European Union · European Union

General Data Protection Regulation (EU 2016/679) compliance software

Demonstrate accountability under the GDPR — lawful basis, data subject rights, records of processing and breach readiness, evidenced in one place.

Overview

What GDPR requires

The General Data Protection Regulation (EU 2016/679) governs the processing of personal data of people in the European Union, with extraterritorial reach to organisations anywhere that offer goods or services to, or monitor, EU data subjects. Fines scale to 4% of worldwide annual turnover.

Article 5(2) makes accountability itself an obligation: organisations must be able to demonstrate compliance, not merely achieve it. That means maintained records of processing (Article 30), evidenced lawful bases, working data-subject-rights procedures, transfer safeguards and breach-notification readiness.

For Gulf organisations, GDPR frequently applies alongside regional laws such as Saudi Arabia's PDPL. The two share concepts — lawful basis, subject rights, transfer controls — so a shared control model avoids running two parallel privacy programmes.

Who it applies to

  • Organisations established in the EU/EEA processing personal data
  • Non-EU organisations offering goods or services to EU data subjects
  • Processors handling EU personal data under Article 28 contracts
  • Groups managing GDPR alongside regional laws such as PDPL

At a glance

  • Legal instrument: Regulation (EU) 2016/679, applicable since 25 May 2018
  • Supervision: National supervisory authorities coordinated by the EDPB
  • Key obligations: Lawful basis, subject rights, RoPA, DPIA, transfers, breach notification
  • Sanctions: Up to €20m or 4% of worldwide annual turnover
In the platform

How GRCLens supports GDPR

GDPR runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Article-based assessment

GDPR obligations are decomposed into assessable controls with owners, status and evidence — from lawful-basis records to DPIA triggers.

Board and divisional dashboards

Executive, divisional and work-queue views show accountability posture at the level each audience needs.

Shared privacy model with PDPL

Overlapping obligations are mapped, so evidence for subject rights or transfer safeguards is captured once across both regimes.

Breach readiness evidence

Notification procedures, 72-hour workflow records and incident logs attach to the articles that require them.

Questions

GDPR frequently asked questions

Does GDPR apply to organisations outside the EU?

Yes, where they offer goods or services to people in the EU or monitor their behaviour (Article 3). Many Gulf and international organisations are in scope for part of their processing.

What does GDPR accountability require in practice?

Article 5(2) requires organisations to demonstrate compliance: maintained records of processing, documented lawful bases, DPIAs where required, working subject-rights procedures and breach readiness. GRCLens evidences each as an owned, dated control.

Can GDPR and PDPL be managed together?

Yes. The regimes overlap substantially, and GRCLens maps the common obligations so one piece of evidence satisfies both where the requirement is the same.

Does GRCLens replace a Data Protection Officer?

No. It gives the DPO and privacy team a structured, evidenced view of the programme — the accountability record the role is expected to maintain.

Talk to us about GDPR

Security Solution Consultants provides Privacy and data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.

Contact us