> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# GDPR

> Meet EU data protection requirements with automated privacy controls and evidence collection.

The General Data Protection Regulation (GDPR) is the EU's comprehensive data protection law governing how organizations collect, process, store, and share personal data of EU residents — regardless of where the organization is based.

<Note>
  GDPR applies to **any organization** that processes personal data of individuals in the EU, including US-based companies with EU customers.
</Note>

## Who needs GDPR compliance?

<CardGroup cols={2}>
  <Card title="Companies with EU customers" icon="globe">
    Any organization collecting or processing personal data from EU/EEA individuals — including website visitors, customers, and employees.
  </Card>

  <Card title="Data processors" icon="server">
    Third-party service providers handling personal data on behalf of other organizations (SaaS platforms, cloud providers, analytics tools).
  </Card>
</CardGroup>

## Key GDPR principles

<CardGroup cols={3}>
  <Card title="Lawfulness & Transparency" icon="scale-balanced">
    Data must be processed lawfully, fairly, and transparently.
  </Card>

  <Card title="Purpose Limitation" icon="crosshairs">
    Collected only for specified, legitimate purposes.
  </Card>

  <Card title="Data Minimization" icon="compress">
    Only collect what is necessary.
  </Card>

  <Card title="Accuracy" icon="check">
    Keep personal data accurate and up to date.
  </Card>

  <Card title="Storage Limitation" icon="clock">
    Do not keep data longer than necessary.
  </Card>

  <Card title="Security" icon="lock">
    Protect data with appropriate technical and organizational measures.
  </Card>
</CardGroup>

## Key requirements

| Requirement                 | Description                                                   |
| --------------------------- | ------------------------------------------------------------- |
| **Processing Records**      | Maintain records of all processing activities (Article 30)    |
| **Impact Assessments**      | Assess risks of high-impact processing (Article 35)           |
| **Data Subject Rights**     | Enable access, rectification, erasure, portability, objection |
| **Breach Notification**     | Report breaches to authorities within 72 hours (Article 33)   |
| **Data Protection Officer** | Appoint a DPO for certain types of processing                 |
| **Cross-border Transfers**  | Ensure adequate protections for international transfers       |

<Warning>
  GDPR violations can result in fines up to **€20 million or 4% of global annual turnover**, whichever is higher.
</Warning>

## How DSALTA helps

* **Privacy-specific controls** mapped to GDPR articles
* **Data processing record templates** for Article 30 compliance
* **AI-generated privacy policies** customizable to your needs
* **Vendor risk management** to assess processor compliance
* **Cross-framework mapping** — overlaps with ISO 27001, SOC 2, and HIPAA

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Does GDPR apply to my US-based company?" icon="flag-usa">
    Yes, if you collect or process personal data of EU residents — including website visitors, customers, or employees in the EU.
  </Accordion>

  <Accordion title="What is a DPO?" icon="user-tie">
    A Data Protection Officer oversees data protection strategy and compliance. Required for public authorities and organizations conducting large-scale systematic monitoring.
  </Accordion>

  <Accordion title="How does GDPR overlap with other frameworks?" icon="diagram-project">
    GDPR shares significant overlap with ISO 27001 (security controls), SOC 2 (privacy criteria), HIPAA (data protection), and NIS 2 (cybersecurity). DSALTA maps these overlaps automatically.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**12** of DSALTA's automated checks contribute evidence to this framework, drawn from **5** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Vendor Risk Management](/guides/vendors/executive-summary)
