Your data management,under control
The GDPR (General Data Protection Regulation) governs how any organization processes personal data of people in the European Union. It has applied since May 25, 2018, with the same text across all 27 countries.
This guide summarizes the regulation in plain language and does not replace legal advice. Always check the official text before making decisions.
What the GDPR is
It applies to any organization that processes personal data of people in the EU, whether or not the company is established in Europe, and rests on three pillars.
Data subject rights
Access, rectification, erasure, objection, portability and restriction of processing, for anyone whose data is processed in the EU.
6 legal bases
Every processing activity needs a legal basis: consent, contract, legal obligation, vital interest, public interest or legitimate interest.
One authority per country
Each member state has its own data protection authority — in Spain, the AEPD — coordinated under the same regulation.
From the 1995 directive to the GDPR
01 / 1995
The earlier directive
Directive 95/46/EC lays the groundwork for data protection in the EU, but each country implements it differently.
02 / 2016
GDPR adopted
Regulation (EU) 2016/679 is adopted as a directly applicable regulation, not a directive to transpose.
03 / May 25, 2018
Full application
The GDPR becomes applicable across the EU, with the same text and the same maximum fines in all 27 countries.
€20M/4%
Maximum fine
72 hours
Deadline to report breaches
99
Articles
6
Legal bases
Sanctions
The GDPR defines two fine tiers based on the severity of the infringement. Each country’s authority applies the regulation with its own proportionality criteria.
| Category | Fine | Examples |
|---|---|---|
| Lower-tier infringements | Up to €10M or 2% of global turnover | Not keeping a record of processing activities, not reporting a breach on time, failing Article 32 security obligations. |
| Higher-tier infringements | Up to €20M or 4% of global turnover | Processing data without a legal basis, violating data subject rights, transferring data outside the EU without adequate safeguards. |
46.2%
How much ISO 27001 covers of the GDPR
According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 46.2% of GDPR requirements (43 of 93 controls). It’s the lowest coverage of the 4 frameworks because the GDPR regulates legal and consent obligations that go beyond information security.
What it means for your SME
The GDPR has no size threshold: if your SME has web forms, a customer database, payroll, or uses analytics cookies, it is already processing personal data.
Most SMEs don’t need to appoint a formal Data Protection Officer (DPO). Whether your organization needs one depends on specifics of your operation; it’s worth confirming with legal counsel.
6 minimum requirements
- A clear, accessible privacy policy
- A documented legal basis for each processing activity
- A Record of Processing Activities (RoPA)
- Data processing agreements (DPAs) with your vendors
- A breach protocol with a 72-hour deadline
- A channel for rights requests (ARSOP)
Official sources
This guide is a summary. For the legal detail, consult the regulation’s text directly.
Official GDPR text on EUR-Lex →ISO 27001 as the base, GDPR included
Kardu organizes your compliance evidence around ISO 27001 and maps it to the GDPR and any other frameworks that apply to you, so you don’t duplicate work across regulations.