Skip to content

GDPR

Regulation (EU) 2016/679, applicable since May 2018. A direct legal obligation, with no certificate that proves it.

What the GDPR is

The General Data Protection Regulation is directly applicable across the European Union. It governs the processing of personal data: what you may do with it, under what conditions, and what rights the people whose data you process have.

In Spain it is complemented by Organic Law 3/2018 on Personal Data Protection and the guarantee of digital rights.

There is no certificate attesting compliance with the GDPR. The certification schemes under Article 42 exist, but they are limited in scope and are not equivalent to a general declaration of conformity.

Who the GDPR applies to

  • Any organisation established in the EU that processes personal data
  • Organisations outside the EU offering goods or services to people in the EU, or monitoring their behaviour

There is no size threshold. A three-person company with a mailing list processes personal data and is inside.

What the GDPR requires

Principles (Art. 5). Lawfulness, fairness and transparency. Purpose limitation. Minimisation. Accuracy. Storage limitation. Integrity and confidentiality. And accountability: complying is not enough, you have to be able to demonstrate it.

Legal basis (Art. 6). Every processing operation needs one, and consent is only one of six.

Rights of individuals (Arts. 15 to 22). Access, rectification, erasure, restriction, portability and objection, with response deadlines.

Documentation obligations. Records of processing activities (Art. 30). Data protection impact assessments where processing is high risk (Art. 35). Processor contracts (Art. 28). A data protection officer where Art. 37 applies.

Personal data breaches. Notification to the supervisory authority within 72 hours of becoming aware, and communication to the individuals affected where the risk to their rights is high (Arts. 33 and 34).

How the GDPR is demonstrated

Not with a certificate. With documentation: the record of processing activities, the legal bases, the impact assessments, the processor contracts, the policies and the records of rights requests.

In an inspection, that is the body of evidence that gets reviewed.

With Zerod

The GDPR is not something you pass. It is something you evidence. Zerod is built to leave a trail.

Zerod handles the GDPR two ways. As an activatable framework, with its control register and evidence collection, like the rest. And through the privacy module, which covers the data protection work specifically.

Frequently asked questions

Is there a GDPR compliance certificate?

Not a general one. The Regulation provides for certification schemes, but there is no certificate attesting compliance with the GDPR as a whole. Anyone offering one is selling something else.

Do I need a data protection officer?

It is mandatory in the cases set out in Article 37: public authorities, regular and systematic monitoring on a large scale, or large-scale processing of special categories of data. Outside those cases it is voluntary.

GDPR · Zerod