Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

GDPR compliance: what is it and are you fully compliant?

August 21, 2026
24 min read
stars circling the text reading GRC with the world lightly displayed as a backdrop

In this article

  • Intro
  • What is the data protection law?
  • What is GDPR?
  • The seven principles of GDPR
  • What is involved in GDPR compliance?
  • What is sensitive personal data and what is meant by personal data?
  • How does GDPR affect me?
  • How does data protection affect my board?
  • How does GDPR affect my company?
  • Are there any other privacy laws like GDPR?
  • Failure to comply
  • How can I ensure my company is fully GDPR-compliant?
  • Are you a data processor or data controller?
  • How technology accelerates GDPR compliance
  • GDPR compliance FAQs
The Diligent team

The Diligent team

GRC trends and insights

An organization is GDPR compliant when it meets the General Data Protection Regulation's requirements for handling personal data and can demonstrate that it does. Both halves matter: the GDPR compliant meaning covers maintaining evidence of compliance as well as the compliant practices themselves.

According to What Directors Think 2026 by Diligent Institute and Corporate Board Member, 40% of public company directors expect data privacy and protection to demand the greatest board attention in 2026, second only to AI and technology regulation.

For boards, that makes reliable reporting on privacy ownership, controls, incidents and remediation an immediate oversight requirement.

This guide covers what GDPR compliance requires and how to build toward it:

  • What it means to be GDPR compliant and who GDPR applies to inside and outside the EU
  • The GDPR data protection principles and the difference between personal data and special category data
  • How controllers, processors and data protection officers divide responsibility and demonstrate compliance
  • The penalties and operational consequences of noncompliance

GDPR stands for the General Data Protection Regulation. The European Commission proposed it, and the European Parliament and the Council of the European Union adopted it, replacing the EU Data Protection Directive. In the United Kingdom, the Data Protection Act 2018 replaced the Data Protection Act 1998 and supplemented EU GDPR before Brexit.

GDPR protects people in the EU and can apply to organizations outside it. Organizations that do business in the EU or have EU customers face numerous obligations, and controllers and processors risk administrative fines and corrective orders for failing to meet them. Directors may face consequences under applicable national law or governance duties in limited circumstances, depending on the facts.

Whether you are a resident of the European Union, represent an organization established there or serve on the board of an organization that offers goods or services to people in the EU, GDPR's data protection rules will likely affect you directly. With extensive provisions outlining the core tenets of data protection and the responsibilities of organizations of any size that store any kind of data, many organizations are still trying to get their heads around the regulation years after its official implementation.

What is the data protection law?

Current data protection law grew out of what it replaced. The UK's original Data Protection Act 1998 gave way to GDPR, which the UK now enforces as its own separate framework alongside continued updates to domestic law.

The Data Protection Act 1998

Before GDPR, the Data Protection Act 1998 was a United Kingdom Act of Parliament that was modeled after the 1995 EU directive. Affecting corporation or company use rather than personal use, the data protection act fell into eight areas of protection with various exemptions.

The act defined personal data as any data that can identify a singular individual in any manner. The act also outlined that individuals have the right to Subject Access Requests (for a fee) from any organization that holds data on that individual.

The complications of the act derived from its unwieldy size. As it was a large and complex law, many organizations were unsure of what its aims or primary principles were. The enforcement of the Data Protection Act was also challenging, as it did not extend throughout the full European Union or hold global entities responsible and had fewer protections on personal data than on sensitive personal data. With the expansion of the Internet and the advent of cloud-based technologies, enforcement for data centers outside of the U.K. became equally problematic.

From EU directive to GDPR

The General Data Protection Regulation replaced the 1995 EU directive with a directly applicable regulation that provided stricter enforcement and broader territorial reach. GDPR was adopted in April 2016. Organizations should use that date to distinguish adoption of the regulation from the point at which its requirements became compulsory.

The law became compulsory on May 25, 2018. Current policies, contracts and controls should reflect GDPR rather than the superseded EU directive. Since Brexit, personal data in the UK is governed by UK GDPR and the Data Protection Act 2018, not the repealed 1998 Act.

