HomeFrameworksInformation Security & PrivacyGDPR

Framework  Information Security & Privacy

GDPR

The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's data protection law, adopted April 27, 2016 and applicable since May 25, 2018. It applies to any organization established in the EU that processes personal data, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior.

It sets principles (lawfulness, purpose limitation, minimization, accuracy, storage limitation, security, accountability), individual rights, controller and processor duties, cross-border transfer rules, 72-hour breach notification to the supervisory authority, and fines of up to 20 million euros or 4 percent of worldwide annual turnover.

The accountability principle makes documentation mandatory. Controllers and processors must keep records of processing activities (Article 30), sign written contracts with processors (Article 28), carry out data protection impact assessments for high-risk processing (Article 35), appoint a Data Protection Officer where required (Article 37), publish privacy notices, and keep policies and evidence showing appropriate technical and organizational measures (Article 32).

Certification under Article 42 is voluntary; approved schemes now include Europrivacy as a European Data Protection Seal and national schemes such as GDPR-CARPA in Luxembourg.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedData protection v4by name, on record
Article 24 Demonstratedwith AllyMatter
Process It the Modern WayEvery data-protection policy, acknowledged by the people who process
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every processor on record
Who read which version, and when
03
Show the supervisory authority the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Controllers and processors established in the EU or EEA, regardless of where processing happens, and non-EU organizations that target or monitor people in the EU. Small organizations are exempt from Article 30 records only if they have fewer than 250 employees and their processing is occasional, low risk and does not involve special categories.

What the assessor asks to see

Records of processing activities; lawful basis analysis and consent records; privacy notices; processor agreements and sub-processor lists; data protection impact assessments; DPO designation and reports; data subject request logs; security policies and Article 32 measures; breach register and notifications; international transfer tools and transfer impact assessments; training records; for certification, the scheme's specific criteria evidence.

Where the requirement sits: Art 5(2) accountability; Art 24 policies; Art 30 RoPA; Art 32 security; Art 35 DPIA; Art 39(1)(b) awareness/training

Article 42 certification

Certification is voluntary and does not reduce liability. The EDPB register lists approved mechanisms, including Europrivacy (an EU-wide European Data Protection Seal, with updated criteria approved in EDPB Opinions 14/2026 and 15/2026, the latter for use as a transfer tool by non-EEA importers), GDPR-CARPA (Luxembourg) and national schemes in Germany, Austria, France and the Netherlands.

Check the register for the current list and the accredited certification bodies for each scheme.

What AllyMatter does here

Policy documentation and staff-acknowledgment layer.

AllyMatter publishes this site.

Assessors

Who assesses GDPR

No mandatory assessor. Supervisory authorities (for example CNIL, the Irish DPC, the German state authorities) investigate and enforce. Voluntary Article 42 certification is issued by certification bodies accredited under Article 43 against EDPB-approved criteria, or by the supervisory authority itself.

Accredited by National accreditation bodies under ISO/IEC 17065 (with supervisory authority requirements) or the supervisory authority itself, per Article 43; the EDPB approves criteria for European Data Protection Seals.

Public register of assessors: https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en

No firm has claimed a GDPR assessor listing yet. Claim yours →

Consultants

Who helps with GDPR

A very large ecosystem: privacy law firms, DPO-as-a-service providers, privacy consultancies and GRC platforms. They build records of processing, run DPIAs, draft notices and processor agreements, handle transfer impact assessments and act as outsourced DPO. Engagement shapes range from one-off gap assessments to standing retainers.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

EvalianUKNot yet verified
What they do
Data protection + ISO 27001
Who they help
Evalian is a data protection + ISO 27001 based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. Record of processing activities: are you ready for maturity?Article 30 records are the document a supervisory authority asks for first; this explains what a usable one contains.IAPP
  2. How to draft a GDPR-compliant retention policyPractical guidance on turning storage limitation into a written policy with defensible periods, from the privacy profession's own body.IAPP

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for GDPR

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of GDPR in AllyMatter

Approve the policies GDPR asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.