European Union law

GDPR

The GDPR (Regulation (EU) 2016/679) is the EU data protection regulation which, since 25 May 2018, obliges organisations to process personal data lawfully, transparently and securely — with fines of up to EUR 20 million or 4% of annual worldwide turnover.

Start assessmentRead about the standard
45
controls in Guardiso
30
free-test questions
PL · EN
two languages

What is the GDPR?

The GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data — is the primary legal act governing personal data protection in the European Union. It has applied directly in all member states since 25 May 2018, without the need for national implementation.

The regulation is built on the Article 5 principles: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. These are tied together by the accountability principle — an organisation must not only comply, but also be able to demonstrate compliance with documentation.

Who does it apply to?

The GDPR applies to every organisation — regardless of size or industry — that processes personal data of individuals in the European Union: controllers (entities that determine the purposes and means of processing) and processors (vendors acting on a controller's behalf).

The regulation has extraterritorial reach: it also covers companies outside the EU if they offer goods or services to individuals in the Union or monitor their behaviour (for example via cookies and profiling). In practice, simply holding a customer list, employee records or a newsletter database means an organisation falls under the GDPR.

Key obligations

The GDPR does not impose a single list of safeguards — it requires a risk-based approach in which the organisation selects measures appropriate to the nature and scale of processing. It does, however, rest on specific, verifiable obligations:

  • Record of processing activities (Art. 30) — documenting purposes, data categories, recipients, retention and safeguards for every process.
  • Legal bases (Art. 6) — every processing operation must have a defined basis: consent, contract, legal obligation, vital interests, public task or legitimate interests.
  • Data subject rights (Art. 12-22) — handling requests for access, rectification, erasure, restriction, data portability and objection, as a rule within one month.
  • Breach notification (Art. 33-34) — notifying the supervisory authority within 72 hours of becoming aware of a breach and, in high-risk cases, communicating it to the affected individuals.
  • Data protection impact assessment — DPIA (Art. 35) — mandatory before processing likely to result in high risk, such as large-scale profiling or large-scale processing of sensitive data.
  • Data protection officer — DPO (Art. 37) — required for public authorities and for organisations whose core activities involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data.
  • Data processing agreements (Art. 28) and safeguards for transfers outside the EEA (Chapter V) — control over vendors and data flows to third countries.

Fines and enforcement

The GDPR provides two tiers of administrative fines. Breaches of organisational obligations (for example missing records of processing, no DPIA, failure to notify a breach) carry fines of up to EUR 10 million or 2% of total annual worldwide turnover of the preceding year — whichever is higher. Breaches of the processing principles, legal bases, data subject rights and transfer rules raise the ceiling to EUR 20 million or 4% of turnover.

In Poland the supervisory authority is the President of the Personal Data Protection Office (UODO), which conducts inspections, handles complaints and imposes fines. Beyond financial penalties, the authority can order the restriction or an outright ban of processing, and data subjects can claim compensation in civil proceedings. GDPR violations also carry a tangible reputational risk — fining decisions are published.

How does Guardiso help?

Guardiso turns GDPR requirements into a structured, measurable data protection programme — instead of scattered spreadsheets and documents, the organisation works on a single platform with full accountability.

  • GDPR registers in one place — record of processing activities (Art. 30), consent register, register of processing agreements and transfers, always current and ready to present to the supervisory authority.
  • Policy and notice generator — data protection policy, privacy notices (Art. 13-14) and DPA templates tailored to the organisation's profile, in Polish and English.
  • Data subject rights handling — receiving and tracking requests (access, erasure, rectification, objection) with the one-month deadline monitored and a full audit trail.
  • Breach register with a 72-hour clock — breach risk assessment, the documentation required by Article 33(5), and support for deciding on notification to the authority and communication to data subjects.
  • Self-assessment and control mapping — assessment questions linked to GDPR articles reveal gaps and implementation priorities, while cross-mapping connects the GDPR with ISO 27001 and other standards so one piece of work satisfies multiple requirements.
Official sources
01Select standard›02Complete the self assessment›03Close gaps in Guardiso
—
GDPR readiness score
0/30 answered
The score updates live as you answer.

Other standards to assess

ISO 27001GlobalNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443GlobalISO 21434Automotive
Browse all 30 standards