
An organization is GDPR compliant when it meets the General Data Protection Regulation's requirements for handling personal data and can demonstrate that it does. Both halves matter: the GDPR compliant meaning covers maintaining evidence of compliance as well as the compliant practices themselves.
According to What Directors Think 2026 by Diligent Institute and Corporate Board Member, 40% of public company directors expect data privacy and protection to demand the greatest board attention in 2026, second only to AI and technology regulation.
For boards, that makes reliable reporting on privacy ownership, controls, incidents and remediation an immediate oversight requirement.
This guide covers what GDPR compliance requires and how to build toward it:
GDPR stands for the General Data Protection Regulation. The European Commission proposed it, and the European Parliament and the Council of the European Union adopted it, replacing the EU Data Protection Directive. In the United Kingdom, the Data Protection Act 2018 replaced the Data Protection Act 1998 and supplemented EU GDPR before Brexit.
GDPR protects people in the EU and can apply to organizations outside it. Organizations that do business in the EU or have EU customers face numerous obligations, and controllers and processors risk administrative fines and corrective orders for failing to meet them. Directors may face consequences under applicable national law or governance duties in limited circumstances, depending on the facts.
Whether you are a resident of the European Union, represent an organization established there or serve on the board of an organization that offers goods or services to people in the EU, GDPR's data protection rules will likely affect you directly. With extensive provisions outlining the core tenets of data protection and the responsibilities of organizations of any size that store any kind of data, many organizations are still trying to get their heads around the regulation years after its official implementation.
Current data protection law grew out of what it replaced. The UK's original Data Protection Act 1998 gave way to GDPR, which the UK now enforces as its own separate framework alongside continued updates to domestic law.
Before GDPR, the Data Protection Act 1998 was a United Kingdom Act of Parliament that was modeled after the 1995 EU directive. Affecting corporation or company use rather than personal use, the data protection act fell into eight areas of protection with various exemptions.
The act defined personal data as any data that can identify a singular individual in any manner. The act also outlined that individuals have the right to Subject Access Requests (for a fee) from any organization that holds data on that individual.
The complications of the act derived from its unwieldy size. As it was a large and complex law, many organizations were unsure of what its aims or primary principles were. The enforcement of the Data Protection Act was also challenging, as it did not extend throughout the full European Union or hold global entities responsible and had fewer protections on personal data than on sensitive personal data. With the expansion of the Internet and the advent of cloud-based technologies, enforcement for data centers outside of the U.K. became equally problematic.
The General Data Protection Regulation replaced the 1995 EU directive with a directly applicable regulation that provided stricter enforcement and broader territorial reach. GDPR was adopted in April 2016. Organizations should use that date to distinguish adoption of the regulation from the point at which its requirements became compulsory.
The law became compulsory on May 25, 2018. Current policies, contracts and controls should reflect GDPR rather than the superseded EU directive. Since Brexit, personal data in the UK is governed by UK GDPR and the Data Protection Act 2018, not the repealed 1998 Act.
UK GDPR update: UK GDPR remains a separate framework from EU GDPR, enforced by the Information Commissioner's Office (ICO) alongside the Data Protection Act 2018. The maximum fine under UK GDPR is £17.5 million or 4% of annual worldwide turnover, whichever is higher, according to ICO fining guidance.
The Data (Use and Access) Act 2025 amended UK data protection law, with its remaining data protection provisions taking effect by June 19, 2026, per the ICO DUAA summary. Among the changes is a list of "recognised legitimate interests," a UK lawful basis covering purposes such as crime prevention and safeguarding that does not require the usual balancing test, according to the UK government factsheet. Organizations operating in both the UK and the EU need to track the two regimes separately.
GDPR compliance means meeting the regulation's requirements for collecting, using, sharing, retaining and protecting personal data and maintaining evidence that demonstrates compliance. The evidence obligation comes from Article 5(2) accountability, which states that the controller "shall be responsible for, and be able to demonstrate compliance with" the data protection principles. As the GDPR overview explains, an organization that follows the rules but cannot document how it follows them has not finished the job.
