REGULATION (EU) 2016/679 · APPLIES SINCE 25 MAY 2018 · EU AND UK

A GDPR programme you can evidence.

If the people whose data you touch are in the EU or the UK, GDPR reaches you — wherever you are incorporated. This page is what it actually asks for, and what the proof looks like.


A sealed kraft document envelope on a dark surface, stamped CONFIDENTIAL, for authorized personnel only Illustrative materials
Personal data is somebody else’s, held on trust
Article 30 records Lawful basis DPIAs Data subject rights 72-hour breach clock
Applicability

Seven questions, then you’ll know

Most GDPR pages open by telling you it applies to everyone. It does not. Tick what is true, and we will name the articles each answer pulls in.

Tick everything that is true of your organisation

This is a scoping aid, not legal advice. It tells you which articles your situation engages — it cannot tell you whether you satisfy them, and under this Regulation several of the tests are genuinely arguable.

The regulation

What GDPR actually asks of you

Not a consent banner and a policy page. A demonstrable programme — and the burden of demonstrating it is on you.

It follows the person, not the company

Regulation (EU) 2016/679 has applied since 25 May 2018. It governs the processing of personal data — anything relating to an identified or identifiable person — and Article 3(2) reaches organisations outside the EU where they offer goods or services to, or monitor the behaviour of, people in the Union. The UK runs a near-identical regime with its own fine caps and its own supervisory authority.

Everything starts at Article 5

Six principles — lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and security — plus accountability, which is the one that turns the other six into documents. Every purpose needs a lawful basis under Article 6, and special category data needs a further condition under Article 9.

Then the operational duties

A record of processing under Article 30. A DPIA where processing is likely to be high risk. 72 hours to notify a personal data breach. A lawful transfer mechanism for anything leaving the EEA. And eight rights your processes have to be able to honour on request.

The two that catch AI teams

Purpose limitation and Article 22. Data collected to deliver a service cannot simply be reused to train a model. And a solely automated decision with legal or similarly significant effects is prohibited unless one of three narrow gateways applies.

Territorial reach Article 3(2)

Where the person is, not where you are. Establishment in the EU is not required for the Regulation to apply.

Maximum exposure €20M or 4%

Of global annual turnover, whichever is higher — the Article 83(5) tier, for principles, rights and transfers.

Who needs GDPR compliance

  • Controllers

    You decide why and how personal data is processed. Almost every duty on this page lands on you first, whoever actually runs the systems.

  • Processors

    You process on a controller’s instructions. Article 28 binds you by contract, and Articles 30, 32, 33 and Chapter V bind you directly — not through your customer.

  • Employers and HR platforms

    Employee data is personal data, consent is rarely a valid basis in an employment relationship, and monitoring almost always needs a DPIA.

  • Anyone running automated decisions

    Solely automated decisions with legal or similarly significant effects engage Article 22: a lawful gateway, meaningful information about the logic, and a route to human intervention.

  • SaaS, cloud and AI vendors

    Your customers cannot answer their own Article 30, Article 28 or transfer questions without your documentation. Increasingly it is procurement, not a regulator, that asks first.

  • Organisations outside the EU and UK

    Article 3(2) reaches you if you offer goods or services to, or monitor the behaviour of, people in the EU. Your place of establishment is not the test.

Requirement & coverage

How iDharma supports GDPR compliance

Twelve obligations with their articles, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the duty beside it.

Records of processing Article 30
A completed ROPA for each role you hold, with purposes, categories, recipients, transfers and retention filled in rather than left as headings.
Lawful basis register Articles 6 and 9
A basis recorded per purpose, the Article 9 condition where special category data is involved, and a legitimate interests assessment where you rely on one.
Privacy notices Articles 13 and 14
Notices per audience, checked line by line against the mandatory content list — including the Article 14 case where you did not collect the data yourself.
Data subject rights procedure Articles 12 and 15–22
One intake route, an identity-verification step, the one-month clock with its extension criteria, and a decision record per request.
Impact assessments Article 35
A screening test that says when a DPIA is needed, the methodology, and completed DPIAs for the processing that triggers it.
Breach response Articles 33 and 34
A detection-to-decision runbook, the 72-hour notification pack, the internal breach register, and the high-risk test for telling individuals.
Processor contracts Article 28
A clause-by-clause review of your processor terms, a sub-processor position, and the gap list against the eight mandatory contract terms.
International transfers Chapter V
A transfer register, the mechanism per route — adequacy, SCCs, BCRs — and a transfer impact assessment where the mechanism needs one.
Retention schedule Article 5(1)(e)
A period per data category with the justification beside it, and the deletion route named rather than assumed to exist.
Security measures Article 32
The measures you actually run, mapped to the risk they address, so “appropriate” is an argument on paper rather than an adjective.
Accountability and roles Articles 5(2), 24 and 37–39
The DPO test answered either way in writing, a RACI for the duties, and the evidence pack that demonstrates compliance rather than asserting it.
Automated decision safeguards Article 22
A register of solely automated decisions, the lawful gateway for each, the logic explanation, and a human-intervention route that a person can actually reach.

