What is GDPR?
GDPR sets the rules for processing personal data: any information that identifies a person directly or indirectly, such as a name, an email address, an IP address or a device identifier. It has applied across the EU and the EEA since 25 May 2018.
The UK has its own version, the UK GDPR, which closely follows it.
Who GDPR applies to
GDPR applies to organizations established in the EU, and also to organizations outside it that offer goods or services to people in the EU or monitor their behaviour there (Article 3). A SaaS company in India or the US with EU customers or users is usually in scope.
- Controller: decides why and how personal data is processed.
- Processor: processes personal data on a controller's behalf, for example a SaaS vendor hosting its customers' data. Processors have direct obligations of their own.
The core principles (Article 5)
- Lawfulness, fairness and transparency.
- Purpose limitation: collect data for specified purposes, and do not reuse it for incompatible ones.
- Data minimisation: only what you need.
- Accuracy: keep it correct and up to date.
- Storage limitation: keep it no longer than necessary.
- Integrity and confidentiality: protect it with appropriate security.
- Accountability: be able to demonstrate all of the above.
What GDPR requires in practice
- A lawful basis for each processing activity (Article 6): consent, contract, legal obligation, vital interests, public task or legitimate interests.
- Clear privacy notices (Articles 12 to 14).
- A way to handle data subject rights: access, rectification, erasure, restriction, portability and objection (Articles 15 to 22).
- Data processing agreements with your processors (Article 28).
- Records of processing activities (Article 30).
- Appropriate security measures (Article 32).
- Notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people (Article 33).
- Data protection impact assessments for high-risk processing (Article 35).
- A Data Protection Officer where the regulation requires one (Article 37).
- Safeguards for transfers of personal data outside the EU and EEA (Chapter V).
GDPR fines
Article 83 sets two tiers of administrative fines: up to €10 million or 2% of total worldwide annual turnover, and up to €20 million or 4% for breaches of the core principles, the lawful basis rules, data subject rights and international transfers. In each tier, the higher of the two amounts applies.
Where teams usually fall short
- No record of processing activities, or one that is out of date.
- Processors without a signed data processing agreement.
- No tested process for notifying a breach within 72 hours.
- Data subject requests handled ad hoc, with no deadline tracking.
- Retention periods that are not defined, or not enforced.
- International transfers without a documented safeguard.
What the free assessment covers
The free SwaSec GDPR assessment asks 13 questions across 6 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.
- Principles and Lawful Basis (Art. 5-6). Core data protection principles and requirements for establishing a lawful basis for processing.
- Data Subject Rights (Art. 12-22). Transparency obligations and mechanisms for exercising data subject rights.
- Accountability and Governance (Art. 24-31). Organizational accountability measures, data protection by design, processor agreements, and records of processing.
- Security and Breach Notification (Art. 32-34). Security measures proportionate to risk and breach notification procedures.
- Impact Assessments and Transfers (Art. 35, 44-49). Data protection impact assessments and safeguards for international data transfers.
- Consent (Art. 7-8). Conditions for valid consent as a lawful basis for processing.
Start the GDPR assessment. It is a self-assessment, not an audit or a certification.
How GDPR overlaps with other frameworks
GDPR shares 6 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.
- Security Policy, shared with ISO 27001, ISO 42001 and SOC 2. Asked once.
- Risk Assessment, shared with ISO 27001, ISO 42001, SOC 2 and EU AI Act. Asked separately, because each framework wants something different.
- Incident Response, shared with ISO 27001 and SOC 2. Asked once.
- Vendor/Supplier Management, shared with ISO 27001, ISO 42001 and SOC 2. Asked once.
- Data Governance, shared with ISO 42001 and EU AI Act. Asked separately, because each framework wants something different.
- Transparency, shared with EU AI Act. Asked separately, because each framework wants something different.
Frequently asked questions
Does GDPR apply to companies outside the EU?
Yes, if they offer goods or services to people in the EU or monitor their behaviour there. Where the company is based does not decide it.
Is there a GDPR certification?
There is no single official GDPR certificate. Article 42 allows approved certification schemes, but most companies show compliance through their documentation, contracts and, for the security side, audits such as ISO 27001 or SOC 2.
How quickly must a data breach be reported under GDPR?
To the supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. High-risk breaches must also be communicated to the people affected without undue delay.
What does the free SwaSec GDPR assessment cover?
13 questions across 6 domains, taking about 10 minutes, with no signup. It gives you a score for GDPR, the gaps it found, and the clause, control or article each gap relates to.
Sources
This guide is general information, not legal advice. Last updated 1st October 2026.