UK GDPR update: UK GDPR remains a separate framework from EU GDPR, enforced by the Information Commissioner's Office (ICO) alongside the Data Protection Act 2018. The maximum fine under UK GDPR is £17.5 million or 4% of annual worldwide turnover, whichever is higher, according to ICO fining guidance.

The Data (Use and Access) Act 2025 amended UK data protection law, with its remaining data protection provisions taking effect by June 19, 2026, per the ICO DUAA summary. Among the changes is a list of "recognised legitimate interests," a UK lawful basis covering purposes such as crime prevention and safeguarding that does not require the usual balancing test, according to the UK government factsheet. Organizations operating in both the UK and the EU need to track the two regimes separately.

What is GDPR?

GDPR compliance means meeting the regulation's requirements for collecting, using, sharing, retaining and protecting personal data and maintaining evidence that demonstrates compliance. The evidence obligation comes from Article 5(2) accountability, which states that the controller "shall be responsible for, and be able to demonstrate compliance with" the data protection principles. As the GDPR overview explains, an organization that follows the rules but cannot document how it follows them has not finished the job.

GDPR contains 99 articles that outline the core tenets of data protection and the responsibilities of organizations that process personal data, so organizations should map the articles relevant to their activities to named owners, controls and evidence. GDPR is a regulation that seeks to strengthen the protection of individuals' personal data, and it encompasses the full European Union while addressing personal data outside the borders of the EU as well.

Under Article 3, the regulation applies on two triggers: processing carried out in the context of an establishment in the EU, regardless of where the processing itself takes place, and processing by organizations outside the EU that offer goods or services to people in the Union or monitor their behaviour there. A United States-based company that markets to customers in the EU is just as accountable for a breach of data as an organization physically located in the EU.

The European Commission designed GDPR to harmonize data privacy laws across the EU's 27 member countries and strengthen rights and protections for individuals in those states. The regulation responded to shifting public attitudes toward privacy after the earlier EU Data Protection Directive fell behind the internet era and modern data collection practices.

The seven principles of GDPR

GDPR sets out seven key principles. Organizations should use these principles as the foundation for policies, control design and compliance evidence. These include:

  1. Lawfulness, fairness and transparency: Organizations must be clear about the data and how it's going to be collected.
  2. Purpose limitation: Organizations must have a legitimate reason for collecting and processing personal data. Further processing may be permitted when it is compatible with the original purpose or supported by another lawful basis.
  3. Data minimization: Data must be "adequate, relevant, and limited to what is necessary concerning the purposes for which they are processed." Organizations should collect only the data needed for a specified purpose.
  4. Accuracy: All data must be fit for purpose and up to date, meaning organizations should regularly review the data they have on file. Individuals can also have their say on the accuracy, and if they request that inaccurate or incomplete data be erased or rectified, this has to be addressed within one calendar month.
  5. Storage limitation: The GDPR does not state how long you can keep personal data but if you no longer need it for the same purpose for which it was originally obtained, it should be deleted unless new permissions are granted.
  6. Integrity and confidentiality: Dealing exclusively with security, this principle focuses on protecting the data you hold, ensuring all appropriate measures are in place to do so. This includes protection from external cybersecurity threats such as phishing, malware or data theft. Poor security could impact your GDPR compliance.
  7. Accountability: A principle introduced under GDPR specifically, the accountability principle states that organizations must take responsibility for the data they hold and demonstrate their compliance with the six previously mentioned principles.

The ICO advises that these data protection principles should be at the heart of an organization's approach to data.

What is involved in GDPR compliance?

Individuals have the right to know how their data is handled, stored and regulated. Organizations that capture or store personal data are responsible for tracking it.

Under Article 37, GDPR requires organizations to appoint a data protection officer (DPO) in three situations: the processing is carried out by a public authority or body; the organization's core activities require regular and systematic monitoring of data subjects on a large scale; or its core activities involve large-scale processing of special categories of data or data relating to criminal convictions. Outside those triggers, appointment is voluntary. Where one is in place, the role resembles a compliance officer's, overseeing IT processes, information privacy issues, data storage and protection, cyberattacks and breaches of data protection.

