EU Regulation 2016/679

GDPR Compliance

The General Data Protection Regulation is the world's strongest data privacy law. Ensure your business is compliant and avoid penalties up to €20 million.

€20M
Maximum fine
or 4% global revenue
72hrs
Breach notification
Mandatory deadline
447M
People protected
EU residents
2018
Effective since
May 25th

Who Must Comply with GDPR?

GDPR applies to any organization that processes personal data of EU residents, regardless of where the organization is located.

EU-Based Companies

Any company established in the EU that processes personal data, regardless of where the processing takes place.

Non-EU Companies

Companies outside the EU that offer goods/services to EU residents or monitor their behavior.

Data Processors

Third-party service providers that process personal data on behalf of a controller (e.g., cloud providers).

Key GDPR Requirements

Understanding the core principles and obligations under GDPR

Lawful Basis for Processing

You must have a valid legal basis (consent, contract, legal obligation, legitimate interest, vital interest, or public task) to process personal data.

Purpose Limitation

Personal data must be collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes.

Data Minimization

Collect only data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

Storage Limitation

Personal data must not be kept longer than necessary for the purposes for which it is processed.

Security & Integrity

Implement appropriate technical and organizational measures to ensure security, including protection against unauthorized processing and accidental loss.

Data Subject Rights

Enable rights including access, rectification, erasure ("right to be forgotten"), data portability, and the right to object.

Data Subject Rights Under GDPR

GDPR grants individuals powerful rights over their personal data. Organizations must be able to fulfill these requests within 30 days.

Right to Access

Obtain confirmation and a copy of their data

Right to Rectification

Correct inaccurate personal data

Right to Erasure

"Right to be forgotten" in certain cases

Right to Portability

Receive data in a machine-readable format

Right to Object

Object to processing for certain purposes

Right to Restrict

Limit how data is processed

Automated Decisions

Not be subject to solely automated decisions

Right to Withdraw

Withdraw consent at any time

Non-Compliance Risks

GDPR Penalties Are Severe

EU regulators have issued billions in fines. Don't let your company be next.

Standard Violations

Lower tier offenses

€10M

or 2% of annual global turnover, whichever is higher

  • Failure to implement data protection by design
  • No data processing records maintained
  • Failure to notify breach within 72 hours

Serious Violations

Higher tier offenses

€20M

or 4% of annual global turnover, whichever is higher

  • Processing without valid legal basis
  • Violating data subject rights
  • Illegal cross-border data transfers

Notable GDPR Fines

€1.2B
Meta
2023
Illegal data transfers to US
€746M
Amazon
2021
Behavioral advertising violations
€225M
WhatsApp
2021
Transparency violations
€90M
Google
2022
Cookie consent violations

How Dependra Helps with GDPR Compliance

Our platform automatically scans your digital infrastructure to identify compliance gaps and non-EU data processors that could put you at risk.

  • Identify all third-party data processors in your stack
  • Flag non-EU services that require additional safeguards
  • Assess data transfer risks post-Schrems II
  • Discover GDPR-native EU alternatives
  • Generate compliance reports for audits
  • Monitor for new compliance issues continuously
Start Free GDPR Audit

Official Resources

GDPR Quick Facts

Full Name
General Data Protection Regulation
Regulation Number
EU 2016/679
Adopted
April 14, 2016
Effective Date
May 25, 2018
Total Articles
99
Scope
EU + EEA + Global (extraterritorial)

Ready to Ensure GDPR Compliance?

Start scanning your digital infrastructure in minutes. Identify non-EU data processors and get actionable recommendations to achieve compliance.