Solutions / By Regulation

GDPR compliance for the modern enterprise.

Operationalize Articles 5–32 with consent, data mapping, DSR automation, DPIAs, and breach response — pre-built for EU and UK GDPR requirements.

GDPR at a glance
€20M
or 4% of global turnover, whichever is higher
72 hrs
to notify supervisory authority of a breach
1 month
to respond to a data subject request
27+
EU member-state supervisory authorities

What is GDPR?

Overview

The GDPR governs the processing of personal data of individuals in the EU and EEA, regardless of where the controller or processor is located. It establishes principles like lawfulness, purpose limitation, data minimization, accuracy, storage limitation, and accountability — and gives data subjects rights to access, rectify, erase, restrict, and port their data.

Who must comply

Typical applicability thresholds

  • Any organization processing EU/EEA residents' personal data
  • Controllers and processors, including non-EU entities
  • UK GDPR applies in parallel for UK data subjects
  • Public authorities and most large-scale processors need a DPO

Key requirements

What GDPR expects from your organization.

Lawful basis for processing

Identify and document a valid Art. 6 basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for every processing activity.

Records of Processing (ROPA)

Maintain Art. 30 records describing controllers, processors, purposes, categories of data, recipients, transfers, and retention.

Data subject rights

Honor access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making within one month.

DPIAs for high-risk processing

Conduct Data Protection Impact Assessments before processing likely to result in high risk to rights and freedoms.

International transfers

Use SCCs, adequacy decisions, or BCRs and complete Transfer Impact Assessments for transfers outside the EEA.

Breach notification

Notify the supervisory authority within 72 hours and affected data subjects without undue delay where high risk is likely.

Penalties & enforcement

What's at stake

Tiered administrative fines: up to €10M or 2% of global annual turnover for some infringements, and up to €20M or 4% of global annual turnover (whichever is higher) for the most serious — including violations of basic principles, data subject rights, and international transfer rules.

How Clarip helps

Operationalize GDPR on one platform.

Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for GDPR.

Consent & cookie compliance

  • IAB TCF v2.2 support
  • Geo-targeted EU/UK banners
  • Granular purpose & vendor consent

Data subject rights

  • Self-service portal in 40+ languages
  • ID verification workflows
  • One-month SLA monitoring

ROPA & data mapping

  • Auto-discover personal data
  • Living Art. 30 records
  • Cross-border transfer registry

DPIAs & TIAs

  • Templated DPIA & TIA workflows
  • Risk scoring & mitigations
  • Approval chains with DPO sign-off

Breach response

  • 72-hour notification workflows
  • Authority & data subject templates
  • Regulator-ready incident records

Vendor & DPA management

  • Processor inventory
  • DPA & SCC tracking
  • Sub-processor change alerts
FAQ

GDPR compliance, answered.

Quick answers to the questions privacy, legal, and engineering teams most often ask about GDPR.

Yes. GDPR has extraterritorial scope: it applies to any organization that offers goods or services to people in the EU/EEA or monitors their behavior, regardless of where the organization is established (Art. 3).

Article 6 lists six lawful bases: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. You must identify and document the applicable basis before processing personal data, and special categories of data (Art. 9) require additional conditions.

A Data Protection Impact Assessment is required when processing is likely to result in a high risk to rights and freedoms — including systematic profiling, large-scale processing of special category data, or systematic monitoring of public areas (Art. 35). Many supervisory authorities publish lists of mandatory DPIA scenarios.

Generally within one month of receipt. You may extend by up to two further months for complex or numerous requests, with notification to the data subject within the original month.

A DPO is required if you are a public authority, your core activities involve regular and systematic large-scale monitoring of data subjects, or you process special categories of data on a large scale (Art. 37). Many organizations appoint one voluntarily as best practice.

Clarip provides cookie consent (IAB TCF v2.2), DSR automation, automated ROPA generation, DPIA and TIA workflows, breach response with 72-hour notification templates, and vendor/DPA management — giving DPOs a single audit-ready system of record.

Get GDPR-ready with Clarip.

Book a 30-minute walkthrough and a custom gap assessment against GDPR requirements — mapped to the systems and vendors you already use.