Yes. GDPR has extraterritorial scope: it applies to any organization that offers goods or services to people in the EU/EEA or monitors their behavior, regardless of where the organization is established (Art. 3).
Solutions / By Regulation
Operationalize Articles 5–32 with consent, data mapping, DSR automation, DPIAs, and breach response — pre-built for EU and UK GDPR requirements.
What is GDPR?
The GDPR governs the processing of personal data of individuals in the EU and EEA, regardless of where the controller or processor is located. It establishes principles like lawfulness, purpose limitation, data minimization, accuracy, storage limitation, and accountability — and gives data subjects rights to access, rectify, erase, restrict, and port their data.
Typical applicability thresholds
Key requirements
Identify and document a valid Art. 6 basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for every processing activity.
Maintain Art. 30 records describing controllers, processors, purposes, categories of data, recipients, transfers, and retention.
Honor access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making within one month.
Conduct Data Protection Impact Assessments before processing likely to result in high risk to rights and freedoms.
Use SCCs, adequacy decisions, or BCRs and complete Transfer Impact Assessments for transfers outside the EEA.
Notify the supervisory authority within 72 hours and affected data subjects without undue delay where high risk is likely.
Penalties & enforcement
Tiered administrative fines: up to €10M or 2% of global annual turnover for some infringements, and up to €20M or 4% of global annual turnover (whichever is higher) for the most serious — including violations of basic principles, data subject rights, and international transfer rules.
How Clarip helps
Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for GDPR.
Quick answers to the questions privacy, legal, and engineering teams most often ask about GDPR.
Yes. GDPR has extraterritorial scope: it applies to any organization that offers goods or services to people in the EU/EEA or monitors their behavior, regardless of where the organization is established (Art. 3).
Article 6 lists six lawful bases: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. You must identify and document the applicable basis before processing personal data, and special categories of data (Art. 9) require additional conditions.
A Data Protection Impact Assessment is required when processing is likely to result in a high risk to rights and freedoms — including systematic profiling, large-scale processing of special category data, or systematic monitoring of public areas (Art. 35). Many supervisory authorities publish lists of mandatory DPIA scenarios.
Generally within one month of receipt. You may extend by up to two further months for complex or numerous requests, with notification to the data subject within the original month.
A DPO is required if you are a public authority, your core activities involve regular and systematic large-scale monitoring of data subjects, or you process special categories of data on a large scale (Art. 37). Many organizations appoint one voluntarily as best practice.
Clarip provides cookie consent (IAB TCF v2.2), DSR automation, automated ROPA generation, DPIA and TIA workflows, breach response with 72-hour notification templates, and vendor/DPA management — giving DPOs a single audit-ready system of record.
Book a 30-minute walkthrough and a custom gap assessment against GDPR requirements — mapped to the systems and vendors you already use.