Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
GDPR

GDPR: security of processing you can evidence, not just describe

Map the GDPR's accountability and security requirements to controls with automated checks, keep your records of processing, impact assessments and processor agreements as dated evidence, and show a customer, a regulator or an auditor that the safeguards operate.

What is GDPR?

The GDPR is the European Union's General Data Protection Regulation, in force since 25 May 2018 and mirrored in the UK as the UK GDPR. It applies to any organization that processes personal data about people in the EU, whether as a controller deciding why and how data is processed or as a processor acting on a controller's instructions, regardless of where the organization is based. It rests on principles such as lawfulness, purpose limitation, data minimization and accountability, and it gives people rights over their data: access, rectification, erasure, portability and objection. Organizations must keep records of processing activities, run data protection impact assessments for high-risk processing, bind processors with written agreements, secure processing with appropriate technical and organizational measures, report qualifying breaches to the supervisory authority within 72 hours, and in some cases appoint a data protection officer. Supervisory authorities can fine up to 20 million euros or 4 percent of worldwide annual turnover, whichever is higher. There is no mandatory certification; compliance is shown through documentation and evidence that safeguards operate.

In one paragraph

The General Data Protection Regulation (EU) 2016/679 is the European Union's data protection law, applied since 25 May 2018. It governs any organization that processes the personal data of people in the EU, wherever the organization is based, and the UK GDPR carries the same regime in the United Kingdom. There is no mandatory GDPR certificate; compliance is demonstrated through documentation, implemented safeguards and the ability to honor people's rights.

Who it's for

Companies with customers, users or employees in the EU or the UK, and any SaaS vendor whose customers ask for a data processing agreement before they sign.

With Viglyn

How Viglyn runs GDPR

  • Article 32 security of processing mapped to controls with automated checks on encryption, access, logging, backups and change management across your cloud, identity and code systems
  • Records of processing activities, data protection impact assessments and legitimate-interest assessments held as dated evidence with a full audit trail
  • Processor and sub-processor management in the vendor module: data processing agreements, transfer mechanisms and assessments per vendor
  • Data subject request and breach notification procedures as controlled documents, with the 72-hour clock and incident records as evidence that the process ran
  • One evidence base shared with ISO 27001, ISO 27701 and SOC 2, so the security work is done once
Straight answers

The GDPR questions that decide it

Is there a GDPR certification?

Not a mandatory one. Article 42 allows approved certification schemes, but most organizations demonstrate compliance through documentation, implemented safeguards and audits of them. Many pair GDPR work with ISO 27001 and ISO 27701, which do carry certificates buyers recognize.

Does GDPR apply to a company outside the EU?

Yes, if you offer goods or services to people in the EU or monitor their behavior, or if you process EU personal data for a customer who does. A SaaS vendor with EU customers is usually a processor under the regulation, and those customers will ask for a data processing agreement and evidence of your safeguards.

How much does GDPR cost with Viglyn?

GDPR counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no auditor fee unless you choose an independent audit or certification, which you would pay directly; we take no commission.

Compared with

GDPR against the standards it is weighed with

FAQ

More GDPR questions

What is the difference between a controller and a processor?
A controller decides why and how personal data is processed; a processor handles it on the controller's documented instructions. Most SaaS vendors are processors for their customers' data and controllers for their own employees and marketing contacts, and the obligations differ for each role.
What does Article 32 actually require?
Technical and organizational measures appropriate to the risk, which the regulation illustrates with pseudonymization and encryption, the ability to ensure confidentiality, integrity, availability and resilience, the ability to restore access after an incident, and regular testing of the measures. These are the controls Viglyn checks automatically.
How fast must we report a breach?
To the supervisory authority within 72 hours of becoming aware of it, where the breach is likely to result in a risk to people, and to the affected people without undue delay where the risk is high. Processors must notify their controllers without undue delay.

See GDPR run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.