The "Digital Single Market" relies on all EU members following the regulation. Each EU member has created its own Independent Supervisory Authority for complaints, concerns and enforcement. An organization has a "one-stop-shop" that is responsible for supervising all behaviors under the regulation, regardless of how many locations it has within the EU. This limits confusion between different laws in various countries within the EU and on the consumer side as well.

What is sensitive personal data and what is meant by personal data?

GDPR allows regulators the opportunity to refine and modernize the definitions of data as it relates to an individual. The regulation's formal term for what is commonly called sensitive personal data is "special categories of personal data." Both ordinary personal data and special category data are protected by GDPR. Unlawful processing of special category data may breach Article 9 and expose an organization to the higher Article 83 fine tier.

Personal data is any data that relates to a living individual that can assist in the identification of the individual. For example, phone numbers, addresses of current or former domiciles, email addresses or digital data like non-anonymized cookies or IP addresses. Special categories of personal data include details of a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data or data concerning sex life or sexual orientation. Data relating to criminal convictions and offences receives separate protection under Article 10.

How does GDPR affect me?

GDPR gives individuals distinct rights over their personal data. Some of these rights include:

  • "The right to be forgotten," also referred to as the right to erasure, lets an individual ask a company to remove personal data when the conditions in Article 17 are met, subject to exceptions such as legal obligations and public-interest grounds.
  • An individual can ask that their email is removed from mailing lists or request removal of other personal data when the applicable conditions are met. An organization is responsible for assessing the request, applying any relevant exceptions and documenting how it responded.
  • Personal data must be protected by default. Pseudonymization processes personal data so it cannot be attributed to a person without additional information, which must be kept separately and protected. Data masking is a related but distinct technique that changes a data value, such as a credit card number, while preserving its format.
  • Notification of a personal data breach: Under Article 33, controllers must generally notify the relevant supervisory authority within 72 hours of a breach, unless it's unlikely to risk individuals' rights and freedoms. Under Article 34, affected individuals must be informed without undue delay when that risk is high, as the GDPR breach checklist sets out.

Meeting these rights requires organizations to locate personal data quickly, apply exceptions correctly and document every response.

How does data protection affect my board?

GDPR significantly affects board responsibilities for data protection and information privacy. Organizations that meet the Article 37 criteria must appoint a data protection officer. Finding someone with the skillset to mitigate risk and effectively manage compliance and legal issues is not an easy task. Compliance software can help teams complete internal audits and identify gaps as part of their risk management strategy.

Privacy compliance requires standing board oversight. Boards need recurring, reliable reporting on privacy ownership, controls, incidents and remediation so directors can test whether privacy receives appropriate attention in agendas, risk reporting and committee oversight and challenge gaps before they become enforcement or operational problems.

Board oversight of privacy is shifting toward continuous governance rather than periodic updates. "It's not surprising that boards are seeking expert advice and further training. Boards are paying attention to AI, data privacy, sanctions and tariffs, which represent some of the most technical and rapidly evolving regulatory landscapes boards have ever faced," says Kristy Grant-Hart, Vice President and Head of Advisory Services at Spark Compliance, a Diligent brand.

The board of directors also plays a role in data protection that can create company-wide liabilities and governance consequences. GDPR administrative fines ordinarily apply to controllers and processors. In limited circumstances, directors may face consequences under applicable national law, employment arrangements or governance duties, depending on the facts, and an organization may take actions such as terminating a director for failures connected with protecting personal data.

How does GDPR affect my company?

As explained earlier, GDPR applies once either Article 3 trigger is met: An EU establishment carries out the processing, or an organization outside the EU targets people in the Union with goods, services or behavioural monitoring. Once GDPR applies, your organization may be the controller of that data. As controller, you may use any number of processors to collect, modify or store data (for example, a payroll company for your employee salaries or a cloud-based technology company that manages your servers).

