EU Regulation 2016/679

GDPR Readiness — Evidence-Linked

EU Regulation 2016/679 — General Data Protection Regulation. OneComply helps teams manage privacy evidence, breach workflows, DSR tracking, and mapped controls alongside DORA operational-resilience work.

What is GDPR?

The General Data Protection Regulation (GDPR) is the EU's comprehensive data protection framework that governs how organisations collect, process, store, and transfer personal data of individuals in the European Union.

GDPR applies to any organisation worldwide that processes personal data of EU residents, regardless of where the organisation is based. It grants data subjects extensive rights including access, erasure, portability, and the right to object to processing.

Non-compliance can result in fines of up to €20 million or 4% of annual global turnover — whichever is higher — making it one of the most heavily enforced regulations globally.

43

Controls

99

Articles

9

Data Subject Rights

Workflow acceleration examples

Before vs After — Operational Lift

Example improvements when privacy evidence, DSRs, breach workflows, and mapped controls are managed in one workspace. Actual timelines depend on customer data quality and review process.

WorkflowManual ProcessWith OneComplyTime Saved
Data Processing Inventory (ROPA)2–4 weeks (spreadsheets + interviews)30 minutes (guided wizard + templates)96%
Consent Audit Trail1–2 weeks per auditInstant (automated tracking)100%
Data Subject Request Handling5–10 days per request15 minutes (automated workflow)97%
Privacy Policy Drafting1–2 weeks (legal drafting)Template-based draft for reviewFaster first draft
Breach Notification8–24 hours (manual reporting)15 minutes (auto-generated report)95%
Consent Management Audit2–3 days per auditInstant (automated tracking)100%
Cross-Border Transfer Assessment1–2 weeks (legal analysis)10 minutes (automated TIA)95%
Vendor DPA Review3–5 days per agreementAssisted clause gap checkFaster review

What We Automate

GDPR privacy and security evidence coverage with 43 mapped controls, ROPA/DSR/DPIA workflows, breach evidence tracking, and explicit legal-review boundaries.

Art. 5–11

Lawful Processing & Principles

10 mapped controls

  • Lawful basis tracking per processing activity
  • Purpose limitation documentation
  • Data minimisation assessment
  • Consent management & proof
Art. 12–23

Data Subject Rights

9 mapped controls

  • DSR intake & fulfillment workflow
  • Right to erasure automation
  • Data portability export tools
  • Automated response tracking (30 days)
Art. 24–31

Controller & Processor Obligations

8 mapped controls

  • ROPA (Record of Processing Activities)
  • DPA clause checker for vendors
  • Joint controller agreements
  • Processor sub-processor tracking
Art. 32–34

Security of Processing

6 mapped controls

  • Technical & organisational measures (TOMs)
  • Breach detection & 72h notification
  • DPA authority reporting templates
  • Data subject breach communication
Art. 44–49

International Transfers

7 mapped controls

  • Transfer impact assessments (TIA)
  • SCCs & adequacy decision tracking
  • Binding Corporate Rules management
  • Derogation documentation
Art. 37–39

DPO & Accountability

8 mapped controls

  • DPO task & reporting dashboard
  • Accountability evidence management
  • Processing activity documentation
  • Compliance status tracking per article

GDPR Penalty Framework

GDPR has a two-tier penalty system. Understanding which tier applies helps prioritize compliance efforts.

Tier 1 — Higher Penalties

€20M / 4%

of annual global turnover (whichever is greater)

Applies to violations of: data processing principles (Art. 5), lawful basis (Art. 6), consent conditions (Art. 7), data subject rights (Art. 12-22), and international transfers (Art. 44-49).

Tier 2 — Standard Penalties

€10M / 2%

of annual global turnover (whichever is greater)

Applies to violations of: controller/processor obligations (Art. 25-39), certification body obligations (Art. 42-43), and monitoring body obligations (Art. 41).

Start your GDPR compliance journey

Link GDPR privacy/security evidence to controls, vendors, incidents, and audit trail without overstating legal compliance.