What Is GDPR?
The regulation that rewrote the rules for handling personal data – and applies far beyond Europe.
GDPR (the General Data Protection Regulation) is a European Union regulation that came into force in May 2018, replacing a 1995 directive that had fragmented data protection across member states into inconsistent national laws. It sets a single, binding standard for how personal data must be collected, processed, stored, and deleted – and unlike its predecessor, it applies directly as law across all EU member states with no national reinterpretation required.
Welcome to Session 1: GDPR Introduction. In this section, we’ll explore the GDPR articles in their official sequence, providing a clear understanding of the regulation’s structure and purpose. For a more interactive learning experience, watch the accompanying video below as you follow along.
The word “regulation” rather than “directive” matters here. A directive tells member states to pass their own laws achieving a given result. A regulation is the law itself, applying uniformly and immediately across all 27 EU member states the moment it was enacted.

| Three things about GDPR catch organisations off guard before they’ve even started scoping their compliance work. | COMMON FIRST SURPRISES
|
GDPR’s scope rests on two triggers – the establishment criterion (an organisation is based in the EU) and the targeting criterion (an organisation outside the EU offers goods or services to EU residents, or monitors their behaviour). Either one is enough to bring an organisation into scope.
Related reading: Personal Data & the 7 Principles · Controllers vs Processors · Who Needs GDPR Compliance?
How GCAI helps: GCAI starts every GDPR engagement by confirming which trigger brings your organisation into scope – establishment, targeting, or both – because the distinction affects which supervisory authority you answer to and what your representative obligations look like.
Personal Data & the 7 Principles
GDPR protects more than names and email addresses – and the principles it rests on aren’t optional guidance.
Personal data under GDPR is any information that relates to an identified or identifiable natural person – a “data subject.” That definition is deliberately broad. An IP address is personal data. A device ID linked to browsing behaviour is personal data. A pseudonymised identifier that could be re-linked to an individual with additional information is personal data. The only data fully outside GDPR’s scope is truly anonymised data – and the standard for anonymisation is high.

| The personal data definition catches more than people expect. If there’s any realistic path back to identifying an individual, the data is in scope. | WHAT COUNTS AS PERSONAL DATA
|
Every GDPR compliance obligation traces back to seven data protection principles set out in Article 5. They’re not aspirational values – they’re binding requirements that controllers must be able to demonstrate they’re meeting:
- Lawfulness, fairness, and transparency. Data must be processed on a valid legal basis, handled fairly, and individuals must be clearly informed.
- Purpose limitation. Data collected for one purpose cannot be repurposed for an incompatible use without a new legal basis or fresh notice.
- Data minimisation. Only collect what you actually need. More isn’t safer – it’s a liability.
- Accuracy. Keep data accurate and up to date. Processes to correct or delete inaccurate records are required.
- Storage limitation. Data must be deleted when it’s no longer needed for its original purpose. Retention periods must be defined and enforced.
- Integrity and confidentiality. Appropriate technical and organisational security measures must protect data against unauthorised access, loss, or damage.
- Accountability. The organisation must be able to demonstrate compliance – not just claim it. Documentation, policies, and evidence are what make this real.
Related reading: What Is GDPR? · Controllers vs Processors · The GDPR Compliance Process
How GCAI helps: GCAI maps your data processing activities against each of the seven principles before any control work begins, so remediation is targeted at the gaps rather than applied generically across every system.
Controllers vs Processors: What’s the Difference?
Same regulation, two distinct roles – and knowing which one you are changes what you’re required to do.
GDPR distinguishes between two roles in any data processing relationship. A data controller determines the purposes and means of processing – the why and the how. A data processor carries out processing on the controller’s instructions. Most SaaS companies encounter GDPR first as processors, only to discover that the moment they start making independent decisions about their users’ data, they’ve crossed into controller territory.

| Data Controller | Data Processor | |
|---|---|---|
| Who it is | Decides why and how personal data is processed | Processes data only on the controller’s instructions |
| Legal basis | Must establish and document a lawful basis for processing | Relies on the controller’s legal basis – doesn’t need its own |
| Governing contract | Must execute a DPA before sharing data with a processor | Signs the DPA and is bound by its terms |
| Data subject rights | Directly responsible for handling access, erasure, and portability requests | Must assist the controller in responding to requests |
| Breach notification | Must notify supervisory authority within 72 hours | Must notify the controller without undue delay |
| Typical examples | SaaS product collecting user data, HR platform | Cloud hosting provider, payroll processor, analytics vendor |
| The Data Processing Agreement (DPA) is the contract that formalises the controller–processor relationship. It’s not optional – Article 28 requires it, and a processor operating without a DPA is a compliance gap for both parties. | WHAT A DPA MUST COVER
|
Joint controllers are a third scenario that often gets overlooked: two organisations that jointly determine the purposes and means of processing must agree in writing on their respective obligations under GDPR, and data subjects must be able to exercise their rights against either party.
Related reading: What Is GDPR? · Who Needs GDPR Compliance? · The GDPR Compliance Process
How GCAI helps: GCAI reviews your vendor contracts and data flows to confirm every controller–processor relationship is covered by a compliant DPA before an audit or customer review surfaces the gap.
Who Needs GDPR Compliance?
Geography of incorporation is irrelevant. What matters is where your users are.
GDPR applies to any organisation that processes the personal data of individuals in the EU or UK, regardless of where the organisation itself is based. A company incorporated in Singapore, the United States, or India with no physical presence in Europe is still in scope if it sells to, serves, or tracks the behaviour of people located in the EU or UK. This extraterritorial reach is one of the most misunderstood aspects of the regulation.
EU and UK-based organisations. All organisations established in the EU are in scope by default, covering every sector and every size. UK organisations follow UK GDPR – substantively identical but enforced by the ICO rather than EU supervisory authorities.
Non-EU SaaS and tech companies. Any platform with EU users, EU-targeted marketing, or EU-denominated pricing is processing EU personal data and falls under the targeting criterion of Article 3(2), whether or not the founders realise it.
B2B vendors and subprocessors. A company that never directly interacts with EU consumers can still be in scope as a processor if it handles personal data on behalf of a controller that does.
Startups at earlier stages. GDPR obligations start from the first EU user, not from the first enterprise contract or the first investor asking for proof. The obligation doesn’t wait for scale.

| A few indicators that reliably confirm GDPR scope, regardless of where the company is incorporated. | ARE YOU IN SCOPE?
|
One nuance worth flagging: organisations below 250 employees have a partial exemption from the obligation to maintain Records of Processing Activities (RoPA) under Article 30, but only for non-regular processing that carries no risk. In practice, most organisations – even small ones – have at least some processing activities that fall outside the exemption, making a partial RoPA necessary regardless of size.
Related reading: What Is GDPR? · Controllers vs Processors · GDPR vs ISO 27001
How GCAI helps: GCAI scopes GDPR around your actual data flows and user geography before any implementation work starts, so the programme is sized to what you actually process rather than the broadest possible interpretation.
GDPR vs ISO 27001: Which Do You Need?
A privacy regulation and an information security standard that overlap more than they compete.
GDPR and ISO 27001 solve different problems. GDPR is a binding legal requirement governing the privacy rights of individuals and the lawful use of their personal data. ISO 27001 is a voluntary international standard for building and maintaining an Information Security Management System (ISMS). They’re not alternatives – organisations in scope for GDPR often pursue ISO 27001 precisely because it helps demonstrate the “appropriate technical and organisational measures” Article 32 requires.
| GDPR | ISO 27001 | |
|---|---|---|
| What it is | EU/UK privacy regulation | International information security standard |
| Mandatory? | Yes, if processing EU/UK personal data | No – voluntary, but often commercially required |
| What you get | Compliance status, not a certificate | A certifiable ISMS with an auditable certificate |
| Issued by | No certificate; enforced by supervisory authorities | Accredited certification body after a third-party audit |
| Primary focus | Data subject rights, lawful processing, privacy | Confidentiality, integrity, and availability of information |
| Overlap | Article 32 security requirements, breach response, access controls | Annex A controls covering much of GDPR’s Article 32 territory |
The practical relationship: ISO 27001 controls – access management, incident response, supplier security, asset management – directly support GDPR’s Article 32 obligation to implement appropriate security measures. Evidence gathered for ISO 27001 can often be reused as GDPR evidence rather than collected twice.
GDPR also sits alongside other regional privacy laws that organisations targeting specific markets may need. The UK’s Data Protection Act 2018 sits on top of UK GDPR. US-based organisations with EU operations may also face CCPA obligations for California residents, though the two regimes have different scopes and enforcement mechanisms.
Related reading: What Is GDPR? · Who Needs GDPR Compliance? · The GDPR Compliance Process
How GCAI helps: GCAI maps GDPR requirements against ISO 27001 controls so organisations pursuing both don’t build two separate evidence sets from scratch – the same documentation work supports both programmes wherever they overlap.
The GDPR Compliance Process

