Back to blog
Guides

Data privacy compliance: the complete guide

GDPR, UK GDPR, the Saudi PDPL and US state laws share a common architecture. Learn the structure once - lawful basis, rights, records, transfers, breach notification - and the specific regimes become variations rather than separate programmes.
GRC Copilot Team
Data privacy compliance: the complete guide

Privacy regimes look intimidating in the plural and repetitive in the singular. GDPR, UK GDPR, the Saudi PDPL and most modern laws share an architecture: a lawful reason to process, transparency about it, limits on what you keep, rights for individuals, obligations on transfers, and a clock when things go wrong. Learn the structure once and each specific law becomes a variation.

The architecture common to nearly every regime

  1. A lawful basis for each processing purpose — consent is only one, and often the weakest because it can be withdrawn.
  2. Transparency — telling people what you do, in language they can understand.
  3. Purpose limitation and minimisation — collect for a stated purpose, no more than needed.
  4. Storage limitation — delete when no longer necessary. Indefinite retention is a violation, not a neutral default.
  5. Security appropriate to the risk.
  6. Individual rights — access, correction, deletion, objection, portability, with deadlines.
  7. Accountability — being able to demonstrate compliance, which is what turns privacy into a documentation discipline.
  8. Transfer controls when data crosses borders.
  9. Breach notification within a defined window.

The operational obligations that actually consume time

  • Records of processing. The foundation — you cannot answer any other obligation without knowing what you hold, why, where and for how long.
  • Data subject requests. Usually one month, covering data anywhere including email, backups and messaging. Organisations without a search capability across their estate cannot meet this reliably, and the deadline does not care.
  • DPIAs for high-risk processing, completed before processing starts — a retrospective one is itself evidence of failure.
  • Processor contracts with required terms and equivalent flow-down to sub-processors.
  • Retention schedules that actually execute rather than sitting in a document.
  • Breach triage fast enough to decide within the notification window.
The single most common gap is the gap between the privacy notice and reality. Notices describe careful, minimal processing; systems do something broader. Auditors and regulators compare the two, and so do journalists.

Make privacy evidence auditable

GRC Copilot keeps processing records, DPIAs, retention decisions and the controls behind them in one place — so "demonstrate compliance" is a query, not a project.

Where the regimes genuinely differ

  • Transfer mechanics. The EU and UK maintain separate adequacy decisions and separate instruments — EU standard contractual clauses need the UK Addendum for a UK export. The PDPL sets its own conditions.
  • Representatives. Processing for people in a territory where you have no establishment generally requires a local representative — commonly missed.
  • Notification windows and recipients vary, and sector regulators often impose shorter ones than the privacy regulator.
  • Consent standards differ, particularly for marketing and cookies, where enforcement is far more active than most sites assume.
  • Scope of "personal data" and the treatment of pseudonymised data varies more than people expect.

A sensible build order

Map your data first — you cannot do anything else meaningfully without it. Then lawful bases and notices, then rights handling, then retention, then transfers, then breach readiness. Attempting rights handling before you know where data lives produces a process that misses half your systems.

Detailed guidance

AI & Automation

Checklists

Comparisons

Frameworks

Guides

Saudi & GCC

Templates

US & Americas

Checklists

Comparisons

EU & UK

Frameworks

Saudi & GCC

Templates

Frequently asked questions

Do we need a DPO?

Only in defined circumstances — public authorities, large-scale systematic monitoring, or large-scale special category processing. Many organisations appoint a privacy lead voluntarily, which is fine provided the role is not misrepresented as a statutory DPO.

Is consent the safest lawful basis?

Usually the opposite. Consent must be freely given, specific and withdrawable — and if it is withdrawn you must stop. Legitimate interests or contractual necessity are often more appropriate and more robust.

Does deleting from production satisfy an erasure request?

Generally yes, provided you explain that backups age out on a defined schedule and restores re-apply the deletion. Silence about backups is what causes problems.

Does ISO 27001 cover privacy?

It covers security, which is one privacy obligation among many. ISO 27701 extends it into privacy management, but neither replaces legal advice on lawful basis and rights.

How do we handle several regimes at once?

Build to the strictest requirement, document once, and maintain the regime-specific paperwork — transfer instruments and representatives — separately. The substantive controls rarely differ.

Key takeaways

  • Modern privacy laws share one architecture — learn it once.
  • Records of processing are the foundation; everything else depends on knowing what you hold.
  • Rights handling at scale needs a search capability, not a policy.
  • Transfer instruments and representatives are where regimes genuinely diverge.
#privacy #complete-guide #pillar #gdpr #pdpl #dpia #data-subject-rights