GDPR contains 99 articles that outline the core tenets of data protection and the responsibilities of organizations that process personal data, so organizations should map the articles relevant to their activities to named owners, controls and evidence. GDPR is a regulation that seeks to strengthen the protection of individuals' personal data, and it encompasses the full European Union while addressing personal data outside the borders of the EU as well.
Under Article 3, the regulation applies on two triggers: processing carried out in the context of an establishment in the EU, regardless of where the processing itself takes place, and processing by organizations outside the EU that offer goods or services to people in the Union or monitor their behaviour there. A United States-based company that markets to customers in the EU is just as accountable for a breach of data as an organization physically located in the EU.
The European Commission designed GDPR to harmonize data privacy laws across the EU's 27 member countries and strengthen rights and protections for individuals in those states. The regulation responded to shifting public attitudes toward privacy after the earlier EU Data Protection Directive fell behind the internet era and modern data collection practices.
GDPR sets out seven key principles. Organizations should use these principles as the foundation for policies, control design and compliance evidence. These include:
The ICO advises that these data protection principles should be at the heart of an organization's approach to data.
Individuals have the right to know how their data is handled, stored and regulated. Organizations that capture or store personal data are responsible for tracking it.
Under Article 37, GDPR requires organizations to appoint a data protection officer (DPO) in three situations: the processing is carried out by a public authority or body; the organization's core activities require regular and systematic monitoring of data subjects on a large scale; or its core activities involve large-scale processing of special categories of data or data relating to criminal convictions. Outside those triggers, appointment is voluntary. Where one is in place, the role resembles a compliance officer's, overseeing IT processes, information privacy issues, data storage and protection, cyberattacks and breaches of data protection.
The "Digital Single Market" relies on all EU members following the regulation. Each EU member has created its own Independent Supervisory Authority for complaints, concerns and enforcement. An organization has a "one-stop-shop" that is responsible for supervising all behaviors under the regulation, regardless of how many locations it has within the EU. This limits confusion between different laws in various countries within the EU and on the consumer side as well.
GDPR allows regulators the opportunity to refine and modernize the definitions of data as it relates to an individual. The regulation's formal term for what is commonly called sensitive personal data is "special categories of personal data." Both ordinary personal data and special category data are protected by GDPR. Unlawful processing of special category data may breach Article 9 and expose an organization to the higher Article 83 fine tier.
Personal data is any data that relates to a living individual that can assist in the identification of the individual. For example, phone numbers, addresses of current or former domiciles, email addresses or digital data like non-anonymized cookies or IP addresses. Special categories of personal data include details of a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data or data concerning sex life or sexual orientation. Data relating to criminal convictions and offences receives separate protection under Article 10.
GDPR gives individuals distinct rights over their personal data. Some of these rights include:
Meeting these rights requires organizations to locate personal data quickly, apply exceptions correctly and document every response.
GDPR significantly affects board responsibilities for data protection and information privacy. Organizations that meet the Article 37 criteria must appoint a data protection officer. Finding someone with the skillset to mitigate risk and effectively manage compliance and legal issues is not an easy task. Compliance software can help teams complete internal audits and identify gaps as part of their risk management strategy.
Privacy compliance requires standing board oversight. Boards need recurring, reliable reporting on privacy ownership, controls, incidents and remediation so directors can test whether privacy receives appropriate attention in agendas, risk reporting and committee oversight and challenge gaps before they become enforcement or operational problems.
Board oversight of privacy is shifting toward continuous governance rather than periodic updates. "It's not surprising that boards are seeking expert advice and further training. Boards are paying attention to AI, data privacy, sanctions and tariffs, which represent some of the most technical and rapidly evolving regulatory landscapes boards have ever faced," says Kristy Grant-Hart, Vice President and Head of Advisory Services at Spark Compliance, a Diligent brand.
