SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    GDPR

    The GDPR, explained for the teams who build with personal data.

    The GDPR — Regulation (EU) 2016/679 — is the EU's data protection law, applicable since 25 May 2018 and binding in its entirety in every Member State. It decides when you may process personal data at all, what the people in the data can demand from you, what you must have in place before something goes wrong, and what it costs when it does.

    Applicability

    Who is in scope

    Two scope dimensions — what the processing is, and where you or the people are — and the controller and processor roles that carry the duties.

    Principles & lawful bases

    Seven principles, six bases, one prohibition

    Article 5 sets what all processing must look like. Article 6 decides whether it may happen at all. Article 9 closes a category of data behind stricter doors.

    Data subject rights

    What the people in your data can demand

    Chapter III gives data subjects enforceable rights against you — on a one-month information clock, free of charge in the ordinary case.

    Obligations

    What you must have in place

    The accountability duties run before, during and after the processing — and two of them come with clocks.

    International transfers

    The Chapter V ladder

    Adequacy first, safeguards second, derogations last — and the rule at the top governs onward transfers too.

    Enforcement

    Two fine tiers, plus the claims you owe individuals

    Article 83 prices infringements by what was infringed. Articles 77 and 82 give individuals their own routes.

    GDPR, NIS2, DORA and the CRA

    Data law, next to the cyber laws

    The GDPR protects the people in the data. The EU's cyber laws regulate entities and products. Treat overlapping duties as parallel, not interchangeable.

    How Ansvar helps

    From article text to a cited gap analysis or DPIA

    Every answer grounded in the regulation, in the AI client your team already uses.

    FAQ

    Questions teams ask about the GDPR

    If your question is not here, email us — every message gets a human answer.

    Does the GDPR apply to my company?

    Two questions decide it: is the processing within the material scope of Article 2 — personal data processed wholly or partly by automated means, plus manual processing that forms or is intended to form part of a filing system — and is there a territorial hook under Article 3. Any one territorial route is enough: an establishment in the Union whose activities the processing relates to (Article 3(1)); with no Union establishment at all, offering goods or services to people who are in the Union, paid or not, or monitoring their behaviour there (Article 3(2)); or a place where Member State law applies by virtue of public international law (Article 3(3)). The trigger is people in the Union, not citizenship. Processing by a natural person in the course of a purely personal or household activity is excluded.

    What are the GDPR fines?

    Article 83 sets two ceilings. The lower tier, Article 83(4): up to EUR 10 000 000 or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher — for the controller and processor obligations (records, security, breach notification, impact assessments and the DPO among them). The upper tier, Article 83(5): up to EUR 20 000 000 or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher — for the basic principles including consent, the data subjects' rights and third-country transfers. Article 82 adds private compensation claims, including for non-material damage.

    What is the deadline for reporting a data breach?

    The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware — unless the breach is unlikely to result in a risk to people's rights and freedoms (Article 33). A later notification carries reasons for the delay, and information may follow in phases without undue further delay. A processor notifies the controller without undue delay. When the breach is likely to result in a high risk, Article 34 adds a second duty: tell the affected people without undue delay — not required where the data were made unintelligible to unauthorised persons (encryption is the named example), where the risk has since been removed, or where individual notice would involve disproportionate effort, in which case a public communication that informs people in an equally effective manner takes its place.

    What counts as valid consent?

    Freely given, specific, informed and unambiguous, given by a statement or a clear affirmative action (Article 4(11)). Article 7 adds the operating conditions: you must be able to demonstrate it; a consent request bundled into a wider declaration must be clearly distinguishable and in plain language; withdrawal must be possible at any time and as easy as giving consent was; and making a contract conditional on consent to unnecessary processing counts against the consent being freely given. Where special-category data under Article 9 rely on consent, it must be explicit.

    When is a data protection impact assessment required?

    Before any processing likely to result in a high risk to people's rights and freedoms, in particular with new technologies — the assessment comes prior to the processing (Article 35(1)). Article 35(3) names three cases in particular: systematic and extensive automated evaluation of personal aspects feeding decisions with legal or similarly significant effects; large-scale processing of special categories or criminal-convictions data; and large-scale systematic monitoring of publicly accessible areas. Your supervisory authority also publishes its own list of processing kinds that trigger the duty.

    Do we need a data protection officer?

    Article 37(1) makes designation mandatory in three cases: you are a public authority or body (courts acting in their judicial capacity excepted); your core activities require regular and systematic monitoring of data subjects on a large scale; or your core activities consist of large-scale processing of the Article 9 special categories and of criminal-convictions data. Otherwise designation is voluntary unless Union or Member State law requires it. A group of undertakings may appoint a single DPO, provided the DPO is easily accessible from each establishment.

    Do small companies have to keep records of processing?

    Often yes. Article 30(5) lifts the record-keeping duty below 250 employees only where the processing is not likely to pose a risk, is only occasional, and includes no special categories and no criminal-convictions data — all three at once. As a practical reading (the Regulation does not define occasional), processing that is a regular part of how the business runs is unlikely to qualify. For a controller the record is the Article 30(1) list — purposes, categories, recipients, transfers, erasure time limits, security measures; a processor keeps the narrower Article 30(2) record of the categories of processing it runs for each controller. Both are kept in writing and shown to the supervisory authority on request.

    How do we transfer personal data outside the EU?

    Chapter V is a ladder, and Article 44 makes it govern onward transfers too. First rung: an Article 45 adequacy decision — the Commission has decided the destination ensures adequate protection, and the transfer needs no specific authorisation. Second, absent adequacy: Article 46 appropriate safeguards with enforceable rights and remedies — the Commission's standard data protection clauses, binding corporate rules, or approved codes of conduct and certification mechanisms together with binding and enforceable commitments from the receiving side. Last rung: the Article 49 derogations for specific situations, explicit consent after being informed of the risks and contract necessity among them, with a tightly conditioned, documented one-off route at the very bottom.

    See where you stand on the GDPR

    A free-tier run produces a cited GDPR gap analysis or DPIA of a system you describe — one row per requirement, each anchored to its article. Start there, then bring your own documents on a paid plan.