Skip to content
All frameworks

What is GDPR?

The EU's General Data Protection Regulation. It governs the processing of personal data — what you may do with it, on what basis, and what rights the people it describes have.

Who it binds

Any organisation processing the personal data of people in the EU, wherever the organisation is established. The UK retains a near-identical regime as UK GDPR, alongside the Data Protection Act 2018.

72h
breach notification

Art. 33, to the supervisory authority, where the breach is likely to result in a risk.

€20M / 4%
maximum fine

Art. 83(5), or of total worldwide annual turnover, whichever is higher.

1 month
to answer a subject request

Art. 12(3), extendable by two further months where complex.

Dates that matter

  • 25 May 2018Applies.
  • OngoingEnforcement is by national supervisory authorities — in Ireland, the Data Protection Commission.

What people get wrong

Security is Article 32, and it is risk-based

Article 32 requires measures appropriate to the risk, and names pseudonymisation and encryption, confidentiality, integrity, availability and resilience of processing systems and services, restoration after an incident, and regular testing of the measures themselves. It does not name specific technologies.

Transfers out of the EU need a safeguard, and it has to be named

Chapter V permits transfers to third countries only on an adequacy decision or an appropriate safeguard such as the Standard Contractual Clauses. Article 13(1)(f) requires you to tell people which one applies. That is a real disclosure obligation, not a footnote.

Processors need a contract with nine specific terms

Article 28(3) sets out what a controller-processor contract must cover, and Article 28(4) flows the same obligations down to sub-processors. If you handle other organisations' data, this is the document a buyer will ask for.

What Vivid Risk does with GDPR

Article citations where a control has a data-protection dimension, verified against the Official Journal, and a subject-request register.

Questions

Does Vivid Risk handle subject access requests for me?

It maintains a register classifying every collection of your own data and can export or erase against it. Answering a request that arrives to YOU, within the Article 12(3) month, is yours to do.

Is GDPR separate from NIS2?

Yes. They overlap on incident handling but have different triggers, recipients and clocks. Reporting a breach to your data protection authority does not discharge a NIS2 notification to your CSIRT, or the reverse.

One assessment, every framework

The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.