European Regulation

GDPR · Data Protection

The General Data Protection Regulation establishes the obligations for processing personal data and the role of the Data Protection Officer (DPO).

Entry into force: May 25, 2018 Applies to: organizations established in the EU and, in certain cases, organizations outside the EU that offer goods or services to people in the Union or monitor their behavior Fines: up to €20M or 4% of global turnover

What is GDPR?

The General Data Protection Regulation (GDPR) establishes the European framework for protecting individuals in relation to the processing of their personal data and the free movement of such data.

The GDPR applies to processing carried out in the context of the activities of controllers' or processors' establishments in the Union and, in certain cases, to organizations not established in the EU when they offer goods or services to people located in the Union or monitor their behavior.

Key principle: The GDPR is based on proactive accountability. Organizations must demonstrate compliance, not just claim it.

Who does it apply to?

The GDPR applies to:

  • Data controllers: Organizations that determine the purposes and means of processing personal data.
  • Data processors: Organizations that process personal data on behalf of the controller.
  • Sub-processors: Organizations that process data on behalf of the processor.

Territorial scope: Applies to organizations established in the EU and, in certain cases, to organizations outside the EU that offer goods or services to people in the Union or monitor their behavior.

The role of the DPO (Data Protection Officer)

The DPO is a key role in data protection. Their duties include:

  • Compliance oversight: Monitoring compliance with the GDPR, applicable regulations and internal data protection policies.
  • Advisory: Informing and advising the organization on its obligations.
  • Impact assessments: Advising on the need for and carrying out of DPIAs and overseeing their correct execution.
  • Breach management: Advice and support in managing security breaches and, where applicable, in notification obligations to the supervisory authority and communication to those affected.
  • Point of contact: Acting as a liaison with supervisory authorities and data subjects.

When is appointing a DPO mandatory?

  • Large-scale processing of special categories of data.
  • Large-scale processing of criminal data.
  • Systematic large-scale monitoring of data subjects.
  • When required by national regulations.

Consequences of non-compliance

  • Financial fines: Up to €20 million or 4% of global annual turnover.
  • Liability and penalties: non-compliance can lead to corrective measures and administrative sanctions against controllers and processors, in addition to possible liability under applicable law.
  • Advice and support for security breaches: including, where applicable, notification obligations to the supervisory authority and communication to those affected.
  • Operational restrictions: Authorities can prohibit data processing.

How can I help you with GDPR and DPO?

External DPO & Privacy Advisory

I act as your external Data Protection Officer. Monthly retainer with initial response within 24 business hours.

View service →

GDPR Audit

We assess your compliance level, identify gaps and design an action plan.

View service →

Impact Assessments (DPIA)

We carry out data protection impact assessments for high-risk processing.

View service →

Do you need an external DPO or to prepare your company for GDPR?

Request an assessment meeting →

20–30 minutes · No commitment · We review context, need and next steps.