← All frameworks

GDPR

28 controls · Regulation (EU) 2016/679

The rules for handling personal information about people in Europe. There is no certificate to earn and no auditor to satisfy - what GDPR asks is that you can explain what you hold, why, and what you would do if it leaked.

Principles and Lawful Basis

Art. 5(1)(a)Lawfulness, fairness and transparency

You have a proper reason for holding people's information, and you are open with them about what you do with it.

Personal data must be processed lawfully, fairly, and in a way the people it belongs to can see and understand.

Art. 5(1)(b)Purpose limitation

You use the information you collect for the reason you collected it, not for something else you thought of later.

Personal data must be collected for specified, explicit and legitimate purposes, and not used later in ways incompatible with those purposes.

Art. 5(1)(c)Data minimisation

You collect what you actually need and no more. Every extra field is something you have to protect and explain.

Personal data must be adequate, relevant, and limited to what is necessary for the purposes it is processed for.

Art. 5(1)(d)Accuracy

The information you hold about people is right, and when you find out it is wrong you fix it promptly.

Personal data must be accurate and kept up to date, and inaccurate data must be erased or corrected without delay.

Art. 5(1)(e)Storage limitation

You delete information once you no longer need it, and you can say how long you keep each kind and why.

Personal data must be kept in an identifiable form no longer than is necessary for the purposes it is processed for.

Art. 5(1)(f)Integrity and confidentiality

The information you hold is protected from being seen, changed or lost by people who should not have it.

Personal data must be processed with appropriate security, protecting against unauthorised or unlawful processing, accidental loss, destruction or damage.

Art. 5(2)Accountability

You can show how you meet the rules, not just believe that you do. Being right is not enough on its own.

The organisation is responsible for the principles above and must be able to demonstrate compliance with them.

Art. 6Lawful basis for processing

For each thing you do with people's information, you know which of the six legal reasons allows it, and you wrote it down.

Processing is lawful only where at least one of the six bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests.

Art. 7Conditions for consent

Where you rely on someone agreeing, they agreed clearly, you can prove it, and stopping is as easy as starting was.

Where processing relies on consent, the organisation must be able to show consent was given, requested clearly and separately, and be as easy to withdraw as to give.

Art. 9Special category data

Health and similarly sensitive information needs a stronger reason than ordinary information, and you know which one you rely on.

Processing of health, biometric, genetic, racial, political, religious, trade union or sex life data is prohibited unless a specific exception applies.

People's Rights

Art. 12Transparent communication and handling requests

When someone asks about their information, you answer in plain language, without charging them, and within a month.

Information and responses to rights requests must be provided concisely, in clear and plain language, free of charge, and generally within one month.

Art. 13-14Telling people what you hold

You have a privacy notice that says what you collect, why, how long you keep it, and who else sees it.

People must be told who is processing their data, why, on what basis, how long it is kept, and who it is shared with - whether the data came from them or elsewhere.

Art. 15Right of access

If someone asks for a copy of everything you hold on them, you can find it all and send it.

People have the right to confirm whether their data is being processed, to obtain a copy of it, and to be told the purposes, recipients and retention period.

Art. 16Right to rectification

If someone tells you their details are wrong, you can correct them everywhere you hold them.

People have the right to have inaccurate personal data corrected and incomplete data completed without undue delay.

Art. 17Right to erasure

If someone asks you to delete their information and you have no reason to keep it, you can actually delete it, including from backups.

People have the right to have their data deleted where it is no longer needed, consent is withdrawn, or it was processed unlawfully, subject to defined exceptions.

Art. 18Right to restriction

You can put someone's information on hold - kept but not used - while a dispute about it is sorted out.

People have the right to have processing paused while accuracy is contested or a decision on erasure or objection is pending.

Art. 20Right to data portability

Someone can ask for their information in a normal file format they could hand to a competitor of yours.

Where processing rests on consent or a contract and is carried out by automated means, people may receive their data in a structured, commonly used, machine-readable format.

Art. 21Right to object

People can tell you to stop, and for marketing you stop every time, with no argument and no conditions.

People may object to processing based on legitimate interests or public task, and may object to direct marketing at any time with no exceptions.

Accountability and Records

Art. 24Responsibility of the controller

You have measures in place that match the risk of what you hold, and you revisit them rather than setting them once.

The organisation must implement appropriate technical and organisational measures, proportionate to risk, and review and update them.

Art. 25Data protection by design and by default

Privacy is considered when you set something up, not bolted on afterwards, and the safe setting is the one switched on by default.

Data protection measures must be built into processing from the outset, and by default only data necessary for each specific purpose should be processed.

Art. 28Contracts with processors

Every supplier who handles your customers' information for you has a contract saying what they may do with it.

Where another organisation processes data on your behalf, a written contract must set out the subject matter, duration, purpose, and the processor's obligations.

Art. 30Records of processing activities

You keep a list of what personal information you hold, why, and who it goes to. It is the first thing a regulator asks for.

The organisation must maintain a record of processing activities, including purposes, categories of people and data, recipients, transfers, and retention periods.

Art. 35Data protection impact assessment

Before doing something risky with people's information, you think through the harm it could cause and write down what you decided.

Where processing is likely to result in a high risk to people's rights, the organisation must assess that impact before starting.

Art. 37Data protection officer

You have checked whether you need a formal data protection officer, and you know why you do or do not.

A data protection officer must be designated where processing is carried out by a public authority, or where core activities involve large-scale regular monitoring or large-scale special category data.

Security and Breaches

Art. 32Security of processing

Your security matches the sensitivity of what you hold, and you test that it works rather than assuming it does.

Appropriate technical and organisational security must be in place given the risk, including as appropriate encryption, resilience, and regular testing of effectiveness.

Art. 33Reporting a breach to the regulator

If personal information is exposed, you can report it to the regulator within 72 hours, and you know who makes that call.

A personal data breach must be reported to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to risk people's rights.

Art. 34Telling the people affected

If a breach could seriously affect the people involved, you tell them directly and plainly, not only the regulator.

Where a breach is likely to result in a high risk to people's rights and freedoms, those people must be told without undue delay, in clear and plain language.

Sending Data Abroad

Art. 44-46Transfers outside the EEA

You know which of your suppliers store information outside Europe, and there is something in writing covering each of them.

Personal data may only be transferred outside the EEA where the destination is covered by an adequacy decision or appropriate safeguards such as standard contractual clauses are in place.

What this page is

Our own summary of what each control area covers, written to be read by someone without a compliance background. It is not the text of the standard, and it is not a substitute for it - where a framework is a copyrighted document, you will need your own copy. Nothing here is legal advice or an assurance that following it satisfies an auditor.