EU regulationEU and EEA, extraterritorial
GDPR
General Data Protection Regulation (EU) 2016/679
The GDPR governs the processing of personal data relating to people in the EU. It applies to organisations established in the EU and to those outside it that offer goods or services to, or monitor, people in the EU. It has applied since 25 May 2018.
Who it reaches
- Any organisation processing personal data of people in the EU: customers, employees, users, contacts.
- Processors acting for controllers, who carry their own Article 28 duties.
- Non-EU companies with EU customers or users, which must also appoint an EU representative in most cases.
What the audit checks
- 01There is no GDPR certificate in general use; audits are assessments against the articles, or against a scheme such as ISO 27701 or a code of conduct.
- 02An audit checks the records of processing, lawful bases, notices, rights handling, DPIAs, processor contracts, transfers and breach handling.
- 03Article 28 gives controllers a right to audit their processors, which is the most common commercial trigger.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| Data mapping and records of processing | 2 to 6 |
| Gap assessment against the articles | 2 to 4 |
| Remediation: notices, contracts, rights, DPIAs | 6 to 16 |
| Assessment or certification audit | 1 to 4 |
Evidence to have ready
- Records of processing activities (Article 30)
- Lawful basis analysis per purpose
- Privacy notices and consent records
- Data subject request log and response times
- Data protection impact assessments
- Processor agreements and sub-processor lists
- International transfer mechanism and transfer impact assessments
- Breach register and notifications to the authority
- DPO appointment and advice records
- Retention schedule and deletion evidence
Questions people ask
- Is there a GDPR certification?
- Article 42 provides for certification schemes, and a few national schemes exist, but there is no single EU-wide GDPR certificate. ISO 27701, the privacy extension to ISO 27001, is the most common certifiable proxy.
- When is a DPIA mandatory?
- Where processing is likely to result in a high risk to individuals: systematic profiling with significant effects, large-scale special-category data, large-scale monitoring of public areas, and processing meeting two or more of the EDPB criteria.
- What are the fines?
- Up to 10 million euro or 2 percent of worldwide turnover for the lower tier, and up to 20 million euro or 4 percent for the upper tier, whichever is higher.