Frameworks
GDPR — General Data Protection Regulation
Privacy compliance for anyone with users in Europe — which is nearly everyone.
Book a demoGDPR applies to anyone processing personal data of people in the EU, wherever the company sits. Eight years of enforcement have made the pattern clear: regulators reward organizations that can show their work — records, legal bases, response processes — and punish those improvising after a complaint.
The operating obligations
Beyond principles, GDPR demands operations: records of processing activities (Article 30), a lawful basis for every processing purpose, data protection impact assessments for risky processing, honored subject rights within a month, processor agreements with your vendors, and 72-hour breach notification. Each is a workflow, not a paragraph in a policy.
GDPR meets AI
Automated decision-making, profiling, and AI training data sit squarely inside GDPR — Article 22 rights, DPIA triggers, transparency duties. If you're deploying AI on personal data, your GDPR and AI-governance programs are one conversation, and the EU AI Act only tightens the weave.
How Compriska helps
Compriska keeps the evidence layer current: processing records, DPIA workflows, subject-request tracking with deadlines, processor status in vendor management, and incident timelines that count the 72 hours for you — all mapped so GDPR work reinforces ISO 27001 and ISO 42001.
Frequently asked questions
Do we need a Data Protection Officer?
Only in specific cases — public authorities, large-scale systematic monitoring, or large-scale special-category data. Many companies appoint a privacy lead anyway; what matters is that the duties are owned.
Does GDPR apply to US companies?
Yes, if you offer goods or services to people in the EU or monitor their behavior. Server location doesn't matter; the people whose data you process do.
Other frameworks
Automate GDPR with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo