The practical guide to GDPR compliance
The GDPR is 99 articles, 173 recitals, and thousands of pages of regulatory guidance. These guides cut through it and tell you what actually matters for your business.
Data subject rights and your obligations
The GDPR gives individuals specific rights over their personal data — access, rectification, erasure, portability, and objection. Your obligation isn't just to respect them, it's to have a documented process that can respond within one calendar month.
Lawful bases, ROPA, and impact assessments
Every time you process personal data, you need a lawful basis. Every processing activity needs to be recorded. And some activities require a formal impact assessment before you start. This is where most compliance gaps live.
Sub-processors, DPAs, and international transfers
Every SaaS tool in your stack that touches personal data is a sub-processor with data processing implications. You need a DPA with each one, and if they transfer data outside the EU, you need a legal mechanism to justify it.
Breach notification and incident response
A breach isn't just a cyberattack. An email sent to the wrong recipient, a lost laptop, an unencrypted export — all qualify. You have 72 hours to notify your supervisory authority once you're aware. That window is too short to figure out your process on the fly.
Cookie consent, legitimate interest, and the ePrivacy rules
Consent under the GDPR isn't just a cookie banner. It's a specific lawful basis with strict conditions: freely given, specific, informed, and unambiguous. And the ePrivacy Directive adds its own layer of rules for electronic communications and terminal equipment access.
Not sure where your gaps are? The assessment scans your operations against 142 GDPR requirements and shows you exactly where you stand. Takes 12 minutes, no account required.
Start free assessment