Compliance · Regulation

GDPR — EU General Data Protection Regulation

It applies to you based on whose data you touch — not where you're incorporated.

The GDPR governs personal data of people in the EU and UK, regardless of where your company sits. It's a law, not a certification — so the goal isn't a certificate, it's being able to demonstrate accountability when a customer, partner, or regulator asks.

72 hrs

Breach notification

4% / €20M

Max penalty

Extra-territorial

Reach

What GDPR requires

Accountability is the theme — you must not only comply, but be able to show it.

Lawful basis & purpose

Every processing activity needs a lawful basis and a defined purpose. 'We might need it later' is not one, and consent is not always the right choice.

Data subject rights

Access, rectification, erasure, portability, restriction, and objection — each with statutory deadlines you have to meet operationally, not theoretically.

Accountability & transfers

ROPAs, DPIAs for high-risk processing, processor contracts, and a lawful mechanism for moving data outside the EEA.

Who GDPR applies to

Far more organizations than realize it.

  • Any company offering goods or services to people in the EU or UK
  • Organizations monitoring the behavior of EU/UK individuals
  • US companies with EU customers, users, or employees
  • Processors handling EU personal data for their customers

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Data mapping & ROPA

We find the personal data, map the flows, and build the records of processing everything else depends on.

Lawful basis review

We assign and document a defensible basis per activity, and fix the ones relying on consent that shouldn't.

Rights operations

We make access and erasure requests a repeatable process that completes inside the deadline.

DPIAs & transfers

We run impact assessments for high-risk processing and implement transfer mechanisms like SCCs.

Processor governance

We get Article 28 terms in place and bring your sub-processors under control.

Breach readiness

We build the detection, assessment, and notification path that makes 72 hours achievable.

How the engagement runs

1

Map data

Discover personal data, flows, and purposes; build the ROPA.

2

Assess

Gap the current state against the regulation.

3

Remediate

Fix lawful basis, notices, contracts, retention, and security.

4

Operationalize

Stand up rights handling, DPIAs, and breach response.

5

Demonstrate

Keep the evidence that proves accountability on demand.

Frequently asked questions

Can we get GDPR certified?

Not in the way you certify to ISO 27001. The GDPR anticipates certification mechanisms under Article 42, but approved schemes are limited and none is a general 'GDPR certificate'. Anyone selling you one is overstating it. In practice, ISO 27701 is the strongest certifiable evidence of a privacy program.

We're a US company with no EU office — does GDPR apply?

If you offer goods or services to people in the EU/UK, or monitor their behavior, then yes — the regulation reaches you regardless of where you're incorporated. Having EU-based users or employees is usually enough to bring you in scope.

Do we need a Data Protection Officer?

A DPO is mandatory for public authorities, for large-scale systematic monitoring, and for large-scale processing of special category data. Many other organizations appoint one voluntarily or use an outsourced DPO. We'll assess whether you're required to and support the role either way.

What actually triggers the 72-hour clock?

It starts when you become aware of a personal data breach, and you notify the supervisory authority unless the breach is unlikely to result in risk to individuals. The practical problem is rarely the notice — it's being able to assess scope and risk fast enough to make the decision. That's a detection and response problem.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

GDPR for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.