Once your organization operates as a controller for EU personal data, moving that data outside the EU raises its own requirements. GDPR restricts transfers to countries outside the EU unless a valid mechanism is in place, such as an adequacy decision, Standard Contractual Clauses or binding corporate rules. Many US companies rely on the EU-US Data Privacy Framework for this purpose. The European General Court upheld the framework's validity in September 2025, though additional legal challenges are expected and the European Commission must continue monitoring whether it still meets GDPR's standards.

Are there any other privacy laws like GDPR?

Other nations across the world have recognized the need for greater, more modern regulation around data privacy. The original comparison identified six other countries with privacy laws similar to GDPR. Organizations should treat that comparison as a historical snapshot of privacy obligations at the time.

Data protection frameworks now exist across much of the world, and the old framing that only a handful of countries have GDPR-style laws no longer holds. Stricter privacy laws are becoming common across global economies. Organizations will need ongoing compliance programs. Notable examples include:

  • United Kingdom: UK GDPR closely mirrors EU GDPR but is a separate framework enforced by the ICO. The framework was amended by the Data (Use and Access) Act 2025, as covered in the callout earlier in this article.
  • Australia: Similar to the EU's GDPR, the Privacy Amendment (Notifiable Data Breaches) came into force in 2018. Eligible organizations must disclose qualifying data breaches to affected individuals and the relevant regulator and may face penalties for failing to comply.
  • Brazil: Officially introduced in 2020, Brazil's Lei Geral de Proteção de Dados (LGPD) unified more than 40 different statutes that previously governed personal data, with an approach similar to GDPR's. On January 26, 2026, the European Commission adopted an adequacy decision confirming Brazil provides an adequate level of protection for personal data transferred from the EU.
  • Japan: Japan's Act on the Protection of Personal Information applies to both foreign and domestic companies that process the data of Japanese citizens. Amendments enacted in 2020 took effect on April 1, 2022, according to DLA Piper's tracker, and a further amendment bill approved by Japan's Cabinet in April 2026 covers areas such as children's data and biometric information.
  • South Korea: As the longest-standing privacy act in this list, South Korea's Personal Information Protection Act has been in effect since 2011. It includes regulation around data consent, the scope of applicable data and limitations around justification.
  • Thailand: The Thailand Personal Data Protection Act (PDPA) has been effective since June 2022, with a broad definition of personal data and a legal-basis requirement similar to GDPR's. According to the Data Protection Report, a violation could result in "civil liability, criminal liability, and administrative fines."
  • USA: Every state has its own data privacy laws, including the California Consumer Privacy Act (CCPA), which came into force on January 1, 2020. It states that businesses must use "reasonable security procedures and practices" to protect personal information or risk legal action should a customer's data become exposed in a breach.

Several of these frameworks changed again within the past year alone: Brazil secured its EU adequacy decision in January 2026, the UK's Data (Use and Access) Act reached full effect by June 2026 and Japan's Cabinet approved a further amendment bill in April 2026. Organizations operating across these markets need a compliance program that tracks each regime on its own timeline rather than treating global privacy law as a single, static standard.

Failure to comply

GDPR levies heavy financial penalties both for noncompliance and for a breach of data protection. Article 83 sets two tiers of administrative fines:

  • Tier 1: up to €10 million or 2% of total worldwide annual turnover, whichever is higher, for infringements of controller and processor obligations such as security measures, records and impact assessments
  • Tier 2: up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for infringements of the basic processing principles, data subjects' rights and international transfer rules

Supervisory authorities actively use these powers: a 2026 fines survey reported approximately €7.1 billion in cumulative GDPR fines issued through January 10, 2026, including approximately €1.2 billion in 2025 alone. That level of sustained enforcement is why compliance programs need recurring control testing rather than a one-time setup.

Among recent decisions, Ireland's Data Protection Commission fined TikTok €530 million in 2025 for unlawful transfers of European user data to China and for failing to tell users about those transfers. The consequences of noncompliance can include fines, processing restrictions or suspension, erasure orders, remediation costs and reputational damage.

How can I ensure my company is fully GDPR-compliant?

Compliance is fully achievable if you put the right processes in place. A 2019 McKinsey report emphasized security controls and data management across all sectors, and automation also received particular attention. A GDPR compliance checklist should cover the following areas.

