General Data Protection Regulation (EU 2016/679) compliance software
Demonstrate accountability under the GDPR — lawful basis, data subject rights, records of processing and breach readiness, evidenced in one place.
What GDPR requires
The General Data Protection Regulation (EU 2016/679) governs the processing of personal data of people in the European Union, with extraterritorial reach to organisations anywhere that offer goods or services to, or monitor, EU data subjects. Fines scale to 4% of worldwide annual turnover.
Article 5(2) makes accountability itself an obligation: organisations must be able to demonstrate compliance, not merely achieve it. That means maintained records of processing (Article 30), evidenced lawful bases, working data-subject-rights procedures, transfer safeguards and breach-notification readiness.
For Gulf organisations, GDPR frequently applies alongside regional laws such as Saudi Arabia's PDPL. The two share concepts — lawful basis, subject rights, transfer controls — so a shared control model avoids running two parallel privacy programmes.
Who it applies to
- Organisations established in the EU/EEA processing personal data
- Non-EU organisations offering goods or services to EU data subjects
- Processors handling EU personal data under Article 28 contracts
- Groups managing GDPR alongside regional laws such as PDPL
At a glance
- Legal instrument: Regulation (EU) 2016/679, applicable since 25 May 2018
- Supervision: National supervisory authorities coordinated by the EDPB
- Key obligations: Lawful basis, subject rights, RoPA, DPIA, transfers, breach notification
- Sanctions: Up to €20m or 4% of worldwide annual turnover
How GRCLens supports GDPR
GDPR runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Article-based assessment
GDPR obligations are decomposed into assessable controls with owners, status and evidence — from lawful-basis records to DPIA triggers.
Board and divisional dashboards
Executive, divisional and work-queue views show accountability posture at the level each audience needs.
Shared privacy model with PDPL
Overlapping obligations are mapped, so evidence for subject rights or transfer safeguards is captured once across both regimes.
Breach readiness evidence
Notification procedures, 72-hour workflow records and incident logs attach to the articles that require them.
GDPR frequently asked questions
Does GDPR apply to organisations outside the EU?
Yes, where they offer goods or services to people in the EU or monitor their behaviour (Article 3). Many Gulf and international organisations are in scope for part of their processing.
What does GDPR accountability require in practice?
Article 5(2) requires organisations to demonstrate compliance: maintained records of processing, documented lawful bases, DPIAs where required, working subject-rights procedures and breach readiness. GRCLens evidences each as an owned, dated control.
Can GDPR and PDPL be managed together?
Yes. The regimes overlap substantially, and GRCLens maps the common obligations so one piece of evidence satisfies both where the requirement is the same.
Does GRCLens replace a Data Protection Officer?
No. It gives the DPO and privacy team a structured, evidenced view of the programme — the accountability record the role is expected to maintain.
One platform, many obligations
Talk to us about GDPR
Security Solution Consultants provides Privacy and data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.
Contact us