GDPR, explained for teams getting ready

The General Data Protection Regulation is EU law on how personal data is collected, used and protected, and it reaches far beyond Europe. Here is who it applies to, what it requires, and where teams usually fall short.

Assess GDPR free

13 questions · about 10 min · no signup

Type
EU regulation
Reference
Regulation (EU) 2016/679
Applies since
25 May 2018
Maximum fine
€20M or 4% of turnover

This guide is growing. A fuller GDPR guide, with requirement-by-requirement detail and worked examples, is being written. Last updated 1st October 2026.

On this page
01

What is GDPR?

GDPR sets the rules for processing personal data: any information that identifies a person directly or indirectly, such as a name, an email address, an IP address or a device identifier. It has applied across the EU and the EEA since 25 May 2018.

The UK has its own version, the UK GDPR, which closely follows it.

02

Who GDPR applies to

GDPR applies to organizations established in the EU, and also to organizations outside it that offer goods or services to people in the EU or monitor their behaviour there (Article 3). A SaaS company in India or the US with EU customers or users is usually in scope.

  • Controller: decides why and how personal data is processed.
  • Processor: processes personal data on a controller's behalf, for example a SaaS vendor hosting its customers' data. Processors have direct obligations of their own.
03

The core principles (Article 5)

  • Lawfulness, fairness and transparency.
  • Purpose limitation: collect data for specified purposes, and do not reuse it for incompatible ones.
  • Data minimisation: only what you need.
  • Accuracy: keep it correct and up to date.
  • Storage limitation: keep it no longer than necessary.
  • Integrity and confidentiality: protect it with appropriate security.
  • Accountability: be able to demonstrate all of the above.
04

What GDPR requires in practice

  • A lawful basis for each processing activity (Article 6): consent, contract, legal obligation, vital interests, public task or legitimate interests.
  • Clear privacy notices (Articles 12 to 14).
  • A way to handle data subject rights: access, rectification, erasure, restriction, portability and objection (Articles 15 to 22).
  • Data processing agreements with your processors (Article 28).
  • Records of processing activities (Article 30).
  • Appropriate security measures (Article 32).
  • Notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people (Article 33).
  • Data protection impact assessments for high-risk processing (Article 35).
  • A Data Protection Officer where the regulation requires one (Article 37).
  • Safeguards for transfers of personal data outside the EU and EEA (Chapter V).
05

GDPR fines

Article 83 sets two tiers of administrative fines: up to €10 million or 2% of total worldwide annual turnover, and up to €20 million or 4% for breaches of the core principles, the lawful basis rules, data subject rights and international transfers. In each tier, the higher of the two amounts applies.

06

Where teams usually fall short

  • No record of processing activities, or one that is out of date.
  • Processors without a signed data processing agreement.
  • No tested process for notifying a breach within 72 hours.
  • Data subject requests handled ad hoc, with no deadline tracking.
  • Retention periods that are not defined, or not enforced.
  • International transfers without a documented safeguard.
07

What the free assessment covers

The free SwaSec GDPR assessment asks 13 questions across 6 domains and takes about 10 minutes. It scores where you stand and ties each gap to the clause, control or article it relates to.

  • Principles and Lawful Basis (Art. 5-6). Core data protection principles and requirements for establishing a lawful basis for processing.
  • Data Subject Rights (Art. 12-22). Transparency obligations and mechanisms for exercising data subject rights.
  • Accountability and Governance (Art. 24-31). Organizational accountability measures, data protection by design, processor agreements, and records of processing.
  • Security and Breach Notification (Art. 32-34). Security measures proportionate to risk and breach notification procedures.
  • Impact Assessments and Transfers (Art. 35, 44-49). Data protection impact assessments and safeguards for international data transfers.
  • Consent (Art. 7-8). Conditions for valid consent as a lawful basis for processing.

Start the GDPR assessment. It is a self-assessment, not an audit or a certification.

08

How GDPR overlaps with other frameworks

GDPR shares 6 areas with the other frameworks SwaSec covers. Where it can, the assessment asks a shared area once, and the answer counts toward each framework.

09

Frequently asked questions

Does GDPR apply to companies outside the EU?

Yes, if they offer goods or services to people in the EU or monitor their behaviour there. Where the company is based does not decide it.

Is there a GDPR certification?

There is no single official GDPR certificate. Article 42 allows approved certification schemes, but most companies show compliance through their documentation, contracts and, for the security side, audits such as ISO 27001 or SOC 2.

How quickly must a data breach be reported under GDPR?

To the supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. High-risk breaches must also be communicated to the people affected without undue delay.

What does the free SwaSec GDPR assessment cover?

13 questions across 6 domains, taking about 10 minutes, with no signup. It gives you a score for GDPR, the gaps it found, and the clause, control or article each gap relates to.

10

Sources

This guide is general information, not legal advice. Last updated 1st October 2026.

The other frameworks