  • Data encryption: Unencrypted data is easy to read if a breach occurs, so encryption is a practical safeguard even though GDPR does not mandate a specific method. Data stored in the cloud needs both at-rest encryption, which protects data held on the server, and in-transit encryption, which protects data as it moves between systems. Limit access to only those who need it.
  • Proactiveness: Prevention is better than cure and GDPR compliance requires ongoing attention. Continuously monitor your data, evaluate any cybersecurity vulnerabilities and implement good cyber hygiene practices to reduce the risk of a breach. Sound data privacy risk management protects customers as well as the compliance program.
  • Relevant data only: GDPR regulates all data that is identifiable (the full list appears earlier in this blog). Make sure that you are holding only the most necessary data for your organization and delete any that may no longer be serving a purpose.
  • A security-first culture: GDPR responsibilities extend across departments beyond IT and marketing. Each department must understand GDPR, what it is and the steps needed to put security first. Invest in training and keep data protection at the forefront of conversations across the board.
  • Clear responsibilities: Everyone who handles personal data needs to understand their GDPR duties. Whether you're a data controller, a data processor or a data protection officer, the GDPR defines your responsibility and the evidence you need to maintain.

Those practices sit inside a broader accountability framework, one part of good regulatory compliance management generally. To demonstrate compliance end to end, work through the following steps:

  • Map personal data and maintain records of processing activities. Where Article 30 applies, it requires records covering purposes, data categories, recipients, transfers, retention periods and security measures.
  • Document a lawful basis for each processing activity. Article 6 sets six lawful bases; identify one before processing begins, and record balancing assessments where you rely on legitimate interests. This prevents teams from treating lawful basis as a retrospective paperwork exercise.
  • Keep privacy notices accurate and accessible. Articles 12-14 require concise, plain-language information at the point of collection.
  • Establish procedures for data subject requests. Build workflows to handle access, rectification, erasure, restriction, portability and objection requests within one calendar month. Assign owners and escalation paths so the response period can be met and evidenced.
  • Sign appropriate data processing agreements with processors. Article 28 requires a written contract with every processor, with the same obligations flowing down to sub-processors.
  • Conduct data protection impact assessments for high-risk processing. Article 35 requires a DPIA before any processing likely to result in a high risk to individuals, especially where new technologies are involved.
  • Appoint a data protection officer when the Article 37 criteria apply, as described earlier in this article.
  • Document controls, decisions, incidents and remediation. Article 5(2) accountability means keeping the evidence, DPIAs, lawful-basis assessments, contracts, training records and incident logs ready to produce on request.

Build a practical policy

Use this privacy policy template as a structured starting point for documenting how your organization collects, uses, retains and protects personal data.

Are you a data processor or data controller?

A data controller determines the purpose and means by which data is processed. Controllers are subject to several requirements under EU law and must: comply with EU data protection law; implement strategies or processes to protect personal data; provide information about the data they hold; and formally enter into agreements with processors with clear instruction of how the data may be used.

A data processor is usually a third, external party, which processes personal data on behalf of the controller. Processors are typically subject to fewer direct obligations than controllers (previously they could avoid all direct liability), but processors now carry a level of direct responsibility, including maintaining a record of all processing, implementing security measures, informing the controller of any data breach and appointing a data protection officer where the Article 37 criteria are met.

Whichever category your organization falls under, the accountability principle applies to the relationship itself. Document the processing records, the data processing agreement, the security measures and any incidents and remediation, because a supervisory authority investigating either party will ask both to produce that evidence. It's critical to understand which category your organization or role falls under to fully comply with the GDPR.

Records, contracts, assessments and incident evidence often sit across legal, IT, HR and security teams. This makes consistent reporting difficult. "This 'partial integration' picture is important context for understanding why GCs may struggle to deliver the concise, forward looking risk narratives boards are asking for. Without a single, connected view, GCs must invest additional time to stitch together data manually, a theme that surfaced in survey comments about the broader risk environment and GRC practices," says Nithya Das, Chief Legal Officer and GM of Governance at Diligent. Centralized technology can connect those records to obligations and controls, but it does not replace the controller's legal accountability.