Additional compliance capabilities

The six workstreams the engagement is organised around. Each one is a change in how the organisation operates, not a document that lands and then ages.

Processing inventory and records

Data mapped from the system inwards rather than the questionnaire outwards, so the Article 30 record matches what your estate actually does.

Data protection impact assessments

A screening test, a methodology and completed DPIAs — including the residual-risk call and, where it stands, the consultation question.

Data subject rights workflows

One intake route, identity verification, a search that reaches the backups and the ticketing system, and a decision record per request.

Breach detection and notification

The 72-hour clock starts at awareness, not at confirmation. We set the trigger, the decision tree and the notification pack before you need them.

Consent and lawful basis tracking

Where consent is the basis, it has to be recorded, granular and as easy to withdraw as to give. Where it is not the basis, we say what is.

Processor and transfer governance

Article 28 terms, sub-processor chains and the Chapter V mechanism per route — with the transfer impact assessment where the mechanism needs one.

Article 5, and one from Article 25

The eight GDPR principles

Six in Article 5(1). Accountability in Article 5(2). Data protection by design is Article 25 — an obligation, not a principle. We keep it here because every working programme treats it as one, and we label it honestly.

8 Principles Article 5 and Article 25
8 Data subject rights Articles 13–22
72h To notify a breach From awareness, not from confirmation
1 month To answer a request Extendable by two for complexity

The six

Article 5(1) — the principles themselves
Article 5(1)(a)

Lawfulness, fairness and transparency

A lawful basis for every purpose, processing that a person would not find unfair or surprising, and information that is actually reachable.

  • A basis recorded per purpose, not per system
  • Special category data has an Article 9 condition too
  • Notices written to be read, not to be defensible
Article 5(1)(b)

Purpose limitation

Collected for a specified purpose and not reused for something incompatible with it. This is the principle secondary AI training most often breaks.

  • Purposes specified before collection
  • A compatibility test for any new use
  • Model training named as a purpose, or not done
Article 5(1)(c)

Data minimisation

Adequate, relevant and limited to what is necessary. Necessary for the purpose — not for a purpose you might find later.

  • Field-level justification for what you collect
  • Pseudonymisation where identity is not needed
  • Sample rather than copy, where a sample answers
Article 5(1)(d)

Accuracy

Kept accurate and, where necessary, up to date — with inaccurate data erased or rectified without delay.

  • A correction route that reaches downstream copies
  • Inferences and scores treated as data too
  • Source-of-truth named per data category
Article 5(1)(e)

Storage limitation

Kept in identifiable form no longer than necessary. A retention schedule nobody executes is not storage limitation.

  • A period per category with its justification
  • Deletion that reaches backups and logs
  • Archive rules where a longer period is lawful
Article 5(1)(f)

Integrity and confidentiality

Appropriate security against unauthorised processing, loss and damage — argued against the risk, under Article 32.

  • Measures mapped to the risks they address
  • Access on need, reviewed rather than granted once
  • Encryption and pseudonymisation where they fit

The one that makes it provable

Article 5(2) — accountability
Article 5(2)

Accountability

You must be able to demonstrate compliance, not merely achieve it. This is the principle that turns everything above into documents.

  • Records, policies and assessments kept current
  • Decisions written down with their reasoning
  • A named owner per obligation

The one that decides the cost

Article 25 — an obligation, not a principle
Article 25

Data protection by design and by default

Not an Article 5 principle — an obligation in its own right, and the one that decides whether the other seven are cheap or expensive.

  • A privacy gate in the delivery lifecycle
  • Defaults that process the least data
  • DPIA triggered by design review, not by launch

The eighth is not an Article 5 principle. Data protection by design and by default is Article 25 — an obligation in its own right. It is here because every working programme treats it as a principle, and because it is the one that decides whether the other seven are cheap or expensive. Citing it as Article 5 would be convenient and wrong, so the card carries its real article.

Chapter III

The eight data subject rights

What a person can ask you for, and what your processes have to be able to do about it inside a month. Most of these fail on search coverage, not on willingness.

Articles 13–14 “What do you have on me?”

Right to be informed

What you do with the data, told at collection or within a month if you got it elsewhere.

  • Mandatory content list, in full
  • Layered notices where the list is long
  • Article 14 notice for third-party data
Article 15 “Send me a copy.”

Right of access

A copy of the personal data, plus the supplementary information about how and why it is processed.

  • One month, extendable by two for complexity
  • Search that reaches email, tickets and backups
  • Third-party redaction with the reasoning kept
Article 16 “That’s wrong — fix it.”

