Privacy & Security →Compliance→ GDPR
GDPR Compliance
The General Data Protection Regulation is the world's most comprehensive data privacy law. If you collect or process personal data from EU residents — regardless of where your organisation is headquartered — GDPR applies. AIQA helps you build compliant data practices from the ground up.
What It Is
Privacy by Design — Not Afterthought
GDPR, in force since May 2018, grants EU residents significant rights over their personal data and imposes strict obligations on organisations that process it. It applies extraterritorially — any organisation targeting or monitoring EU residents must comply, regardless of where it is established.
Fines can reach €20 million or 4% of global annual turnover — whichever is higher. Supervisory authorities across EU member states enforce compliance through investigations, audits, and binding decisions.
Six Lawful Bases
Processing personal data is only lawful under one of six bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Identifying and documenting the correct basis for each processing activity is a foundational compliance requirement.
Quick Facts
- ▸In force May 25, 2018
- ▸Max fine €20M or 4% global revenue
- ▸Scope Any org processing EU residents' data
- ▸Breach notification 72 hours to supervisory authority
- ▸Key principle Privacy by design and default
Core Principles
Seven Principles of GDPR
Lawfulness
Processing must have a valid legal basis.
Purpose Limitation
Data collected for specific, explicit, legitimate purposes only.
Data Minimisation
Only collect what is necessary for the stated purpose.
Accuracy
Personal data must be kept accurate and up to date.
Storage Limitation
Data must not be kept longer than necessary.
Integrity & Confidentiality
Appropriate security measures must protect personal data.
Accountability
Controllers must demonstrate compliance proactively.
How AIQA Helps
End-to-End GDPR Programme
Data Mapping & RoPA
We inventory your personal data assets, document processing activities, and build a complete Record of Processing Activities (RoPA) — the GDPR accountability cornerstone.
Privacy by Design
We embed data protection into your product and system architecture from the start, including Data Protection Impact Assessments (DPIAs) for high-risk processing.
Rights & Response
We build operational workflows for handling data subject rights requests — access, erasure, portability, objection — within GDPR's strict timelines.
Common Challenges
Where Organisations Struggle
Consent Management
Obtaining, recording, and managing valid consent — and honouring withdrawals — across multiple channels and systems is operationally complex.
Third-Party Data Flows
Ensuring processors and sub-processors provide adequate guarantees and operate under compliant data processing agreements requires active vendor management.
Cross-Border Transfers
Transferring personal data outside the EEA requires appropriate transfer mechanisms — SCCs, adequacy decisions, or BCRs — that are up to date.
Breach Response
A 72-hour notification window leaves little room for error. Organisations without practiced incident response processes regularly miss it.
Other Compliance Frameworks
Start With a Complimentary GDPR Consultation
We will review your current data practices, identify the highest-risk processing activities, and give you a clear view of where to focus first. No cost, no commitment.
30–60 minutes. No cost. No commitment.