The board of directors also plays a role in data protection that can create company-wide liabilities and governance consequences. GDPR administrative fines ordinarily apply to controllers and processors. In limited circumstances, directors may face consequences under applicable national law, employment arrangements or governance duties, depending on the facts, and an organization may take actions such as terminating a director for failures connected with protecting personal data.
As explained earlier, GDPR applies once either Article 3 trigger is met: An EU establishment carries out the processing, or an organization outside the EU targets people in the Union with goods, services or behavioural monitoring. Once GDPR applies, your organization may be the controller of that data. As controller, you may use any number of processors to collect, modify or store data (for example, a payroll company for your employee salaries or a cloud-based technology company that manages your servers).
Once your organization operates as a controller for EU personal data, moving that data outside the EU raises its own requirements. GDPR restricts transfers to countries outside the EU unless a valid mechanism is in place, such as an adequacy decision, Standard Contractual Clauses or binding corporate rules. Many US companies rely on the EU-US Data Privacy Framework for this purpose. The European General Court upheld the framework's validity in September 2025, though additional legal challenges are expected and the European Commission must continue monitoring whether it still meets GDPR's standards.
Other nations across the world have recognized the need for greater, more modern regulation around data privacy. The original comparison identified six other countries with privacy laws similar to GDPR. Organizations should treat that comparison as a historical snapshot of privacy obligations at the time.
Data protection frameworks now exist across much of the world, and the old framing that only a handful of countries have GDPR-style laws no longer holds. Stricter privacy laws are becoming common across global economies. Organizations will need ongoing compliance programs. Notable examples include:
Several of these frameworks changed again within the past year alone: Brazil secured its EU adequacy decision in January 2026, the UK's Data (Use and Access) Act reached full effect by June 2026 and Japan's Cabinet approved a further amendment bill in April 2026. Organizations operating across these markets need a compliance program that tracks each regime on its own timeline rather than treating global privacy law as a single, static standard.
GDPR levies heavy financial penalties both for noncompliance and for a breach of data protection. Article 83 sets two tiers of administrative fines:
Supervisory authorities actively use these powers: a 2026 fines survey reported approximately €7.1 billion in cumulative GDPR fines issued through January 10, 2026, including approximately €1.2 billion in 2025 alone. That level of sustained enforcement is why compliance programs need recurring control testing rather than a one-time setup.
Among recent decisions, Ireland's Data Protection Commission fined TikTok €530 million in 2025 for unlawful transfers of European user data to China and for failing to tell users about those transfers. The consequences of noncompliance can include fines, processing restrictions or suspension, erasure orders, remediation costs and reputational damage.
Compliance is fully achievable if you put the right processes in place. A 2019 McKinsey report emphasized security controls and data management across all sectors, and automation also received particular attention. A GDPR compliance checklist should cover the following areas.
Those practices sit inside a broader accountability framework, one part of good regulatory compliance management generally. To demonstrate compliance end to end, work through the following steps:
A data controller determines the purpose and means by which data is processed. Controllers are subject to several requirements under EU law and must: comply with EU data protection law; implement strategies or processes to protect personal data; provide information about the data they hold; and formally enter into agreements with processors with clear instruction of how the data may be used.
A data processor is usually a third, external party, which processes personal data on behalf of the controller. Processors are typically subject to fewer direct obligations than controllers (previously they could avoid all direct liability), but processors now carry a level of direct responsibility, including maintaining a record of all processing, implementing security measures, informing the controller of any data breach and appointing a data protection officer where the Article 37 criteria are met.
Whichever category your organization falls under, the accountability principle applies to the relationship itself. Document the processing records, the data processing agreement, the security measures and any incidents and remediation, because a supervisory authority investigating either party will ask both to produce that evidence. It's critical to understand which category your organization or role falls under to fully comply with the GDPR.
