By regulation

GDPR

The General Data Protection Regulation sets out the rules for how organisations process personal data of individuals in the European Economic Area. Most enforcement action comes from a small set of practical obligations that are easy to describe and hard to maintain.

Article 30 records of processing

Article 30 requires controllers and processors to maintain a record of processing activities. For most organisations, this is the single most useful governance document: it forces the business to name what data it holds, why it holds it, where it flows, who it is shared with, and how long it is kept. Regulators routinely ask for it first in an investigation. A record that is out of date or incomplete usually signals wider problems.

Data Protection Impact Assessments

A DPIA is required before processing that is likely to result in a high risk to individuals. This includes systematic profiling, large-scale use of sensitive data, extensive automated decision-making, and systematic monitoring of public areas. The assessment must describe the processing, assess necessity and proportionality, identify risks to rights and freedoms, and set out the measures to address those risks. A poor DPIA is one of the most common findings in supervisory audits.

Lawful basis

Every processing operation must have a lawful basis. The six bases are consent, contract, legal obligation, vital interests, public task and legitimate interests. Most organisations rely on consent, contract or legitimate interests. The choice must be documented before processing begins, and it must be reviewed when the purpose changes. Consent must be freely given, specific, informed and unambiguous, with a clear affirmative action.

International transfers

Transferring personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a derogation. Since the Schrems II judgment, the appropriate safeguards route — particularly Standard Contractual Clauses — now requires a transfer impact assessment to confirm that the data will receive a level of protection essentially equivalent to that in the EU. Many organisations still have legacy transfer arrangements that have not been reassessed.

The 72-hour breach notification

Article 33 requires controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. The notification must describe the breach, the categories and approximate number of affected individuals and records, the likely consequences, and the measures taken or proposed. If the breach is likely to result in a high risk to the rights and freedoms of individuals, controllers must also communicate directly to those individuals.

The 72-hour clock starts when the controller becomes aware; detection, escalation and decision-making processes therefore matter as much as technical controls.

EU institutions and bodies

EU institutions and bodies are not subject to the GDPR. They are governed by Regulation (EU) 2018/1725, which contains equivalent rules tailored to the EU public administration.

How CYBERVETTER helps

We help organisations move beyond checkbox compliance to an operational privacy programme that can withstand scrutiny:

  • Article 30 records of processing activities, mapped to actual systems and data flows.
  • DPIA methodology, templates and review of high-risk processing.
  • Lawful basis and consent audits, including marketing and analytics environments.
  • Transfer impact assessments and Standard Contractual Clause governance.
  • Breach playbooks and notification workflows that can meet the 72-hour deadline.

Close the practical GDPR gaps

We build the records, assessments, transfer analysis and breach response capability that regulators actually ask for.

Data protection service