See compliance in one view

Discover how centralized controls and evidence can improve compliance reporting and oversight.

How technology accelerates GDPR compliance

GDPR compliance programs often struggle with fragmented evidence, changing regulatory requirements, manual status reporting and difficulty demonstrating accountability. These challenges become more significant when departments or jurisdictions maintain separate records and control processes.

"The convergence of these factors keeps risk levels high and requires businesses to invest more in proactive compliance, risk management, scenario planning and governance frameworks," says Taras Lytovchenko, Chief Legal and Compliance Officer at Trinitex.

Regulatory Compliance Management from Diligent addresses those gaps by centralizing regulatory obligations, controls and evidence across departments. Its AI-powered compliance assistant analyzes regulatory updates and suggests controls, while a regulation library provides continuously updated content through partners. Teams can connect that content to a central controls repository.

For GDPR programs, records of processing, lawful bases, DPIAs, processor agreements and breach procedures can sit in one repository. Teams can map each obligation to a control and each control to supporting evidence. Automated status reporting, real-time monitoring and built-in reporting help identify missing evidence, communicate remediation priorities and demonstrate compliance to regulators.

Organizations managing GDPR alongside security and IT frameworks face an additional coordination challenge. Diligent IT Compliance supports multi-framework control mapping, automated evidence collection and board-ready dashboards. A control implemented once can be connected to several applicable frameworks. This reduces duplicate evidence requests and supports reporting based on current compliance data.

For growing organizations with lean compliance teams, centralized obligations and evidence reduce reliance on disconnected spreadsheets and manual status checks. Pre-IPO companies can use the same records, control mappings and reporting histories to support regulatory readiness. Large organizations can coordinate multi-jurisdictional programs across departments while maintaining consistent oversight.

Across every segment, the controller retains legal responsibility for GDPR compliance. Centralizing obligations, controls and evidence turns scattered compliance work into a single, defensible record for regulators, the board and the organization itself. Request a demo to see how Diligent supports GDPR compliance across your organization.

GDPR compliance FAQs

What does it mean to be GDPR compliant?

Being GDPR compliant means processing personal data lawfully under the regulation's principles and being able to demonstrate compliance under Article 5(2). Organizations need documented evidence such as processing records, DPIAs, consent records, processor agreements and incident logs; sound practices without supporting records may not satisfy the accountability requirement. Assign an owner to each obligation and regularly confirm that the related control and evidence remain current.

Who is responsible for ensuring GDPR compliance?

Accountability is shared across controllers, processors, leadership and the operational teams that apply controls. A data protection officer monitors compliance and advises where Article 37 requires one, but appointing a DPO does not transfer legal accountability from the controller or remove processors' direct statutory duties. Organizations should document who owns each processing activity, control, request workflow and incident response step, with clear escalation paths for unresolved issues.

Does GDPR apply to US companies?

Yes. GDPR applies when a US company offers goods or services to people in the EU or monitors their behaviour there. Companies caught by Article 3(2) generally need an EU representative under Article 27 unless an exception applies, and transfer mechanisms do not remove their baseline GDPR obligations. US companies should document whether the Article 3 and Article 27 tests apply and identify an owner for EU data processing and transfer requirements.

What happens if an organization is not GDPR compliant?

Authorities can impose fines of up to €10 million or 2% of worldwide annual turnover under the lower tier and €20 million or 4% under the higher tier, whichever is greater. They can also restrict processing, order erasure and require remediation, while trust and reputation may take longer to recover. Organizations should maintain an incident and remediation process that records decisions, owners, deadlines and evidence of corrective action.

Is GDPR changing in 2026?

In the UK, the Data (Use and Access) Act 2025 amended UK GDPR, with remaining data protection provisions in force by June 19, 2026. In the EU, the Commission's Digital Omnibus proposal had not been formally adopted, so organizations should track it without changing programs until the text is final. Maintain separate change logs for enacted requirements and proposals so controls are updated only when the applicable law changes.

Centralize GDPR obligations, controls and evidence with Regulatory Compliance Management. Schedule a demo.