What is GDPR?
The EU's General Data Protection Regulation. It governs the processing of personal data — what you may do with it, on what basis, and what rights the people it describes have.
Any organisation processing the personal data of people in the EU, wherever the organisation is established. The UK retains a near-identical regime as UK GDPR, alongside the Data Protection Act 2018.
Art. 33, to the supervisory authority, where the breach is likely to result in a risk.
Art. 83(5), or of total worldwide annual turnover, whichever is higher.
Art. 12(3), extendable by two further months where complex.
Dates that matter
- 25 May 2018Applies.
- OngoingEnforcement is by national supervisory authorities — in Ireland, the Data Protection Commission.
What people get wrong
Security is Article 32, and it is risk-based
Article 32 requires measures appropriate to the risk, and names pseudonymisation and encryption, confidentiality, integrity, availability and resilience of processing systems and services, restoration after an incident, and regular testing of the measures themselves. It does not name specific technologies.
Transfers out of the EU need a safeguard, and it has to be named
Chapter V permits transfers to third countries only on an adequacy decision or an appropriate safeguard such as the Standard Contractual Clauses. Article 13(1)(f) requires you to tell people which one applies. That is a real disclosure obligation, not a footnote.
Processors need a contract with nine specific terms
Article 28(3) sets out what a controller-processor contract must cover, and Article 28(4) flows the same obligations down to sub-processors. If you handle other organisations' data, this is the document a buyer will ask for.
What Vivid Risk does with GDPR
Article citations where a control has a data-protection dimension, verified against the Official Journal, and a subject-request register.
Questions
Does Vivid Risk handle subject access requests for me?
It maintains a register classifying every collection of your own data and can export or erase against it. Answering a request that arrives to YOU, within the Article 12(3) month, is yours to do.
Is GDPR separate from NIS2?
Yes. They overlap on incident handling but have different triggers, recipients and clocks. Reporting a breach to your data protection authority does not discharge a NIS2 notification to your CSIRT, or the reverse.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.