Skip navigation

What is GDPR compliance?

A data breach involving EU residents can trigger fines, investigations, and mandatory notifications within 72 hours. General Data Protection Regulation (GDPR) compliance defines how to protect that data and document it for regulators.

What is GDPR compliance

Key takeaways

  • GDPR applies globally based on the data you process, not where you are located. Any organization handling EU residents' personal data must comply, whether the organization is in Berlin, Boston, or Bangalore.

  • The regulation is built on seven principles that guide every compliance decision. Lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability form the foundation. Article 32 specifically requires technical security measures like encryption and access controls.

  • Identity security is central to compliance. Controlling who accesses personal data, verifying their identity through MFA, and monitoring access patterns directly support GDPR's integrity and confidentiality requirements.

  • Compliance is ongoing, not a one-time project. Regular audits, access reviews, staff training, and vendor management are required to maintain compliance as the organization and threat landscape evolve.

What are the data protection principles under GDPR?

GDPR is built on seven core principles for handling personal data defined in Article 5.

Personal data under GDPR means any information relating to an identified or identifiable person: names, email addresses, IP addresses, location data, biometric data, and even online identifiers like cookies.

These seven principles are binding obligations that shape every decision an organization makes about personal data, from collection through deletion.

  1. Lawfulness, fairness, and transparency: every processing activity must have a documented legal basis, be fair to the individual, and be communicated clearly. Lawful grounds include consent, contract performance, and legitimate interest, as defined in Article 6.

  2. Purpose limitation: data collected for one stated purpose cannot be reused for unrelated reasons. An email address collected for order confirmations cannot later be used for marketing without separate justification.

  3. Data minimization: organizations collect only the data necessary for the stated purpose. If a service only needs an email address, it should not also collect a home address, phone number, and date of birth.

  4. Accuracy: personal data must be accurate and kept up to date. Individuals have the right to request corrections to inaccurate data.

  5. Storage limitation: data should be retained only as long as necessary for its stated purpose. Once that purpose is fulfilled, the data must be deleted or anonymized, and retention periods must be documented for each data category.

  6. Integrity and confidentiality: organizations must protect personal data against unauthorized access, loss, or damage using appropriate technical and organizational measures. Article 32 specifies these measures, including encryption, access controls, and regular security testing. This is where identity security connects most directly to GDPR.

  7. Accountability: organizations must document compliance through audits and impact assessments and be prepared to prove it to regulators.

What are the key GDPR compliance guidelines?

Knowing the principles is one thing. Putting them into practice requires decisions about legal justification, transparency, individual rights, and technical security measures.

Every processing activity needs a documented legal justification, with six lawful bases defined in Article 6. They are:

  • Consent

  • Contract performance

  • Legal obligation

  • Vital interests

  • Public task

  • Legitimate interests

Most commercial processing relies on consent or legitimate interest, and the chosen basis must be documented before processing begins.

Organizations must clearly communicate how they use personal data, typically through privacy notices, and maintain Records of Processing Activities (RoPAs) as required by Article 30. RoPAs document what data is processed, why, where it is stored, who has access, and how long it is retained. These records are the primary evidence of compliance during regulatory inquiries.

GDPR grants individuals rights over their personal data. These include the right to access their data (Article 15), correct inaccuracies (Article 16), request deletion (Article 17, the "right to be forgotten"), restrict processing (Article 18), receive their data in a portable format (Article 20), and object to processing (Article 21). Organizations must respond to these requests within one month.

Finally, Article 32 requires measures that ensure a level of security appropriate to the risk. The regulation specifically mentions encryption and pseudonymization, but identity security measures like multi-factor authentication, role-based access control, and continuous monitoring of access patterns are equally critical. In fact, weak authentication and excessive access permissions recently led to a breach that resulted in €42 million, or around $48.7 million, in combined fines (Kiteworks, 2026).

Flowchart of the 5 GDPR compliance steps: data scope, access controls and MFA, documentation, ongoing monitoring, and breach response

What are the steps to comply with GDPR?

GDPR compliance requires a structured approach that spans data governance, technical controls, documentation, and ongoing monitoring. These five steps provide a practical framework for GDPR compliant data practices at any stage of compliance maturity.

