GDPR Compliance Guide 2026: 10 Obligations, Step by Step
GDPR compliance guide 2026: the 10 obligations in order — lawful basis, ROPA, notices, rights, DPIA, processors, transfers, security, breach, retention.
Expert analysis and practical guides on GDPR compliance, data protection law, DPO obligations, lawful bases, data subject rights, and enforcement. From Article-by-Article breakdowns to implementation checklists.
EU Regulation 2016/679
The GDPR (Regulation 2016/679) has shaped how every organization touching EU residents' data operates since 25 May 2018. Cumulative enforcement passed €5.5 billion by end of 2025, with the largest single fine (€1.2B against Meta) tied to international transfers. Below are deep-dive guides on the principles, obligations, and enforcement priorities that matter in 2026 — ordered by reader frequency.
Start with Article 5: the seven core data privacy principles, including the storage limitation principle, purpose limitation, and accuracy. Move to operational requirements: Article 28 sub-processor obligations, the DPA template, and vendor audit checklist. For international transfers, see our cross-border transfers guide, the SCCs reference, and the Transfer Impact Assessment methodology.
Operating multi-jurisdiction? Compare the BCR vs SCC vs DPF mechanisms, or read our global compliance guide. For Switzerland, the RGPD/nLPD guide and nLPD vs RGPD differences are the right starting points. For DPO functions, see the DPO job description template and certification comparison.
GDPR compliance guide 2026: the 10 obligations in order — lawful basis, ROPA, notices, rights, DPIA, processors, transfers, security, breach, retention.
12 GDPR consent examples: cookie banner, newsletter, marketing, profiling and special category wording, CNIL and AEPD tested, plus the fines you avoid.
Practical guide to GDPR right of access under Article 15 — what individuals can request, what to disclose, and how to respond compliantly.
Opt-in means ask first; opt-out means stop on request. When GDPR requires each, with a comparison table and examples for email, cookies, calls and data sharing.
GDPR consent wording examples: 8 copy-ready templates for cookies, newsletters, health data, children and sharing — plus the failures DPAs actually sanction.
GDPR compliance framework: the 11 deliverables in build order — ROPA, lawful basis register, DPIA triggers, DPAs, transfer map, breach playbook, audit cycle.
Australia has no EU adequacy decision. Which SCC module applies, how to run the transfer impact assessment against Australian government access powers, and the contract path for Australian vendors.
Canada's adequacy decision covers only recipients subject to PIPEDA. What falls outside it — public bodies, non-profits, some employee and health data — and when SCCs are required.
Consent and legitimate uses against six lawful bases, Consent Managers, the rights India's DPDP Act omits, the Data Protection Board, rupee penalties, and the phased commencement to May 2027.
Art. 35(3)(b) names large-scale Art. 9 processing, so a health DPIA is rarely optional. The Art. 35(7) content applied to a clinical system, WP248 criteria, Art. 36 prior consultation, and when to redo it.
When the GDPR reaches an Australian business under Art. 3(2), the two scope tests applied to Australian fact patterns, the Art. 27 EU representative duty, and what non-compliance costs.
Canada's adequacy decision does not exempt Canadian companies from the GDPR. When Art. 3(2) applies, the Art. 27 EU representative duty, and what health data changes.
Buying guide for Australian companies subject to the GDPR: EU hosting, Art. 30 records, DSAR workflow, Art. 27 representative arrangements, and dual Privacy Act + GDPR record-keeping.
Choosing GDPR compliance software in Canada: running Art. 30 records alongside PIPEDA and Quebec Law 25, bilingual output, three breach clocks, and what the market actually delivers.
GDPR software for Indian IT-services firms: Art. 30(2) processor records per client, sub-processor management, DPA and SCC registers, and audit evidence for European client due diligence.
Buying guide for Singapore companies subject to the GDPR: EEA hosting, Art. 30 records for controller and processor activities, DSAR workflow, Art. 27 representative records, dual PDPA + GDPR registers.
Health data needs an Art. 9(2) condition on top of an Art. 6 lawful basis. Controller mapping across providers, insurers and vendors, why consent fails in care, Art. 9(4) national law.
Most Indian companies meet the GDPR as processors for European clients, not through Art. 3(2) targeting. What Arts. 28, 30(2), 32 and 33(2) require, and why health data is audited hardest.
The MDR Art. 11 Authorised Representative does not satisfy GDPR Art. 27. Two separate appointments, plus controller/processor status for telemetry, post-market surveillance versus minimisation, and SaMD.
When the GDPR reaches a Singapore business under Art. 3(2), the processor nuance that catches regional service centres, the Art. 27 representative duty, and what follows for health data.
Which Art. 9(2) conditions health organisations actually rely on and how each one fails: explicit consent, 9(2)(h) with the Art. 9(3) secrecy trap, public health, and research under Art. 89(1).
India has no EU adequacy decision. Which SCC module applies to an Indian processor, how to run the transfer impact assessment, and how to answer the government-access questions.
The PDPA's consent-centric model against the GDPR's six lawful bases: access rights, the absence of a special-category tier, the DNC registry, breach notification timing, and PDPC enforcement.
PIPEDA's ten principles against the GDPR's structure: consent, erasure, breach reporting to the OPC, Quebec Law 25, enforcement powers and the state of federal reform.
The 13 Australian Privacy Principles against the GDPR's structure: lawful bases, consent, data subject rights, the NDB scheme vs Art. 33/34, OAIC vs EU supervisory authorities, and the reform direction.
Singapore has no EU adequacy decision, and the EU–Singapore Digital Trade Agreement is not one. Which SCC module applies, how to run the transfer impact assessment, and the contract path.
GDPR Article 30 ROPA data model: 14 mandatory fields, controller vs processor versions, template structure, EDPB recommended extensions, examples.
The GDPR requires obtaining the consent of individuals before processing their personal data in certain cases, here's how to do that
The General Data Protection Regulation (GDPR) is one of the most important regulation in the European Union in the field of data protection
GDPR vs AML conflicts: 5-10 year retention, KYC data minimization, AMLA 2026 launch, sanctions screening. Resolutions per Art. 6(1)(c) + Art. 23.
The CNIL has just imposed a €500,000 fine on a company for conducting commercial prospecting without complying with the GDPR
Here is the list of GDPR information notices that you must mandatorily provide before collecting personal data
How to design a questionnaire that is compliant with the GDPR and ensures data collection in accordance with the law
Only the DPO is regulated by the GDPR. See how the Data Protection Officer differs from a compliance officer, when it is mandatory, and who appoints one.
The GDPR gives the Data Protection Officer specific tasks: informing and advising, monitoring compliance, staff training and advising on DPIAs under Article 39.
Art. 38 GDPR rules on DPO independence: 4 dismissal-protection cases (CJEU C-453/21, X-FAB, Würth), reporting to top management, conflict of interest tests.
The GDPR accuracy principle under Article 5(1)(d): what it requires, how to implement it in practice, and how opinions and historical records are treated.
The GDPR requires the collection of consent from individuals before processing their personal data in certain cases, here's how to do that
Article 5 of the GDPR lays out key principles related to the purposes for which personal data can be processed.
Meta €1.2B fine. 15 adequate countries (Switzerland renewed 2024). SCC vs BCR vs DPF decision tree + Transfer Impact Assessment template inside.
Art. 20 applies only with consent/contract + automated processing. JSON/CSV/XML format. Provided vs derived data + 30-day response deadline workflow.
Step-by-step GDPR compliance guide for e-commerce: cookie consent, checkout data, payment processor agreements, cross-border selling, and data retention rules.
How to conduct a GDPR audit from scoping to remediation. Includes a 10-step checklist, document templates, and real enforcement examples.
Art. 25 GDPR step-by-step: 7 principles + Notebooksbilliger €10.4M case + checklist for design phase + default settings + CNIL recent enforcement 2025.
A practical GDPR compliance checklist covering all key requirements, from data mapping to breach response, so your organisation meets every obligation.
Learn how to handle data subject access requests (DSARs) under GDPR — from receiving the request to responding within the legal deadline, with practical steps.
Learn how to comply with GDPR step by step — from data auditing and legal bases to breach response and ongoing monitoring.
6 GDPR compliance tools compared for 2026: Legiscope, OneTrust, Dastra, TrustArc, Vanta, Sprinto. Real pricing from €79/month, pros and cons, and SME picks for France, Spain, and Germany.
An independent comparison of six leading consent management platforms for 2026, covering GDPR compliance, TCF 2.2 support, Google Consent Mode v2, pricing, and which CMP fits each use case.
Cookie consent under GDPR and ePrivacy: legal framework, valid consent rules, cookie categories, enforcement fines, and compliance checklist.
Map the overlapping EU compliance stack in 2026: GDPR, DORA, NIS2, AI Act, and CRA obligations, with a practical framework for multi-regulation management.
Detailed breakdown of GDPR compliance costs by company size, from micro-enterprises to large corporations. Compare DIY, consultant, and software approaches.
Legiscope vs OneTrust compared for mid-market companies. Pricing, features, ROPA, DPA audit, EU hosting, and implementation time side by side.
A practical migration guide for moving GDPR compliance from spreadsheets to automated software. Why spreadsheets fail, what to look for, how to switch.
Art. 4(7) GDPR defines the data controller as the entity that determines processing purposes and means. Understand your obligations, liability and examples.
How to choose the right GDPR audit tool. Manual vs automated comparison, feature checklist, cost analysis, and what Legiscope delivers for mid-market teams.
Art. 33 GDPR requires breach notification within 72 hours. Learn what counts as a breach, what the notice must contain, and when to inform data subjects.
Real GDPR compliance cost breakdown by company size: DPO, tools, audit, training. Compare costs vs fines and learn where automation delivers ROI.
GDPR compliance software buyer's guide 2026: the 5 features that matter, real pricing (€50-2,000/month), a 7-point evaluation framework, and ROI math.
Art. 7 GDPR sets strict consent management requirements. Learn consent lifecycle management, CMP selection, withdrawal mechanisms, and enforcement trends.
What a GDPR data retention policy must contain, how to document retention periods, and how DPAs enforce storage limitation. Includes template structure.
DPO salary ranges by country, certification options (CIPP/E, CIPM), career paths, and freelance vs in-house comparison. Data-driven guide for 2026.
When GDPR applies to US companies under Art. 3(2), what compliance requires, and how EU authorities enforce against non-EU businesses. Practical steps included.
Art. 30 GDPR requires a Record of Processing Activities (ROPA). This guide covers who must maintain one, what to include, template structure, and enforcement.
Is GDPR training for employees mandatory? Art. 39(1)(b) assigns awareness duties to the DPO. Learn what to include, training frequency, and DPA expectations.
Binding Corporate Rules vs Standard Contractual Clauses vs EU-U.S. Data Privacy Framework. Decision criteria, costs, timelines, and 2026 enforcement priorities.
Data privacy compliance roadmap covering GDPR, CCPA, nLPD, and global frameworks. Practical implementation steps, costs, and 2026 enforcement priorities.
Compare DPO certifications: IAPP CIPP/E, CIPM, CIPT, CNIL-certified, AFNOR, TÜV. Cost, recognition, exam difficulty, and which one EU employers require.
GDPR audit framework with 48 control points, scoring methodology, and remediation playbook. Includes templates for internal audits and DPA-led inspections.
Data Protection Officer job description template with required skills, certifications, salary ranges, and 12 essential responsibilities under GDPR Article 39.
GDPR Standard Contractual Clauses guide. Module selection, transfer impact assessment, SCC implementation for US data transfers, and 2024-2026 updates.
Transfer Impact Assessment template and methodology under GDPR. Six-step EDPB framework, country risk profiles, and supplementary measures for compliant transfers.
The EDPB is the EU body that ensures consistent GDPR application. Role, members, guidelines, binding decisions, and how its rulings shape compliance.
GDPR data controller vs processor: definitions, decision criteria, contractual implications. With 8 real-world scenarios from cloud services to analytics.
ISO 27001 and GDPR overlap on security but diverge on data subject rights, lawful basis, and transfers. Mapping the controls and where ISO 27001 alone is insufficient.
Free ROPA template for GDPR Article 30. Mandatory fields, controller vs processor versions, sample entries for HR, marketing, and customer service.
GDPR Article 12 sets the rules for transparent communication with data subjects: clear language, free of charge, 30-day response, identity verification.
GDPR Article 13 lists 14 mandatory information items when collecting personal data directly from data subjects. Privacy notice template and CNIL enforcement.
GDPR Article 14 governs the privacy notice when data is obtained from a source other than the data subject. Timing, content, and the five exemptions.
GDPR Article 18 gives data subjects the right to restrict processing in 4 cases. Practical implementation, technical measures, and DPA enforcement.
GDPR Article 21 gives data subjects the absolute right to object to direct marketing and a qualified right to object to processing under legitimate interests or public task.
GDPR Article 22 prohibits decisions based solely on automated processing that produce legal or similarly significant effects, with three narrow exceptions.
GDPR Article 25 requires data protection by design and by default. Implementation patterns, EDPB guidelines, and architectural examples for SaaS.
GDPR Article 32 requires appropriate technical and organizational security measures: encryption, pseudonymization, integrity, availability, regular testing.
GDPR Article 34 requires communicating personal data breaches to affected data subjects when there's high risk. Threshold, content, exemptions, timing.
GDPR Article 6 sets out the six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, legitimate interests.
GDPR Article 7 sets out conditions for valid consent: demonstrability, intelligible request, easy withdrawal, and freely given. Practical implementation guide.
GDPR Article 9 prohibits processing of special category data (health, biometrics, religion, etc.) except under 10 specific conditions including explicit consent.
Complete index of GDPR articles with deep-dive guides on each. Organised by topic: principles, lawful basis, rights, controllers, transfers, supervision.
GDPR Article 16 gives data subjects the right to have inaccurate personal data corrected and incomplete data completed. Procedure, deadlines, and exceptions.
GDPR Article 24 imposes the accountability obligation on the controller. Risk-based approach, technical and organisational measures, documentation, demonstrability.
GDPR Article 27 requires non-EU controllers targeting EU data subjects to designate an EU representative. Obligations, exemptions, and how to comply in 2026.
GDPR Article 33: notify the supervisory authority within 72 hours of a personal data breach. Process, content, exemptions, and enforcement.
GDPR Article 36 requires prior consultation with the supervisory authority when a DPIA shows high residual risk. Process, timeline, content, and consequences.
GDPR Article 4 defines 26 key terms: personal data, processing, controller, processor, consent, pseudonymization, biometric, profiling. Reference glossary.
GDPR Article 44 sets the general principle for international data transfers: protection must not be undermined. Safeguards hierarchy, adequacy, derogations.
GDPR Article 83 governs administrative fines: two tiers (up to €10M/2% or €20M/4%), 11 calculation criteria, and the EDPB Guidelines 04/2022 methodology.
UK GDPR vs EU GDPR in 2026: Data (Use and Access) Act changes, adequacy status, ICO vs EDPB approach, and the key compliance divergences that matter.
Redirects to the full GDPR Article 28 page.
Redirects to the storage limitation principle guide.
Swiss FADP vs GDPR comparison: breach notification deadlines, sanctions up to CHF 250k, supervisory authorities (FDPIC, EDPB), key differences 2026.
GDPR Article 20 right to data portability: official text, scope, machine-readable format, EDPB WP242 guidance, deadlines, sanctions, implementation checklist.
GDPR Article 21 right to object: official text, absolute right for direct marketing, profiling, opt-out mechanics, sanctions, EDPB guidance.
GDPR Article 33 official text from EUR-Lex: 72-hour breach notification deadline, content requirements, EDPB Guidelines 9/2022, sanctions, examples.
GDPR Article 39 DPO tasks: 6 mandatory duties, EDPB WP243 guidance, independence rules, reporting line, sanctions, internal vs external DPO.
GDPR Article 5(1)(e) storage limitation: official EUR-Lex text, retention rules by data type, EDPB guidance, anonymisation, sanctions €14.5M+.
GDPR automated means definition: Article 2(1) scope, automated decision-making (Art 22), Convention 108+, manual vs automated processing, case law.
GDPR data minimisation (Art 5(1)(c)) and purpose limitation (Art 5(1)(b)): official Commission text, EDPB guidance, cases, implementation.
GDPR data minimisation (Art 5(1)(c)) and storage limitation (Art 5(1)(e)): official Commission text, retention rules, EDPB guidance, sanctions.
Average cost of dual-compliance platforms in the EU 2026: €4,800/yr SMB to €250K+ enterprise, €14,500 median. Vendor benchmarks, pricing models, ROI.
Schrems II supplementary measures catalog: technical, contractual, organisational. EDPB Recommendations 01/2020, use cases, cloud examples, TIA integration.
GDPR compliance software for France 2026: CNIL requirements (registre, AIPD), market comparison of Legiscope, Dastra, Data Legal Drive, OneTrust + pricing.
GDPR compliance software for Germany 2026: 17 supervisory authorities, BDSG specifics, honest comparison of DataGuard, heyData, OneTrust, Legiscope + pricing.
GDPR compliance software for Spanish SMEs (10-300 employees) 2026: AEPD context, LOPDGDD requirements, honest vendor comparison and real pricing ranges.
GDPR software pricing by company size in 2026: real EUR ranges for 10-50, 50-150, 150-300 and 300+ employee bands, plus manual-cost comparison per DPO hour.
GDPR compliance cost for SMEs in 2026: real total-cost numbers by headcount (10/50/150/300) covering consultants, external DPO, software and internal hours.
GDPR compliance software for Danish companies 2026: Datatilsynet context, Databeskyttelsesloven, court-based fine model, vendor comparison and pricing ranges.
GDPR compliance software for Norwegian companies 2026: Datatilsynet context, EEA + Personopplysningsloven, Grindr fine, honest vendor comparison and pricing.
GDPR compliance software for Portuguese SMEs 2026: CNPD context, Lei 58/2019, real CNPD enforcement, honest vendor comparison and real pricing ranges.
GDPR compliance software for startups: what a 10-50 person company actually needs (ROPA, DPAs, DSAR), when investors demand proof, and tools compared by price.
6 TrustArc alternatives for EU companies in 2026: price, EU hosting, GDPR-first design vs US-framework baggage, and SME implementation time — compared honestly.
Cassie (Syrenis) alternatives for 2026: consent-centric platforms vs full GDPR suites for regulated industries, with pricing models and when a DPO needs which.
One EU compliance platform for GDPR, NIS2, DORA and the AI Act: how the registers overlap, what a single tool consolidates, and vendor selection by size.
GDPR compliance software for Austrian companies 2026: DSB context, Datenschutzgesetz, real DSB enforcement, honest vendor comparison and pricing ranges.
GDPR compliance software for Irish companies 2026: DPC context, Data Protection Act 2018, one-stop-shop reality, honest vendor comparison and pricing ranges.
A numbered GDPR audit checklist by chapter — lawful basis, ROPA, DPAs, rights, security, transfers — plus the tools that automate it. Practical, 2026-ready.
GDPR compliance software for Polish companies 2026: UODO context, Polish Data Protection Act, real UODO fines, honest vendor comparison and pricing ranges.
GDPR compliance software for Swedish companies 2026: IMY context, Dataskyddslagen, real IMY sanktionsavgifter, honest vendor comparison and pricing ranges.
Best DPO software 2026 compared by working mode: internal DPO, outsourced multi-client DPO, and law-firm practices, with Art. 37-39 coverage and pricing.
GDPR compliance software for Belgian SMEs 2026: APD/GBA context, bilingual FR/NL reality, IAB Europe TCF case, honest vendor comparison and real pricing ranges.
GDPR compliance software for Switzerland 2026: dual GDPR + revFADP coverage, FDPIC context, CHF 250,000 criminal liability, vendor comparison and pricing.
ROPA software for Article 30 GDPR: why spreadsheets rot, the exact data fields a tool must capture, and an honest vendor comparison with EUR pricing for 2026.
DSAR software compared for 2026: identity verification, one-month deadline tracking, cross-system search and cost per request, with honest vendor pros and cons.
GDPR compliance software for Italian SMEs (10-300 employees) 2026: Garante context, Codice Privacy requirements, honest vendor comparison and real EUR pricing.
GDPR compliance software for Dutch SMEs (10-300 employees) 2026: Autoriteit Persoonsgegevens context, UAVG requirements, vendor comparison and real EUR pricing.
7 OneTrust alternatives compared for EU companies in 2026: price, implementation time, EU hosting and SME fit — honest pros and cons, no vendor spin.
DPO tasks per Articles 37-39 GDPR: designation thresholds, 9 EDPB-mandated tasks, independence + €170K conflict-of-interest fine + 17K-org survey findings.
Step-by-step 72-hour breach playbook: assess, notify DPA, inform subjects + Meta €265M, Marriott £18.4M cases. Articles 33 + 34 GDPR workflow + template.
Article 5(1)(b) compatible-use test. 7 enforcement cases (€100M+ collectively). Purpose documentation template + CNIL/EDPB compatibility criteria 2026.
Retention periods by sector: HR 5y, customers 3y, accounting 10y. Amazon €746M case. Article 5(1)(e) deletion rules + retention policy template.
GDPR supervisory authorities explained: investigative and corrective powers, one-stop-shop mechanism, EDPB coordination, and fines.
Analysis of the economic and productivity losses caused by cookie banners in Europe, including country-specific estimates and legal insights into the outdated EU Directive 2002/58.
An in-depth analysis of the GDPR's principle of accountability, including legal references, case studies, and practical implementation tips.
Is an IP address personal data under GDPR and CCPA? CJEU Breyer ruling, dynamic vs static IPs, and impact on analytics, logging, and cookie consent.
Core GDPR requirements every organisation must meet, from lawful processing and data subject rights to breach notification and accountability.
A step-by-step guide to conducting a Data Protection Impact Assessment (DPIA) under GDPR Article 35 — when required, what to include, and how to document it.
Understand the GDPR right to erasure (right to be forgotten) under Article 17 — when it applies, the exceptions, and how to handle deletion requests properly.
Learn when legitimate interest applies as a lawful basis under GDPR Article 6(1)(f), how to conduct the three-part balancing test, and common mistakes to avoid.
Understand how GDPR fines are calculated, see the largest penalties to date, and learn what steps your organisation should take to reduce enforcement risk.
Side-by-side comparison of GDPR and CCPA covering scope, consumer rights, consent rules, penalties, and compliance.
Learn how GDPR data breach notification works, the 72-hour reporting rule, what to include, and how to avoid regulatory penalties.
Step-by-step guide to writing a GDPR-compliant privacy policy, covering mandatory content, transparency requirements, and common mistakes to avoid.
Art. 4(1) GDPR defines personal data as any information relating to an identifiable person. Learn the definition, examples, special categories, and key CJEU rulings.
Art. 4(8) GDPR defines data processors as entities processing personal data on behalf of controllers. Learn their duties, Art. 28 contracts, and enforcement risks.
Step-by-step guide to conducting a GDPR-compliant cookie audit. Covers discovery, classification, documentation, gap analysis, and ongoing monitoring.
Most cookie banners fail legal requirements. Learn what ePrivacy and GDPR demand, which dark patterns are illegal, and how to test your banner for compliance.
Complete guide to GDPR data processing agreements: mandatory clauses, sub-processor rules, audit rights, and enforcement examples under Article 28.
Step-by-step guide to conducting a Data Protection Impact Assessment under GDPR Article 35, with triggers, methodology, and enforcement examples.
A step-by-step playbook for GDPR data breach notification within 72 hours, covering risk assessment, authority reporting, and subject communication.
A practical guide to GDPR legitimate interest under Article 6(1)(f), covering the three-part test, LIA documentation, and real enforcement cases.
A manual DPA audit costs EUR 10,400-16,000 and 130-200 hours per year. See the full cost breakdown and how automation cuts DPA review time by 98%.
Manual ROPA creation costs EUR 16,000-21,000 and 200-265 hours. See the full cost breakdown and how automation delivers 5-17x ROI in year one.
Complete guide to GDPR Records of Processing Activities (ROPA) under Article 30, covering mandatory fields, templates, and controller vs processor duties.
A Comprehensive Guide to Using 'Legitimate Interests' as a Legal Basis under the GDPR, Including Challenges, Conditions, and Practical Examples
Article 28 of the GDPR is a critical juncture for compliance, governing the relationship between data controllers and processors
When a DPO is mandatory under GDPR Article 37, how to appoint one, and recent EDPB enforcement findings.
An in-depth analysis of the applicability of GDPR to non-EU companies, including legal obligations, case studies, and practical compliance strategies.
An in-depth analysis of the European Data Protection Board's role in enforcing GDPR, including legal frameworks, case studies, and practical compliance tips.
Ensure your business complies with GDPR by appointing an EU Representative. Our 2024 guide covers roles, responsibilities, and benefits for non-EU companies.