No audit deadline forces the pace, but supervisory authorities investigate without warning.
GDPR compliance isn’t built around a single audit event with a fixed timeline. It’s an ongoing programme. That said, the implementation sequence is fairly consistent across organisations:
| Phase | What happens | Typical duration |
|---|---|---|
| Data mapping | Identify every personal data flow – what’s collected, where it goes, who can access it, how long it’s kept | 2–6 weeks |
| Records of Processing (RoPA) | Document all processing activities under Article 30 – purpose, legal basis, data categories, retention periods | 2–4 weeks |
| Legal basis & consent review | Assign and document a lawful basis for every processing activity; audit consent mechanisms against GDPR’s standard | 2–4 weeks |
| Gap remediation | Update privacy notices, implement required controls, fix retention practices, review supplier DPAs | 1–3 months |
| DPIAs | Conduct Data Protection Impact Assessments for high-risk processing activities before they go live | Ongoing |
| Breach response programme | Establish a 72-hour notification workflow to supervisory authority and affected individuals | 2–4 weeks |
| International transfers | Identify data flows outside the EEA; implement SCCs, adequacy decisions, or BCRs as applicable | 2–6 weeks |
| Monitoring & review | Ongoing staff training, periodic data audits, DPA reviews, and policy updates | Continuous |
International data transfers deserve a separate note because they catch organisations off guard long after initial compliance work is done. Sending personal data from the EU to any country outside the European Economic Area (EEA) requires a legal mechanism – either an adequacy decision from the European Commission (covering countries like the UK, Switzerland, Japan, and South Korea), Standard Contractual Clauses (pre-approved contract terms attached to the transfer agreement), or Binding Corporate Rules for intra-group transfers.
| The 72-hour breach notification deadline is the requirement that most consistently creates operational problems for organisations that didn’t pre-build their incident response workflow. | GDPR BY THE NUMBERS
|
Related reading: Controllers vs Processors · Who Needs GDPR Compliance? · GDPR FAQ
How GCAI helps: GCAI builds and maintains the RoPA and breach notification workflow as part of the compliance programme – the two documents OCR and supervisory authorities ask for first when an investigation opens.
GDPR FAQ
The questions that come up most once the basics are out of the way.
Is there a GDPR certificate? No. Unlike ISO 27001, GDPR has no certification body and issues no certificate. “GDPR certified” is a marketing claim from a third-party vendor, not a credential issued under the regulation itself. Compliance is demonstrated through documentation and internal programme evidence, not a badge.
Does GDPR apply to my US-based company? Yes, if you have EU or UK users, target EU or UK customers in your marketing, or process EU personal data as a subprocessor for a client that does. The company’s country of incorporation is irrelevant to GDPR’s applicability.
What is the difference between EU GDPR and UK GDPR? Following Brexit, the UK incorporated GDPR into domestic law as UK GDPR, enforced by the ICO. The two regulations are substantively identical, but they are technically separate: a business serving both EU and UK residents must satisfy both and may need to interact with both supervisory authorities in the event of a breach.
Do we need a Data Protection Officer (DPO)? Not all organisations are required to appoint a DPO. The requirement applies when an organisation is a public authority, carries out large-scale systematic monitoring of individuals, or processes special category data at scale. That said, many organisations appoint a DPO voluntarily for governance reasons, and doing so is never penalised.
How long does it take to become GDPR compliant? An organisation with reasonable data hygiene typically takes two to four months to complete initial implementation. The RoPA and legal basis documentation usually take the most time; breach response and international transfer mechanisms can be layered in alongside that work.
What’s the difference between a DPA and a BAA? A Data Processing Agreement (DPA) under GDPR and a Business Associate Agreement (BAA) under HIPAA serve the same structural function – formalising a data-sharing relationship between two parties – but under different regulatory regimes. They are not interchangeable; an organisation subject to both GDPR and HIPAA typically needs both contracts in place.
Related reading: What Is GDPR? · Controllers vs Processors · GDPR vs ISO 27001
How GCAI helps: GCAI’s GDPR gap assessment covers most of the questions above for your specific data environment in a single working session – including whether a DPO appointment is required and which supervisory authority has lead jurisdiction.