GDPRData PrivacyEuropean UnionAll Industries

EU General Data Protection Regulation

Comprehensive data protection regulation governing how organizations collect, store, and process personal data of EU residents. Non-compliance can result in fines up to 4% of global annual revenue.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

GDPRArticle 30Knowing where the data isA record of access

Records of Processing Activities

Organizations MUST maintain detailed records of all personal data processing activities, including access logs.

You cannot evidence a control over data you have not located. Discovery scans every connected store continuously and classifies what it finds against 200+ built-in patterns and 20+ categories, so the inventory reflects the estate as it is today rather than as it was at the last manual survey. Because the classification is what ranks the scanning and shapes the reports, it cannot quietly go stale without something visibly breaking.

GDPRArticle 32Patching, hardening, and exposureA record of access

Security of Processing

REQUIRES appropriate technical measures including the ability to ensure ongoing confidentiality and integrity of processing systems.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

GDPRArticle 33Detecting it in time to notify

Breach Notification

Data breaches MUST be reported to authorities within 72 hours. Requires real-time detection capabilities.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

The 72-hour clock starts at awareness, so detection latency is the exposure. Deviations are scored and routed in under a second rather than surfacing in a review cycle.

GDPRArticle 35Assessment backed by evidence

Data Protection Impact Assessment

High-risk processing REQUIRES documented impact assessments with evidence of security measures.

An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.

What GDPR covers

Art. 4(1); special categories at Art. 9(1); anonymous data at Recital 26

Any information relating to an identified or identifiable natural person.

In scope

  • Names and identification numbers
  • Location data
  • Online identifiers
  • Factors specific to physical, physiological, genetic, mental, economic, cultural or social identity

Special categories of personal data (Art. 9)

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data processed to identify a person
  • Health data
  • Sex life or sexual orientation

What falls outside

Truly anonymous data falls outside entirely. Pseudonymised data does not — Recital 26 is explicit that data which can be attributed with additional information remains personal data.

Regulation (EU) 2016/679, Art. 4 · as at 2026-08

How GDPR is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by National supervisory authorities, led by the lead authority for the main establishment.

Published maximumChargedAs at
EUR 20 millionthe fixed limb of the upper tier, Art. 83(5)2026-08
4% of total worldwide annual turnoverthe percentage limb; the higher of the two applies, calculated on the whole undertaking2026-08
EUR 10 millionthe fixed limb of the lower tier, Art. 83(4), which covers the Art. 32 security duty2026-08
2% of total worldwide annual turnoverthe percentage limb of the lower tier2026-08

Article 83(5) sets the upper tier for breaches of the basic principles, data subject rights, and transfer rules. A lower tier of EUR 10 million or 2% applies to controller and processor obligations, including the Article 32 security duty. Separately, Article 82 gives any person who suffers damage a direct right to compensation from the controller or processor, which is pursued in the national courts rather than through the regulator.

GDPR itself creates no criminal offence. Article 84 leaves criminal penalties to each Member State, and several have legislated them separately.

Uncapped exposure that sits outside this instrument

These come from company law rather than from GDPR, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Who the instrument makes accountable

Article 24 places the demonstrable-accountability duty on the controller, and Article 39 gives the data protection officer an advisory and monitoring role rather than a deciding one. Deciding not to remediate is a controller decision, and Article 5(2) is why it has to be documented.

The insurance position

Cover for administrative fines is generally unavailable where the Member State treats them as uninsurable, and the position genuinely differs across the Union.

How this class of policy is commonly written. Only your own policy answers what it covers.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for GDPR,
not configured for it afterwards

Policy Template

Personal Data Access Monitoring

Pre-built policy to track all access to tables containing EU resident data

Report

DPIA Evidence Report

Automated report documenting all data access patterns for impact assessments

Classification

EU PII Patterns

Auto-detect EU-specific identifiers: national IDs, IBAN, VAT numbers

Alert

72-Hour Breach Detection

Real-time alerting ensures you detect breaches within notification window

Other Data Privacy frameworks

Walk into the GDPR audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment