GDPR

Knowledge Base | GDPR | What are GDPR compliance requirements?

What are GDPR compliance requirements?

GDPR compliance requirements depend on an organisation’s role and the nature of its processing activities. For an organisation acting as a data controller, the main compliance obligations include:

  • Establishing a lawful basis for each processing purpose. Special categories of personal data and criminal offence data require additional legal conditions.

  • Providing clear privacy information explaining the purposes of processing, lawful bases, recipients, retention periods and individuals’ rights.

  • Collecting only the personal data that is necessary, keeping it accurate and setting appropriate retention periods.

  • Implementing appropriate technical and organisational security measures and applying data protection by design and by default.

  • Respecting individuals’ rights and responding without undue delay, normally within one month. This period can be extended by up to two further months where necessary, provided the individual is informed and given reasons for the delay within the first month.

  • Using appropriate processors under binding agreements and complying with the rules governing international data transfers.

  • Keeping required records of processing activities and maintaining evidence of compliance.

  • Carrying out a data protection impact assessment before processing that is likely to result in a high risk to individuals’ rights and freedoms, and appointing a data protection officer or EU representative where required.

Controllers must also document personal data breaches. They must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, affected individuals must generally be informed without undue delay, subject to the applicable exceptions.

Processors have their own obligations, including following the controller’s documented instructions, protecting personal data, assisting the controller with its compliance obligations and reporting personal data breaches to the controller without undue delay.