The General Data Protection Regulation (GDPR) may have been created in the European Union (EU), but this consumer privacy law applies to any organization, anywhere in the world, that controls or processes the personal data of EU residents. Enforced as of May 25, 2018, GDPR is designed to increase EU individuals’ control over their personal data as well as increase accountability for businesses that hold personal data.
Download this free ebook to learn more about:
- Why GDPR is an organization-wide effort
- How to make GDPR compliance easier
- Why it’s important to maintain a constant state of compliance
Who the GDPR Applies To
The General Data Protection Regulation was created in the European Union and applies to any organization anywhere in the world that controls or processes the personal data of EU residents. It has been enforced since 25 May 2018.
Most requirements fall on data controllers, the businesses that decide how and when personal data is collected, stored, used or transmitted. The law also sets rules for data processors, which handle data on a controller’s behalf.
What Non-Compliance Costs
Fines can reach 4 percent of annual global revenue or €20 million, whichever is higher, before any reputational or legal damage arising from the breach itself.
By January 2021, according to DLA Piper, more than €272.5 million in fines had been issued across the 27 member states plus the UK, Norway, Iceland and Liechtenstein. The French regulator CNIL fined Google €50 million over its data handling, Germany fined H&M €35.2 million for improperly recording employees’ personal activities at a call center, and Italy issued €27.8 million to a telecommunications operator over data handling and marketing.
The recurring cause is worth noting: failure to implement appropriate security measures is among the most common reasons for a GDPR fine.
The Five Things the Regulation Asks You to Demonstrate
Governance and accountability. Do effective policies and processes exist for collecting, storing, using and sharing personal data, and for monitoring and proving compliance with them?
An inventory of personal data. Do you know what personal data you hold, where it is, and whose it is, at any given moment?
Protection of that data. Are privacy, security, integrity and availability maintained both inside and outside the corporate network?
Individual rights. Can you answer requests for access, correction, erasure, portability and restriction of processing within the time allowed?
Breach reporting. Are there processes to identify, assess, report and mitigate a breach quickly enough to meet the notification deadline?
Why the Inventory Comes First
Four of those five depend on the second. Rights cannot be fulfilled for data nobody can find, protection cannot be applied to it, and a breach involving it cannot be assessed or reported accurately.
Building that inventory means identifying personal data in every format it takes, on premises and in cloud services, known and unknown, and associating it with the data subjects it describes. It is the foundation the rest of a compliance program stands on.
Compliance Is Not a Technology Purchase
No product makes an organization GDPR compliant. The regulation asks for processes, adherence to those processes, and documented proof of both, across development, marketing, analytics, legal, IT operations and the executive team.
What technology does is make the evidence a by-product of normal operation rather than a reporting exercise. Automated discovery, classification and protection produce the record continuously, which is the difference between demonstrating compliance and asserting it.
That distinction is where most enforcement action lands. Regulators rarely dispute whether a policy existed. They ask what the organization did, what record proves it, and how quickly the answer could be produced when the request arrived.

