FRAMEWORKS

GDPR Framework

EU data protection framework governing personal data processing, establishing data subject rights, controller obligations, and enforcement mechanisms including administrative fines.

Section 01 · The regulation

What a GDPR audit tests

Regulation (EU) 2016/679 has applied since 25 May 2018. Its reach is set by Article 3 rather than by where a company is registered: it covers processing in the context of an EU establishment, and processing by organisations outside the EU where they offer goods or services to people in the Union or monitor their behaviour. A company with no European entity can therefore be fully in scope.

Every processing operation must satisfy two separate tests. It must respect the principles in Article 5 — lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality — and it must rest on one of the six legal bases in Article 6. Choosing a basis is not a formality: consent can be withdrawn, legitimate interests require a documented balancing test, and the basis determines which rights the individual can exercise.

Obligations follow the role. A controller decides why and how data is processed; a processor acts on documented instructions under Article 28; joint controllers under Article 26 must agree and publish how responsibilities are divided. Getting the role wrong is structural, not clerical: the wrong party ends up carrying — or failing to carry — the Article 5(2) accountability duty.

Enforcement runs through national supervisory authorities, in Poland the President of the Personal Data Protection Office, coordinated through the one-stop-shop mechanism and the European Data Protection Board. Article 83(2) sets eleven criteria that determine any fine, including the gravity and duration of the infringement, whether it was intentional, and how far the organisation cooperated. That is why documented decisions matter even when something has gone wrong.

2016/679
Regulation, applicable since 25 May 2018
7
Processing principles in Article 5
6
Legal bases in Article 6
4%
Upper fine tier, global annual turnover
1 month
Default deadline to answer a request
What the Regulation enumerates

Compliance decisions are measured against the text of the Regulation rather than a maturity model. Each cell represents one provision; point at a group to see its contents. Counts are the complete sets.

Article 5

7 of 34
  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability — Article 5(2)
Section 02 · Readiness drivers

Why GDPR work resurfaces years after the first project

Most organisations completed a GDPR project once, around 2018, and have been drifting from it ever since. Systems were replaced, suppliers changed, analytics and AI features were added, and the records of processing quietly stopped describing reality. The work resurfaces when something forces a comparison between the documentation and the systems: a customer audit, a subject complaint, a supervisory enquiry, or a transfer to a supplier outside the EEA that nobody assessed.

  1. 01 Records that no longer match reality The Article 30 record is the first document a supervisor asks for, and the easiest to disprove. Strength 5 of 5
  2. 02 New processing without a basis Analytics, enrichment and AI features are frequently deployed before anyone selects an Article 6 basis. Strength 4 of 5
  3. 03 Transfers outside the EEA A supplier or hosting change moves data under Chapter V and requires safeguards and a transfer assessment. Strength 4 of 5
  4. 04 Rights requests that cannot be met Requests unanswerable within the one-month deadline show that systems and records have diverged. Strength 3 of 5
  5. 05 Breach decision path The 72-hour clock in Article 33 leaves no time to design an escalation route during the incident. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Controllers

Deciding why and how data is processed carries the accountability duty in Article 5(2) and the full obligation set, including records, impact assessments, and breach notification.

Processors and suppliers

Article 28 imposes direct obligations and requires a written contract; a processor that decides purposes on its own becomes a controller for that processing.

Organisations outside the EU

Article 3(2) applies to offering goods or services to people in the Union or monitoring their behaviour, and Article 27 may require an EU representative.

Section 03 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across an accountability programme. The services that deliver them are listed further down.

Areas of support across a GDPR accountability programme
GDPR support by programme stage
Area of support MapAssessImplementMaintain
Advisory & leadership
Role and legal basis analysis Covered during Map Covered during Assess Not covered during Implement Not covered during Maintain
Data protection officer support Covered during Map Covered during Assess Covered during Implement Covered during Maintain
Policies and decision records Not covered during Map Covered during Assess Covered during Implement Covered during Maintain
Assessment & assurance
GDPR compliance audit Covered during Map Covered during Assess Not covered during Implement Not covered during Maintain
Records of processing review Covered during Map Covered during Assess Not covered during Implement Not covered during Maintain
Impact assessment under Article 35 Not covered during Map Covered during Assess Covered during Implement Not covered during Maintain
Processor and transfer review Not covered during Map Covered during Assess Covered during Implement Covered during Maintain
Engineering
Privacy by design and default Not covered during Map Covered during Assess Covered during Implement Covered during Maintain
Retention, access and logging Not covered during Map Covered during Assess Covered during Implement Covered during Maintain
Enablement & tooling
Rights and breach handling training Not covered during Map Not covered during Assess Covered during Implement Covered during Maintain
Section 04 · Related services

Services supporting GDPR accountability

The catalogue below is selected from the live service graph and grouped by area of expertise. Where the records of processing have drifted from the systems, an audit comes first, because every later decision — retention, transfers, impact assessments — depends on knowing what is actually being processed.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

GDPR Compliance Audit

GDPR compliance audit covering Art.5–35 with gap matrix, RoPA assessment, DPA chain analysis, and remediation roadmap.

GDPR
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

GDPR implementation consultancy and support

GDPR implementation support — gap analysis, policy development, RoPA setup, and ongoing compliance advisory.

GDPR
Read more

Security and Privacy Architecture Review

Security and privacy architecture review for SaaS applications — threat modeling, data flow analysis, and design recommendations.

NIS 2 DirectiveGDPRISO 27001
Read more

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

US Software Review for EU Regulatory Compliance

Review of US-built software against EU privacy and cybersecurity regulations — GDPR, NIS 2, and AI Act compliance.

AI ActNIS 2 DirectiveGDPR
Read more

Compliance and Risk Assessment Workshops

Compliance and risk assessment workshops — DPIA facilitation, risk analysis, and team capability building.

AI ActGDPR
Read more

Secure SDLC Consulting

Secure SDLC consulting — embedding security gates, threat modeling, and DevSecOps practices into your development pipeline.

NIS 2 DirectiveGDPRISO 27001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

Privacy Engineer Role Outsourcing

Embed Privacy by Design and privacy engineering into your software development and data management processes.

GDPR
Read more

Software Engineering for Privacy and Security

SaaS prototyping, architecture reviews, and secure platform upgrades for Python/Django with privacy and security by design.

GDPR
Read more

Data Protection Officer Outsourcing

Outsourced DPO fulfilling GDPR Art. 37–39 — DPIA support, data subject requests, and authority liaison.

GDPR
Read more

EU Data Protection Representative Outsourcing for US based companies

EU Data Protection Representative under GDPR Art. 27 for US companies processing EU personal data.

GDPR
Read more

Process Outsourcing and Managed Services

Ongoing risk assessments, vendor due diligence programs, and compliance monitoring delivered as managed services with defined service levels and regular reporting cadences.

Cybersecurity and Data Protection Risk Assessment

Combined cybersecurity and data protection risk assessment with risk register, treatment plan, and DPIA support.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more

Vendor Risk Assessment

Third-party vendor risk assessment for cybersecurity, data protection, and supply chain security compliance.

NIS 2 DirectiveGDPRISO 27001SOC 2
Read more
Start the conversation

Scope a GDPR engagement against your processing rather than a template.

The first conversation establishes what is actually processed, under which role and legal basis, and where the records have drifted from the systems. That comparison is exactly what a supervisory authority, a customer audit, or a subject complaint will make — so it is worth making it first, in private.

Why Up Secure
Records against reality The Article 30 record is the first document a supervisor asks for and the easiest to disprove. It gets checked against the systems, not against the policy.
Legal and engineering together Article 25 lands in code — defaults, retention, access, logging. Advisers who cannot read it will miss where the obligation actually sits.
Reused, not rebuilt Article 32 evidence also serves NIS 2 and ISO 27001 control A.5.34 rather than being produced three separate times.
Section 05 · Frequently asked

GDPR questions decision-makers ask

Frequently asked questions

Does the GDPR apply to a company with no EU entity?
It can. Article 3(2) extends the Regulation to organisations established outside the Union where they offer goods or services to people in the Union — paid or free — or monitor the behaviour of people in the Union, which covers most analytics and profiling of European visitors. Where Article 3(2) applies, Article 27 generally requires the appointment of a representative established in a Member State, subject to limited exemptions.
How is the right legal basis chosen?
By reference to the purpose, before processing starts. Article 6 offers six bases and they are not interchangeable: consent must be freely given and can be withdrawn, contract covers only what is genuinely necessary to perform it, and legitimate interests require a documented balancing test against the individual's rights. The choice has downstream consequences, because portability applies only to consent and contract, and the right to object applies to legitimate interests and public task.
What makes special category data different?
Article 9 prohibits processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data used for identification, health data, and data concerning sex life or sexual orientation — unless one of the conditions in Article 9(2) applies. An Article 6 basis is still required in addition. Health and biometric processing therefore needs two separate justifications, which is the step most often missed.
How are fines actually determined?
Article 83(2) lists eleven criteria, including the nature, gravity and duration of the infringement, whether it was intentional or negligent, what was done to mitigate the damage, the degree of responsibility given the measures implemented, previous infringements, and the degree of cooperation with the authority. Two tiers apply: up to EUR 10 million or 2% of worldwide annual turnover for most obligations, and up to EUR 20 million or 4% for breaches of the principles, the legal bases, data subject rights, and the transfer rules.
Does a GDPR audit certify compliance?
No. There is no general GDPR certificate. Article 42 provides for certification mechanisms approved by a supervisory authority or the European Data Protection Board, and adherence can be used to demonstrate compliance, but it does not reduce the controller's responsibility. An audit produces evidence, findings, and a remediation position — not a legal conclusion that an organisation is compliant.
How does the GDPR interact with NIS 2 and the AI Act?
They overlap on the same systems without replacing one another. Article 32 security of processing draws on the same controls as the NIS 2 risk-management measures, and where AI processes personal data, Article 22 on automated decisions and Article 35 impact assessments frequently apply alongside the AI Act obligations. Producing one inventory, one risk record, and one supplier assessment that serve all three is considerably cheaper than running three programmes that reach different conclusions about the same system.