Framework guide • EU Privacy

GDPR: the EU’s data-protection law, explained

The General Data Protection Regulation (GDPR) is the EU’s law for handling personal data. It applies to anyone processing the data of people in the EU — wherever they’re based — sets core principles, grants individuals strong rights, requires a lawful basis for processing, and mandates breach notification. GDPR is a legal regulation, not a certification: you must be able to demonstrate ongoing compliance.

A legal regulation, not a certificate

Unlike ISO 27001 or SOC 2, you don’t get “GDPR certified.” GDPR is a binding EU law: you’re expected to comply continuously and to be able to demonstrate it, and regulators can impose significant penalties. A strong security program helps — an ISO 27001 ISMS supports GDPR’s security principle — but GDPR also covers legal and privacy obligations that go beyond security. Treat this guide as an orientation and pair it with qualified legal advice for your situation.

Core principles

The principles behind GDPR

Lawfulness, fairness & transparency

Process personal data lawfully and fairly, and be clear with people about what you do with their data.

Purpose limitation & minimisation

Collect data for specified, legitimate purposes and only what you actually need — no more.

Accuracy & storage limitation

Keep personal data accurate and up to date, and don't retain it for longer than necessary.

Integrity, confidentiality & accountability

Secure the data appropriately, and be able to demonstrate your compliance — accountability is a principle in its own right.

The rights GDPR gives people

GDPR hands individuals a set of rights over their personal data. You need processes to recognize and respond to these requests — usually within a set timeframe:

  • Be informed about how their data is used
  • Access the personal data you hold about them
  • Have inaccurate data rectified
  • Have their data erased (the right to be forgotten)
  • Restrict or object to certain processing
  • Data portability — receive and reuse their data
Lawful bases

Six ways to lawfully process

You need a valid lawful basis before processing personal data. There are six — pick and document the one that fits each activity.

Consent & contract

The person has given clear consent, or processing is necessary to perform a contract with them.

Legal obligation & legitimate interests

Processing is required by law, or is necessary for your legitimate interests balanced against the person's rights.

Vital & public interest

Processing protects someone's vital interests, or is carried out in the public interest or official authority.

Breach notification

GDPR expects you to detect, investigate, and report personal-data breaches. Where a breach is likely to risk people’s rights and freedoms, you generally must notify the relevant supervisory authority without undue delay, and where the risk is high, inform the affected individuals too. Because the exact thresholds and timelines are enforced, confirm the current requirements against the official regulation and take legal advice where appropriate.

FAQ

GDPR, answered

Organize your GDPR readiness

Komply maps data-protection controls into one control set alongside ISO 27001, drafts policies, and tracks evidence — support your compliance program and pair it with legal advice.