Regulation (EU) 2016/679
GDPR & data subject rights
GDPR governs personal data processing in the EU. Organisations must honour data subject rights (access, erasure, portability, etc.) within one month, maintain records, and demonstrate accountability.
Am I affected?
Do you process personal data of individuals in the EU?
Yes - GDPR applies regardless of your establishment.
Do you receive access or erasure requests from customers or employees?
Yes - DSAR workflow required.
Do you use processors or transfer data outside the EEA?
Yes - contracts and transfer tools needed.
Fines & sanctions
| Jurisdiction | Maximum | Notes |
|---|---|---|
| EU (GDPR) | Up to €20M or 4% turnover | For serious infringements. |
| EU (GDPR) | Up to €10M or 2% turnover | For administrative failures. |
Key requirements
- Lawful basis and transparency for each processing activity.
- Respond to data subject requests within one month.
- Maintain records of processing and DPIAs where required.
- Data breach notification within 72 hours to supervisory authority.
- Processor agreements and sub-processor oversight.
- Privacy by design and data minimisation.
Deadlines
- DSAR response1 month (extendable to 3)
- Breach notification72 hours
Documents
Our services
EUCRAB offers audit, compliance, and full-service packages tailored to your assessment results.
View service packages