GDPR: General Data Protection Regulation
The reference framework for data protection in the EU since 2018 — with a record of processing activities, a 72-hour breach-notification duty, comprehensive data-subject rights, and fines of up to 4% of global annual turnover.
The oldest, but still central, building block of EU compliance.
Regulation (EU) 2016/679 (the "GDPR") regulates the processing of personal data uniformly across the EU and applies directly in all member states — to practically any organisation that processes the personal data of people in the EU, regardless of where it is based.
Central building blocks include the record of processing activities (ROPA, Art. 30), a data-protection impact assessment (DPIA, Art. 35) where processing is likely to result in high risk, comprehensive data-subject rights (including access, erasure, and data portability), and technical and organisational measures (TOMs, Art. 32).
Compared with NIS2, DORA, and the AI Act, the GDPR has been fully applicable since 2018 and is primarily refined through guidelines from the European Data Protection Board (EDPB) and national supervisory authorities (in Austria: the Datenschutzbehörde, DSB).
Key deadlines
GDPR enters into force
Regulation (EU) 2016/679 is published in the Official Journal; a two-year transition period follows before full applicability.
GDPR fully applicable
Art. 99(2): the regulation's EU-wide application date — still in force today, with no further transition periods.
Notification of personal-data breaches
Art. 33(1): notification to the supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it".
Up to €20 million or 4% of global annual turnover
Art. 83(5) (more severe infringements, incl. core principles, data-subject rights, international transfers); Art. 83(4) sets a lower framework of up to €10 million / 2% for other infringements, including certain notification-duty failures.
What the GDPR actually requires.
Record of processing activities (ROPA, Art. 30)
Documentation of all personal-data processing activities — purposes, categories, recipients, retention periods, references to TOMs.
Data-protection impact assessment (DPIA, Art. 35)
Where processing is likely to result in high risk to data subjects: a structured assessment of risk, necessity, and proportionality before processing begins.
Personal-data breach notification
Notification to the supervisory authority within 72 hours (Art. 33); where high risk exists, also notification to affected individuals (Art. 34).
Data-subject rights (DSAR)
Access, rectification, erasure, restriction, data portability, and objection — generally to be answered within one month (Art. 12(3)).
ROPA, DPIA, and DSAR — seamlessly linked to ISO 27001.
The ReportAct GDPR Framework Pack maintains a record of processing activities per Art. 30, supports data-protection impact assessments per Art. 35 with AI-assisted drafting, and provides a public DSAR inbox for data-subject requests (/dsar/[slug]).
The TOM assessment per Art. 32 is directly linked to the ISO/IEC 27001 control catalogue — technical and organisational measures don't need to be documented twice.
In the event of a notifiable personal-data breach, the sealed evidence chain provides proof of which measure was in force when — relevant for the 72-hour deadline and the documentation duty under Art. 33(5).
Product/positioning statement, not legal advice.
Read the originals
ReportAct is not a consultancy. This page does not constitute legal advice. The fine framework under Art. 83 is two-tiered: Art. 83(4) (up to €10 million / 2%) and Art. 83(5) (up to €20 million / 4%) apply to different kinds of infringements — which framework applies in a given case depends on the specific infringement. Our Terms of Service apply.
ROPA, DPIA, DSAR — sealed, not just claimed.
Start right away with your record of processing activities — including DSAR inbox and TOM assessment.