✨ Standpoint covers GDPR readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / GDPR
Privacy · Regulation (binding)

GDPR

The GDPR (General Data Protection Regulation) is the European Union's comprehensive data protection law — the rulebook for how organizations collect, use, store, and share the personal data of people in the EU and EEA (European Economic Area). It applies far beyond Europe's borders: if you handle the personal data of people in the EU, it can reach you wherever you are. If a customer, a contract, or your own product is pushing you toward "GDPR compliance," here's the plain-language version: what it is, who it applies to, the principles and rights it sets out, the obligations it puts on you, what non-compliance costs, and how to get ready.

What
the GDPR (Regulation (EU) 2016/679) — a directly applicable EU law that took effect on 25 May 2018, setting rules for processing the personal data of people in the EU/EEA.
Who
any organization — anywhere in the world — that processes the personal data of people in the EU/EEA, whether by offering them goods and services or by monitoring their behaviour.
Core idea
personal data belongs to the person (the "data subject"); organizations may only process it lawfully, fairly, transparently, and for a…
Two key roles
the data controller decides why and how data is processed; the data processor processes it on the controller's behalf.
// What Standpoint gives you

GDPR compliance checklist

A grouped, practical implementation checklist.

Free readiness assessment

See your GDPR gaps in minutes.

Map to other frameworks

How GDPR lines up with ISO 27701, ISO 27001 & SOC 2.

// What the framework covers
Lawfulness, fairness & transparencyGAP
Purpose limitationPARTIAL
Data minimisationDONE
AccuracyGAP
Storage limitationPARTIAL
Integrity & confidentialityDONE

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is GDPR?

The GDPR is a law, not a voluntary framework or a certification you earn. It is a regulation of the European Union, which means it applies directly and uniformly across all EU member states without each country needing to pass its own version. Its aim is twofold: to protect individuals' fundamental right to the protection of their personal data, and to allow that data to move freely within the EU. In practice it defines a set of principles, gives people concrete rights over their data, and imposes clear obligations — backed by significant fines — on the organizations that hold and use that data. "Personal data" is defined broadly: any information relating to an identified or identifiable person — names, email addresses, location data, IP addresses, and online identifiers all count. A special, more tightly protected category covers sensitive data such as health, biometric, racial or ethnic, political, and similar information.

Who does GDPR apply to? (Its extraterritorial reach)

This is what surprises many teams: the GDPR is extraterritorial. It applies to organizations established in the EU, but it also applies to organizations anywhere in the world when they: - offer goods or services to people in the EU/EEA (whether paid or free), or - monitor the behaviour of people in the EU/EEA (for example, tracking and profiling website visitors). So a US, UK, or Asian company with no European office can still fall squarely within GDPR simply by having EU customers or by tracking EU visitors. Organizations outside the EU that are caught this way often must appoint an EU representative — a contact point inside the EU for individuals and regulators.

The key roles: controller vs processor (and the DPO)

Data controller — The organization that decides why and how personal data is processed. The controller carries primary responsibility for compliance. Data processor — An organization that processes personal data on behalf of a controller (e.g., a cloud host or a SaaS vendor). Processors act on the controller's documented instructions and have direct obligations of their own. DPO (Data Protection Officer) — An independent expert some organizations must appoint to oversee data protection — required when you carry out large-scale monitoring or process sensitive data at scale, and for most public …

The core principles

All processing must follow seven principles. They read like common sense, but each carries real obligations:

The six lawful bases for processing

You may only process personal data if you have at least one of six lawful bases, chosen before you start: - Consent — the person has given clear, freely-given, informed agreement. - Contract — processing is needed to perform a contract with the person (or to take steps at their request before entering one). - Legal obligation — you must process the data to comply with the law. - Vital interests — processing is needed to protect someone's life. - Public task — processing is needed for a task in the public interest or official authority. - Legitimate interests — processing is necessary for your …

Data-subject rights

The GDPR gives individuals a set of enforceable rights over their own data. You must have a way to receive and answer these requests, usually within one month: - Right of access — to know whether you hold their data and to get a copy of it. - Right to rectification — to have inaccurate data corrected. - Right to erasure ("right to be forgotten") — to have their data deleted in certain circumstances. - Right to restriction — to limit how their data is used while a dispute is resolved. - Right to data portability — to receive their data in a common format and move it elsewhere. - Right to object — to object to certain processing, including direct marketing. - Rights around automated decisions — protections against solely automated decisions, including profiling, that significantly affect them.

GDPR work counts elsewhere too

The crosswalk maps your GDPR evidence onto the frameworks it overlaps — so you move forward on several at once.

ISO 27001ISO 27701SOC 2

Get your GDPR readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →