Compliance · Data protection
GDPR, evidenced end to end.
The EU's data-protection law: how personal data may be collected, used, shared and kept, and what the people it describes can demand of you.
- 4%of turnover, top fine tier
- 72 hbreach notification window
- 2018in force since 25 May
General Data Protection Regulation (EU) 2016/679
The GDPR sets one rule-book for personal data across the EU and EEA. It applies to any organisation established there, and to any organisation anywhere that offers goods or services to people in the EU or monitors their behaviour. A Moldovan lender with EU customers, or a SaaS with EU users, is in scope regardless of where its servers sit.
The regulation is principle-based: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Every processing activity has to rest on one of six lawful bases, and you have to be able to prove that it does.
Compliance is therefore mostly evidence: a record of processing activities, documented lawful bases, impact assessments for risky processing, processor contracts and a tested breach-response procedure. Those are the artefacts a supervisory authority asks for first.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Lawful basis for every processing activity
Each purpose must rest on one of the six Art. 6 bases — consent, contract, legal obligation, vital interests, public task or legitimate interests — and be documented before processing starts.
Record of processing activities (Art. 30)
A living inventory of what data you hold, why, on what basis, who receives it, how long you keep it and how it is protected. The first document an authority requests.
Data-subject rights within one month
Access, rectification, erasure, restriction, portability and objection (Arts. 15–22), answered within one month, with identity verified and exemptions applied correctly.
Privacy by design and by default (Art. 25)
Data minimisation, pseudonymisation and restrictive defaults built into products and processes rather than bolted on after launch.
72-hour breach notification (Arts. 33–34)
Personal-data breaches reported to the supervisory authority within 72 hours of awareness, and to affected individuals without undue delay when the risk to them is high.
Data Protection Impact Assessments (Art. 35)
A structured risk assessment before high-risk processing such as large-scale profiling, biometrics or systematic monitoring, with prior consultation of the authority where residual risk stays high.
Processor contracts and international transfers
Art. 28 terms with every processor, and a valid transfer mechanism — adequacy decision, standard contractual clauses with a transfer impact assessment, or binding corporate rules — for data leaving the EEA.
Data Protection Officer where required (Art. 37)
Mandatory for public bodies and for organisations whose core activities involve large-scale monitoring or special-category data; advisable for most regulated businesses.
The cost of getting it wrong
- Administrative fines up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements; €10 million or 2% for the lower tier
- Orders to suspend processing or data transfers, which can halt a product overnight
- Compensation claims from individuals and representative actions
- Lost enterprise deals — EU buyers require GDPR evidence in vendor due diligence
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Data mapping and gap assessment
We inventory processing activities, systems and data flows, then score each against the regulation to produce a prioritised gap register.
- 02
Lawful bases, notices and records
We document the basis for every purpose, draft layered privacy notices and build the Art. 30 record in a form that stays maintainable.
- 03
Controls and privacy by design
Our security team implements the technical measures: access control, encryption, retention automation, pseudonymisation and logging.
- 04
DPIAs, processor contracts and transfers
We run the impact assessments, negotiate Art. 28 terms and put a defensible transfer mechanism in place for every non-EEA recipient.
- 05
DPO-as-a-service and breach readiness
We act as your outsourced Data Protection Officer, handle rights requests, run breach drills and keep the programme current as guidance evolves.
Deliverables
- Record of processing activities (Art. 30) and data-flow maps
- Gap assessment and prioritised remediation roadmap
- Privacy notices, consent flows and cookie governance
- Policies for retention, rights handling, breach response and vendor management
- DPIA templates and completed assessments for high-risk processing
- Art. 28 processor agreements and transfer documentation
- Staff training and an annual compliance review
Questions we hear most
We are based in Moldova. Does the GDPR apply to us?
If you offer goods or services to people in the EU, or monitor their behaviour, yes — Art. 3(2) applies regardless of where you are established. Moldovan processors working for EU controllers are also bound by Art. 28 contract terms.
Do we need a Data Protection Officer?
It is mandatory for public bodies and for organisations whose core activities involve large-scale, regular monitoring or special-category data. Many others appoint one voluntarily; our DPO-as-a-service covers both cases without a full-time hire.
Is GDPR a certification?
No. There is no official GDPR certificate; compliance is demonstrated through documentation and evidence. ISO 27701 is the closest certifiable standard and pairs well with a GDPR programme.
How does the GDPR relate to cookie consent?
Cookie consent is governed by the ePrivacy Directive, with the GDPR defining what valid consent looks like. Non-essential cookies need prior, granular, withdrawable consent — which is how this site's own banner works.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.