GDPR: security of processing you can evidence, not just describe
Map the GDPR's accountability and security requirements to controls with automated checks, keep your records of processing, impact assessments and processor agreements as dated evidence, and show a customer, a regulator or an auditor that the safeguards operate.
What is GDPR?
The GDPR is the European Union's General Data Protection Regulation, in force since 25 May 2018 and mirrored in the UK as the UK GDPR. It applies to any organization that processes personal data about people in the EU, whether as a controller deciding why and how data is processed or as a processor acting on a controller's instructions, regardless of where the organization is based. It rests on principles such as lawfulness, purpose limitation, data minimization and accountability, and it gives people rights over their data: access, rectification, erasure, portability and objection. Organizations must keep records of processing activities, run data protection impact assessments for high-risk processing, bind processors with written agreements, secure processing with appropriate technical and organizational measures, report qualifying breaches to the supervisory authority within 72 hours, and in some cases appoint a data protection officer. Supervisory authorities can fine up to 20 million euros or 4 percent of worldwide annual turnover, whichever is higher. There is no mandatory certification; compliance is shown through documentation and evidence that safeguards operate.
The General Data Protection Regulation (EU) 2016/679 is the European Union's data protection law, applied since 25 May 2018. It governs any organization that processes the personal data of people in the EU, wherever the organization is based, and the UK GDPR carries the same regime in the United Kingdom. There is no mandatory GDPR certificate; compliance is demonstrated through documentation, implemented safeguards and the ability to honor people's rights.
Companies with customers, users or employees in the EU or the UK, and any SaaS vendor whose customers ask for a data processing agreement before they sign.
How Viglyn runs GDPR
- Article 32 security of processing mapped to controls with automated checks on encryption, access, logging, backups and change management across your cloud, identity and code systems
- Records of processing activities, data protection impact assessments and legitimate-interest assessments held as dated evidence with a full audit trail
- Processor and sub-processor management in the vendor module: data processing agreements, transfer mechanisms and assessments per vendor
- Data subject request and breach notification procedures as controlled documents, with the 72-hour clock and incident records as evidence that the process ran
- One evidence base shared with ISO 27001, ISO 27701 and SOC 2, so the security work is done once
The GDPR questions that decide it
Is there a GDPR certification?
Not a mandatory one. Article 42 allows approved certification schemes, but most organizations demonstrate compliance through documentation, implemented safeguards and audits of them. Many pair GDPR work with ISO 27001 and ISO 27701, which do carry certificates buyers recognize.
Does GDPR apply to a company outside the EU?
Yes, if you offer goods or services to people in the EU or monitor their behavior, or if you process EU personal data for a customer who does. A SaaS vendor with EU customers is usually a processor under the regulation, and those customers will ask for a data processing agreement and evidence of your safeguards.
How much does GDPR cost with Viglyn?
GDPR counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no auditor fee unless you choose an independent audit or certification, which you would pay directly; we take no commission.
GDPR against the standards it is weighed with
More GDPR questions
What is the difference between a controller and a processor?
What does Article 32 actually require?
How fast must we report a breach?
See GDPR run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