Right to rectification

Inaccurate data corrected, incomplete data completed — and recipients told, where feasible.

  • Correction propagated downstream
  • A record of what was changed and when
  • Notification to recipients under Article 19
Article 17 “Delete me.”

Right to erasure

Deletion where one of the six grounds applies — not an unconditional right, and the exemptions are real.

  • Grounds and exemptions assessed in writing
  • Deletion that reaches every copy
  • Public-domain notification where it applies
Article 18 “Stop using it while we sort this out.”

Right to restriction

Processing paused while accuracy or a legitimate-interests objection is being worked out.

  • A technical way to actually pause processing
  • A flag that survives a system migration
  • Notice before restriction is lifted
Article 20 “Give it to me in a format I can move.”

Right to portability

Data the person provided, on consent or contract and processed by automated means, in a structured machine-readable format.

  • A defined export format per system
  • Scope limited to provided data, not inferred
  • Direct transmission where technically feasible
Article 21 “Stop.”

Right to object

Absolute for direct marketing. For legitimate interests, you must stop unless you can show compelling grounds.

  • Marketing objection honoured immediately
  • Compelling-grounds argument written, not assumed
  • Objection route in the notice itself
Article 22 “A person needs to look at this.”

Rights on automated decisions

Not to be subject to a solely automated decision with legal or similarly significant effects, save on three narrow gateways.

  • A register of solely automated decisions
  • Meaningful information about the logic
  • A human who can actually change the outcome

Withdrawal of consent is not on this list, and that is deliberate. Article 7(3) makes consent as easy to withdraw as to give, but it is a condition of consent rather than one of the Chapter III rights — so it sits inside the lawfulness principle above. If you rely on consent, withdrawal still has to work, and it still has to stop the processing.

Implementation

A 26-week implementation roadmap

A practical path to GDPR compliance with clear milestones. Phase one is the one people skip, and it is the one everything else is built on.

Weeks 1–6

Foundation and gap analysis

Find out what you actually process

  • Data mapping from the systems inwards
  • Article 30 records drafted for each role
  • Lawful basis recorded per purpose
  • Gap assessment against every obligation
  • Roles assigned, DPO question answered
Weeks 7–13

Documentation and policies

Write the things you will be asked for

  • Privacy notices per audience
  • Retention schedule with justifications
  • DSAR procedure and response templates
  • DPIA methodology and screening test
  • Breach runbook and notification pack
Weeks 14–20

Technical and organisational measures

Make the paper true

  • Access control and logging to Article 32
  • Encryption and pseudonymisation where they fit
  • Deletion routes that reach every copy
  • Privacy gate in the delivery lifecycle
  • Processor terms and transfer mechanisms
Weeks 21–26

Assurance and monitoring

Prove it, then keep proving it

  • Role-based training with completion evidence
  • DSAR and breach rehearsals against the clock
  • Internal audit against the gap list
  • Reporting line to the board
  • A review cycle with owners and dates

Twenty-six weeks is elapsed time for a mid-sized estate, not effort. The phases overlap in practice — documentation starts before mapping finishes, and monitoring starts before the technical work is done. Read as four consecutive sprints the ranges add to more than the total, which is the one way to misread this plate.

Enforcement

GDPR penalties are significant and enforced

Two tiers, both statutory, each one “whichever is higher”. They have not moved since 2018 — and they are not the interesting number. The interesting number is what a supervisory authority asks for first, which is the Article 30 record.

Lower tier · Article 83(4)
€10M
or 2% of global annual turnover

Obligations of controllers and processors

  • Records of processing — Article 30
  • Security of processing — Article 32
  • Breach notification — Articles 33 and 34
  • Impact assessments — Articles 35 and 36
  • Data protection officer — Articles 37–39
Higher tier · Article 83(5)
€20M
or 4% of global annual turnover

Principles, rights and transfers

  • The Article 5 principles
  • Lawful basis and consent — Articles 6, 7 and 9
  • The data subject rights — Articles 12–22
  • International transfers — Chapter V
  • Non-compliance with a supervisory authority order

Deliberately no league table of past fines here: the total moves every month and the register is public. For current enforcement, see the European Data Protection Board. UK GDPR runs the same two tiers at £8.7 million or 2 per cent and £17.5 million or 4 per cent.

Policy templates

Complete GDPR policy repository

31 ready-to-use templates aligned to the Regulation and to ISO/IEC 27001, tailored to your estate rather than handed over as a generic pack.

