Kardu
Europa · GDPR

Your data management,under control

The GDPR (General Data Protection Regulation) governs how any organization processes personal data of people in the European Union. It has applied since May 25, 2018, with the same text across all 27 countries.

This guide summarizes the regulation in plain language and does not replace legal advice. Always check the official text before making decisions.

What the GDPR is

It applies to any organization that processes personal data of people in the EU, whether or not the company is established in Europe, and rests on three pillars.

Data subject rights

Access, rectification, erasure, objection, portability and restriction of processing, for anyone whose data is processed in the EU.

6 legal bases

Every processing activity needs a legal basis: consent, contract, legal obligation, vital interest, public interest or legitimate interest.

One authority per country

Each member state has its own data protection authority — in Spain, the AEPD — coordinated under the same regulation.

From the 1995 directive to the GDPR

01 / 1995

The earlier directive

Directive 95/46/EC lays the groundwork for data protection in the EU, but each country implements it differently.

02 / 2016

GDPR adopted

Regulation (EU) 2016/679 is adopted as a directly applicable regulation, not a directive to transpose.

03 / May 25, 2018

Full application

The GDPR becomes applicable across the EU, with the same text and the same maximum fines in all 27 countries.

By the numbers

€20M/4%

Maximum fine

72 hours

Deadline to report breaches

99

Articles

6

Legal bases

Sanctions

The GDPR defines two fine tiers based on the severity of the infringement. Each country’s authority applies the regulation with its own proportionality criteria.

CategoryFineExamples
Lower-tier infringementsUp to €10M or 2% of global turnoverNot keeping a record of processing activities, not reporting a breach on time, failing Article 32 security obligations.
Higher-tier infringementsUp to €20M or 4% of global turnoverProcessing data without a legal basis, violating data subject rights, transferring data outside the EU without adequate safeguards.

46.2%

How much ISO 27001 covers of the GDPR

According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 46.2% of GDPR requirements (43 of 93 controls). It’s the lowest coverage of the 4 frameworks because the GDPR regulates legal and consent obligations that go beyond information security.

What it means for your SME

The GDPR has no size threshold: if your SME has web forms, a customer database, payroll, or uses analytics cookies, it is already processing personal data.

Most SMEs don’t need to appoint a formal Data Protection Officer (DPO). Whether your organization needs one depends on specifics of your operation; it’s worth confirming with legal counsel.

6 minimum requirements

  • A clear, accessible privacy policy
  • A documented legal basis for each processing activity
  • A Record of Processing Activities (RoPA)
  • Data processing agreements (DPAs) with your vendors
  • A breach protocol with a 72-hour deadline
  • A channel for rights requests (ARSOP)

Official sources

This guide is a summary. For the legal detail, consult the regulation’s text directly.

Official GDPR text on EUR-Lex →
How Kardu helps

ISO 27001 as the base, GDPR included

Kardu organizes your compliance evidence around ISO 27001 and maps it to the GDPR and any other frameworks that apply to you, so you don’t duplicate work across regulations.