GDPR for US Companies: When and How It Applies
When GDPR applies to US companies under Art. 3(2), what compliance requires, and how EU authorities enforce against non-EU businesses. Practical steps included.
Page 6 of 12
When GDPR applies to US companies under Art. 3(2), what compliance requires, and how EU authorities enforce against non-EU businesses. Practical steps included.
Art. 30 GDPR requires a Record of Processing Activities (ROPA). This guide covers who must maintain one, what to include, template structure, and enforcement.
Is GDPR training for employees mandatory? Art. 39(1)(b) assigns awareness duties to the DPO. Learn what to include, training frequency, and DPA expectations.
NIS2 penalties explained: Art. 34 fines, management liability under Art. 20, enforcement examples, and essential vs important entity differences.
Binding Corporate Rules vs Standard Contractual Clauses vs EU-U.S. Data Privacy Framework. Decision criteria, costs, timelines, and 2026 enforcement priorities.
Data privacy compliance roadmap covering GDPR, CCPA, nLPD, and global frameworks. Practical implementation steps, costs, and 2026 enforcement priorities.
Compare DPO certifications: IAPP CIPP/E, CIPM, CIPT, CNIL-certified, AFNOR, TÜV. Cost, recognition, exam difficulty, and which one EU employers require.
GDPR audit framework with 48 control points, scoring methodology, and remediation playbook. Includes templates for internal audits and DPA-led inspections.
Data Protection Officer job description template with required skills, certifications, salary ranges, and 12 essential responsibilities under GDPR Article 39.
GDPR Standard Contractual Clauses guide. Module selection, transfer impact assessment, SCC implementation for US data transfers, and 2024-2026 updates.
Transfer Impact Assessment template and methodology under GDPR. Six-step EDPB framework, country risk profiles, and supplementary measures for compliant transfers.
The EDPB is the EU body that ensures consistent GDPR application. Role, members, guidelines, binding decisions, and how its rulings shape compliance.
GDPR data controller vs processor: definitions, decision criteria, contractual implications. With 8 real-world scenarios from cloud services to analytics.
ISO 27001 and GDPR overlap on security but diverge on data subject rights, lawful basis, and transfers. Mapping the controls and where ISO 27001 alone is insufficient.
GDPR Article 12 sets the rules for transparent communication with data subjects: clear language, free of charge, 30-day response, identity verification.
GDPR Article 13 lists 14 mandatory information items when collecting personal data directly from data subjects. Privacy notice template and CNIL enforcement.
GDPR Article 14 governs the privacy notice when data is obtained from a source other than the data subject. Timing, content, and the five exemptions.
GDPR Article 18 gives data subjects the right to restrict processing in 4 cases. Practical implementation, technical measures, and DPA enforcement.