About this Framework
The General Data Protection Regulation (GDPR), effective 25 May 2018, applies to any organisation processing personal data of EU residents regardless of location. GDPR requires a lawful basis for processing, data subject rights, privacy by design and default, 72-hour breach notification and Data Protection Officers where mandated. Fines reach up to €20 million or 4% of global annual turnover, whichever is higher.
Key Control Domains
Lawful Basis for Processing
Data Subject Rights
Privacy by Design & Default
Data Breach Notification (72h)
Data Protection Impact Assessments
Data Transfer Restrictions
Controller & Processor Obligations
DPO Requirements
Records of Processing Activities
Who Needs This?
- Any global organisation processing EU resident data
- E-commerce platforms serving European customers
- SaaS providers with EU users
- Healthcare organisations and clinical research
- Financial services and insurance companies
Compliance Benefits
- Legal compliance and avoidance of multi-million euro fines
- Enhanced data governance across the organisation
- Customer trust and competitive advantage in EU markets
- Foundation for broader global privacy compliance
Official Reference
GDPR Official Guidance
https://gdpr.eu/what-is-gdpr/
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/general-data-protection-regulation-gdpr