Core data protection

  • Data Protection Policy
  • Record of Processing Activities
  • Lawful Basis Register
  • Privacy Notice Set
  • Retention & Deletion Schedule
  • Data Subject Rights Procedure

+ 5 more in this group

Security & breach

  • Information Security Policy
  • Personal Data Breach Runbook
  • Breach Register & Notification Pack
  • Access Control Standard
  • Encryption & Pseudonymisation
  • Logging & Monitoring Standard

+ 4 more in this group

Processors & transfers

  • Article 28 Processor Agreement
  • Sub-processor Governance
  • Vendor Due Diligence Pack
  • Transfer Register
  • Transfer Impact Assessment
  • DPIA Methodology & Template

+ 4 more in this group

Questions

Frequently asked questions

Scope, deadlines, transfers and the questions AI teams keep arriving with. Filter to the one you came for.

1 Scope and roles
Does GDPR apply to us if we are outside the EU?

If you offer goods or services to people in the EU, or monitor their behaviour, Article 3(2) reaches you regardless of where you are established. Payment in money is not required, and an English-language site alone is not enough — the test is whether you envisage offering to people in the Union.

What is the difference between a controller and a processor?

A controller decides the purposes and means of processing; a processor acts on the controller’s documented instructions. The label follows the facts, not the contract: a vendor that decides what to do with the data for its own ends is a controller for that processing, whatever the agreement calls it.

Do we need a Data Protection Officer?

Article 37 requires one if you are a public authority, if your core activities require regular and systematic monitoring of people on a large scale, or if your core activities involve large-scale processing of special category or criminal-offence data. If none applies, you may still appoint one — but record the decision either way, because the assessment is part of accountability.

How does UK GDPR differ?

The obligations are substantially the same. The differences that matter operationally are the fine caps — £8.7 million or 2 per cent, and £17.5 million or 4 per cent — the supervisory authority, and the fact that a transfer between the UK and the EU is its own question with its own mechanism.

2 Obligations and deadlines
How long do we have to answer a data subject request?

One month from receipt. That can be extended by up to two further months where the request is complex or numerous, but you must tell the person within the first month, with the reason. The clock does not pause while you decide whether the request is valid.

When does a DPIA become mandatory?

Under Article 35, whenever processing is likely to result in a high risk to people’s rights and freedoms — in particular systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category processing, or large-scale systematic monitoring of a publicly accessible area. Your supervisory authority also publishes its own list.

What does the 72-hour breach clock actually run from?

From when you become aware of the breach, not from when the investigation finishes. If you cannot supply everything in time you may notify in phases, but the initial notification still has to go in. Whether individuals must be told is a separate, higher test: a high risk to their rights and freedoms.

Do we need to keep records of processing?

Article 30 exempts organisations under 250 employees — but not where the processing is other than occasional, is likely to risk rights and freedoms, or involves special category or criminal-offence data. In practice that exemption almost never survives contact with a real estate, and the record is the first thing a supervisory authority asks for.

3 Data, transfers and AI
Can we use personal data to train a model?

Only with a lawful basis for that purpose and a compatibility assessment if the data was collected for something else. Purpose limitation is the principle secondary training most often breaks, and “the data was already in our warehouse” is not a basis.

What does Article 22 require of an automated decision?

If a decision is solely automated and has legal or similarly significant effects, it is prohibited unless it is necessary for a contract, authorised by law, or based on explicit consent. Where a gateway applies you still owe meaningful information about the logic, and a genuine route to human intervention — a reviewer who can only confirm the output does not satisfy it.

What is a Standard Contractual Clause and do we still need a TIA?

SCCs are the European Commission’s approved contract terms for transferring personal data outside the EEA where no adequacy decision covers the destination. Following Schrems II you also need a transfer impact assessment of the destination’s law and practice, plus supplementary measures where the assessment finds the clauses alone are not enough.

Is consent the safest lawful basis?

Usually the opposite. Consent must be freely given, specific, informed, unambiguous and as easy to withdraw as to give — and withdrawal stops the processing. Where there is an imbalance of power, as with employees, it is rarely valid at all. Contract or legitimate interests is often both more honest and more durable.

How does this connect to the EU AI Act?

They stack rather than substitute. Where an AI system processes personal data you owe both, and the overlap is large: the DPIA and the AI Act’s assessment ask related questions, and Article 22 and the AI Act’s human-oversight duties land on the same control. One review scoped across both is cheaper than two that disagree.

What does an iDharma GDPR review cost and how long does it take?

It is scoped before you are charged. The variables are the number of systems in the estate, how much of the Article 30 record already exists, and whether transfers and automated decisions are in play; we tell you the shape of all three after a short scoping call.

Ready when you are

Ready to make GDPR provable?

Start with a guided assessment: the processing inventory, the lawful basis register, the gap list against every article on this page, and a sequenced plan — scoped before you are charged.

This page is guidance on how we scope a GDPR readiness review, not legal advice. Where a question is genuinely arguable — and under this Regulation many are — we say so in writing rather than pick the convenient answer.