Records, contracts, assessments and incident evidence often sit across legal, IT, HR and security teams. This makes consistent reporting difficult. "This 'partial integration' picture is important context for understanding why GCs may struggle to deliver the concise, forward looking risk narratives boards are asking for. Without a single, connected view, GCs must invest additional time to stitch together data manually, a theme that surfaced in survey comments about the broader risk environment and GRC practices," says Nithya Das, Chief Legal Officer and GM of Governance at Diligent. Centralized technology can connect those records to obligations and controls, but it does not replace the controller's legal accountability.
GDPR compliance programs often struggle with fragmented evidence, changing regulatory requirements, manual status reporting and difficulty demonstrating accountability. These challenges become more significant when departments or jurisdictions maintain separate records and control processes.
"The convergence of these factors keeps risk levels high and requires businesses to invest more in proactive compliance, risk management, scenario planning and governance frameworks," says Taras Lytovchenko, Chief Legal and Compliance Officer at Trinitex.
Regulatory Compliance Management from Diligent addresses those gaps by centralizing regulatory obligations, controls and evidence across departments. Its AI-powered compliance assistant analyzes regulatory updates and suggests controls, while a regulation library provides continuously updated content through partners. Teams can connect that content to a central controls repository.
For GDPR programs, records of processing, lawful bases, DPIAs, processor agreements and breach procedures can sit in one repository. Teams can map each obligation to a control and each control to supporting evidence. Automated status reporting, real-time monitoring and built-in reporting help identify missing evidence, communicate remediation priorities and demonstrate compliance to regulators.
Organizations managing GDPR alongside security and IT frameworks face an additional coordination challenge. Diligent IT Compliance supports multi-framework control mapping, automated evidence collection and board-ready dashboards. A control implemented once can be connected to several applicable frameworks. This reduces duplicate evidence requests and supports reporting based on current compliance data.
For growing organizations with lean compliance teams, centralized obligations and evidence reduce reliance on disconnected spreadsheets and manual status checks. Pre-IPO companies can use the same records, control mappings and reporting histories to support regulatory readiness. Large organizations can coordinate multi-jurisdictional programs across departments while maintaining consistent oversight.
Across every segment, the controller retains legal responsibility for GDPR compliance. Centralizing obligations, controls and evidence turns scattered compliance work into a single, defensible record for regulators, the board and the organization itself. Request a demo to see how Diligent supports GDPR compliance across your organization.
Being GDPR compliant means processing personal data lawfully under the regulation's principles and being able to demonstrate compliance under Article 5(2). Organizations need documented evidence such as processing records, DPIAs, consent records, processor agreements and incident logs; sound practices without supporting records may not satisfy the accountability requirement. Assign an owner to each obligation and regularly confirm that the related control and evidence remain current.
Accountability is shared across controllers, processors, leadership and the operational teams that apply controls. A data protection officer monitors compliance and advises where Article 37 requires one, but appointing a DPO does not transfer legal accountability from the controller or remove processors' direct statutory duties. Organizations should document who owns each processing activity, control, request workflow and incident response step, with clear escalation paths for unresolved issues.
Yes. GDPR applies when a US company offers goods or services to people in the EU or monitors their behaviour there. Companies caught by Article 3(2) generally need an EU representative under Article 27 unless an exception applies, and transfer mechanisms do not remove their baseline GDPR obligations. US companies should document whether the Article 3 and Article 27 tests apply and identify an owner for EU data processing and transfer requirements.
Authorities can impose fines of up to €10 million or 2% of worldwide annual turnover under the lower tier and €20 million or 4% under the higher tier, whichever is greater. They can also restrict processing, order erasure and require remediation, while trust and reputation may take longer to recover. Organizations should maintain an incident and remediation process that records decisions, owners, deadlines and evidence of corrective action.
In the UK, the Data (Use and Access) Act 2025 amended UK GDPR, with remaining data protection provisions in force by June 19, 2026. In the EU, the Commission's Digital Omnibus proposal had not been formally adopted, so organizations should track it without changing programs until the text is final. Maintain separate change logs for enacted requirements and proposals so controls are updated only when the applicable law changes.
Centralize GDPR obligations, controls and evidence with Regulatory Compliance Management. Schedule a demo.