate all of the above
The seventh principle is the one that trips people up. Doing the right thing is not enough. You must show evidence of it, which is where day-to-day data privacy management habits matter more than a well-written policy.
Core GDPR Compliance Requirements
Lawful Basis for Processing
Every activity needs one of six grounds: consent, contract, legal obligation, vital interests, public task or legitimate interests. Choose it before processing starts and write it down.
Consent must be freely given, specific and as easy to withdraw as it was to give. Pre-ticked boxes and bundled permissions do not qualify.
Records of Processing Activities
Article 30 requires a register covering purposes, data categories, recipients, transfers and retention periods. Regulators often ask for it first because it reveals how well the rest of the programme works.
Small organisations under 250 staff get a limited exemption, but it rarely applies once processing is regular or involves sensitive data.
Individual Rights Requests
People can access, correct, erase, restrict, port or object to the use of their data. The response deadline is one month from receipt, extendable by two months for genuinely complex cases.
Assign one owner and log the arrival date. Requests that sit unnoticed in a shared inbox are the most common reason organisations miss the deadline.
Breach Notification
A reportable personal data breach must reach the supervisory authority within 72 hours of the organisation becoming aware of it. If the risk to individuals is high, they must be told as well, without undue delay.
Your information security incident management process should flag personal data involvement at the moment an incident is logged, not during the post-mortem. Three days disappear quickly when the assessment starts late.
International Data Transfers
Moving personal data outside the EU needs a legal route: an adequacy decision, Standard Contractual Clauses with a transfer risk assessment, or binding corporate rules.
Check where your cloud services actually store and support data. Support teams accessing EU records from another country counts as a transfer.
Vendors and Processors
Every processor needs a written agreement covering purpose, duration, security and sub-processor rules. Regulators treat missing contracts as a clear failure.
Add a privacy review to procurement so that third party and vendor security checks happen before a tool goes live, not two years later.
Want to see this working in a real system? Try Effivity for Free and build your processing register in an afternoon.
What Non-Compliance Costs
Fines run to two tiers: up to 10 million euros or 2 percent of global annual turnover for administrative failures, and up to 20 million euros or 4 percent for breaches of core principles or rights, whichever is higher.
Money is only part of it. Regulators can order processing to stop, which can halt a product line overnight. Enforcement decisions are published, and enterprise buyers now read them. Weak GDPR compliance also shows up as failed vendor assessments and stalled deals, a cost that never appears in any fine total.
A Practical GDPR Compliance Roadmap
Most successful programmes follow the same order.

- Run a gap analysis against the regulation to see where you stand.
- Map personal data across systems, teams, vendors and exports.
- Record a lawful basis for every processing activity.
- Update privacy notices so they match what actually happens.
- Build request and breach workflows with named owners and clocks.
- Fix processor contracts and transfer mechanisms.
- Set retention periods, then run and evidence the deletions.
Assess whether you need a Data Protection Officer. It is mandatory for public authorities, large-scale systematic monitoring, and large-scale processing of special category data. Where it is optional, a named privacy owner still helps.
Then keep it moving with short, role-specific information security training for the teams that touch personal data. Awareness closes more gaps than documentation does.
How ISO 27001 Supports GDPR Compliance
The regulation names no standard, but Article 32 asks for security appropriate to the risk, and a certified management system is a practical way to evidence that. ISO 27001 supplies the risk assessment method, control set, audit cycle and management review that GDPR expects but does not spell out.
The overlap is significant: asset registers feed the data map, access controls support confidentiality, incident procedures support breach reporting, and supplier controls support processor management. Treating both as one programme rather than two saves duplicated effort and strengthens your wider cyber security compliance position.
Gaps remain, though. ISO 27001 does not cover lawful basis, consent, transparency notices or individual rights, so those need their own controls.
Managing GDPR Compliance in One System
Spreadsheets can hold a register, but they cannot chase a retention date, escalate a rights request, or prove who approved a transfer two years ago.
Effivity's information security management software brings the pieces together within an ISO 27001 structure: an information asset register, risk management, incident handling, supplier management, document control with version history, and a full audit trail behind every change. All 93 Annex A controls are available out of the box.
Get a Free Personalized Demo to see how your records, requests and evidence sit in one place.
Frequently Asked Questions
GDPR compliance means processing the personal data of people in the EU according to the regulation's principles, rights and security duties. It also means holding evidence that proves it.
Yes. It applies to any organisation offering goods or services to people in the EU or monitoring their behaviour, regardless of where the company is based.
Notify the supervisory authority within 72 hours of becoming aware of a reportable breach. Tell affected individuals too if the risk to them is high.
Up to 10 million euros or 2 percent of global turnover for administrative failures, and up to 20 million euros or 4 percent for serious breaches, whichever is higher.
No. A DPO is mandatory for public authorities, large-scale systematic monitoring, or large-scale special category data. Others may appoint one voluntarily.
No, but it covers much of the security side and provides useful evidence. Lawful basis, consent, notices and rights handling still need separate controls.