1. Determine your data scope

Start with a data mapping exercise. Inventory all personal data your organization collects, processes, and stores. Document where each data category is stored, who has access, why it is processed, and how long it is retained. This inventory becomes your Records of Processing Activities (Article 30) and is the foundation for every other compliance step.

From an identity security perspective, data mapping also reveals which systems and users have access to personal data. This is the starting point for applying least privilege ensuring that each user, application, and service account has access only to the data their function requires.

2. Enforce strong access controls and MFA

Article 32 requires appropriate technical measures to protect personal data. Strong access controls and multi-factor authentication (MFA) are the most direct implementation of that requirement. MFA, which requires two or more verification factors (something the user knows, has, or is), prevents unauthorized access even when credentials are compromised. Phishing-resistant methods, like FIDO2 security keys or passkeys, are particularly effective because they resist the credential theft that drives the many identity-based breaches.

Consider role-based access control (RBAC), which assigns permissions based on job function rather than individual identity. This limits access to sensitive customer data, so that compromised accounts do not necessarily become GDPR compliance risks. Adding just-in-time access, which provides temporary elevated permissions that expire automatically, reduces the window during which compromised credentials can cause damage. Regular access reviews catch permission creep, where users accumulate unnecessary access over time as they change roles.

3. Document and audit existing processes

GDPR's accountability principle (Article 5(2)) requires organizations to demonstrate compliance, not just claim it. Documentation is evidence. Key documents include Records of Processing Activities, data processing agreements with third-party vendors, consent records, Data Protection Impact Assessments (DPIAs, required by Article 35 for high-risk processing), and security policies governing access and data handling.

Audit logs of user access and authentication events are essential for both compliance documentation and breach detection. These logs record who accessed what data, when, and from where, creating the audit trail that regulators expect during inquiries. Conduct internal audits at least annually, with more frequent reviews for privileged accounts and high-risk processing activities.

4. Implement ongoing monitoring and reporting

GDPR compliance requires continuous monitoring. Monitor authentication events (failed and successful login attempts), access to sensitive personal data, changes to user permissions or roles, data exports or large file transfers, and geographic or time-based access anomalies. These signals help detect compromised identities, insider threats, and unauthorized access before they become reportable breaches.

Article 33 requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. Article 34 requires notification to affected individuals when the breach poses a high risk to their rights and freedoms. Monitoring infrastructure is what makes this timeline achievable.

5. Develop a breach response strategy

A documented incident response plan is required under GDPR. The plan should define how to detect a breach, contain it (isolate affected systems, revoke compromised access), assess its scope and impact, issue a breach notification to authorities within 72 hours, notify affected individuals if the breach poses high risk, and conduct a post-incident review to update controls.

Identity-related breaches, where stolen credentials or compromised accounts are the attack vector, are among the most common. The response plan should include specific steps for revoking access, resetting credentials, and investigating the scope of compromised identities.

Regular breach simulation exercises (tabletop drills) test the plan before a real incident forces you to rely on it. These exercises reveal gaps in roles, communication chains, and technical capabilities that are easier to fix in advance.

What are common challenges in complying with GDPR?

While essential, GDPR compliance is not straightforward. Four challenges appear in nearly every organization working toward or maintaining compliance.

Extraterritorial reach
GDPR applies to any organization processing EU residents' data, even if the company is headquartered outside the EU. A U.S.-based SaaS company with European customers must comply. Many organizations underestimate this scope and discover their obligations only after a complaint or investigation.

Intentionally broad language
Some GDPR provisions, like Article 32's requirement for "appropriate technical and organizational measures," are deliberately broad. This flexibility allows the regulation to adapt to different industries and technologies, but it also means organizations must interpret what "appropriate" means for their specific context, risk profile, and data processing activities.

Resource constraints
Small and mid-sized organizations may lack dedicated data protection officers or compliance teams. Documentation requirements (RoPAs, DPIAs, consent records, audit logs) are substantial and maintaining them over time requires sustained investment that smaller teams struggle to resource.

Third-party risk
GDPR holds data controllers responsible for the actions of their data processors. A controller is the organization that determines why and how personal data is processed. A processor is the organization that handles data on the controller's behalf (a cloud storage provider, a payroll vendor, an email marketing platform). If a processor mishandles data, the controller can still be liable. Data processing agreements, vendor audits, and compliance certifications (SOC 2, ISO 27001) are essential for managing this risk.

How should organizations manage GDPR data subject requests?

GDPR grants individuals the right to access, correct, delete, and port their personal data (Articles 15 through 20). When someone exercises these rights, the organization receives a Data Subject Access Request (DSAR). GDPR compliance requires a response within one month (Article 12).

  • Verify the user's identity. Confirm the requester's identity through secure channels. Match the verification level to the sensitivity of the request.

  • Use your data inventory. The data mapping from your compliance scoping work tells you where to look.

  • Coordinate with processors early. If third-party vendors process data on your behalf, loop them in immediately. The one-month clock runs regardless of vendor response times.

  • Deliver and delete securely. Use encrypted channels for data delivery and document erasure actions, including any technical limitations (like backup retention schedules) that prevent immediate full deletion.

  • Track and learn from requests. DSAR volume and type reveal patterns. Frequent erasure requests from a specific user segment may signal a consent or transparency problem worth fixing upstream.

How can organizations maintain ongoing GDPR control?

Four ongoing activities keep EU GDPR compliance current as the organization, its data practices, and the threat landscape evolve.

  • Conduct regular audits and access reviews. Review access permissions, data inventories, and security controls at least quarterly. Update Records of Processing Activities as data practices change. Privileged accounts warrant more frequent review. Organizations that follow an IAM compliance framework will find that access certification and review requirements map directly to GDPR's accountability principle.

  • Train employees on GDPR principles, data handling practices, and how to recognize phishing and social engineering attacks, which are a leading vector for breaches that trigger GDPR enforcement. Training should be role-specific: the obligations of someone handling customer data differ from those of a developer or executive.

  • Update policies as the organization adopts new technologies, like cloud services, AI tools, and new SaaS applications. Privacy policies, consent mechanisms, and security measures must be reviewed and updated. New processing activities may require fresh Data Protection Impact Assessments.

  • Audit third-party processors regularly, review data processing agreements, request compliance certifications (SOC 2, ISO 27001) and conduct audits where appropriate. Changes in a processor's data practices or security posture can affect your compliance status.

How can identity security strengthen GDPR compliance?

GDPR's integrity and confidentiality principle (Article 5(1)(f)) and its security of processing requirements (Article 32) both point to the same conclusion: protecting personal data requires controlling who accesses it and how. An identity-centric approach to GDPR compliance addresses these requirements directly.

Organizations that align to the NIST Cybersecurity Framework will find that subcategories in the Protect and Govern functions directly satisfy Article 32's technical and organizational requirements.

Phishing-resistant MFA prevents unauthorized access at the authentication layer, directly supporting Article 32's requirement for appropriate technical measures. It also reduces the risk of credential-based breaches that trigger the 72-hour notification requirement.

Device trust verifies that devices meet security standards before granting access to systems containing personal data. A compromised or unmanaged device with valid credentials still poses a risk, and device health checks address that gap.

Single sign-on (SSO) centralizes authentication and access control across applications, making it easier to enforce consistent policies and maintain the audit trails that GDPR's accountability principle requires.

Continuous monitoring provides visibility into authentication patterns, anomalous access behavior, and permission drift. These signals support both the Detect function (identifying breaches early) and the accountability requirement (documenting who accessed what and when).

Adaptive access policies adjust authentication requirements based on context like device health, location, and behavioral signals. Higher-risk access attempts trigger additional verification, while trusted access proceeds with minimal friction. This supports Article 32's proportionality requirement, matching security to risk level.

See for yourself how Duo's IAM platform with phishing-resistant MFA, device trust, SSO, and more, can strengthen your organization's security and help with GDPR compliance. Try Duo for free.

Frequently asked questions about GDPR compliance

Common questions about GDPR compliance, from extraterritorial scope to data subject request timelines.

  • Does GDPR apply to organizations outside the European Union?

    Yes. GDPR applies to any organization that processes personal data of EU residents, regardless of where the organization is located. This extraterritorial reach means a U.S.-based company offering services to EU customers, or a company monitoring EU residents' behavior online, must comply with GDPR.

  • What is the time limit to respond to a data subject access request under GDPR?
  • How can organizations ensure third-party vendors are GDPR compliant?
  • What are the penalties for failing to comply with GDPR?
  • How does GDPR define personal data?

Want to learn more about access and identity security?

Discover more 'what-is' content and learning resources, including ebooks, guides and webinars, crafted to help you enhance your organization's access security strategy.