GDPR

General Data Protection Regulation

The EU's landmark data privacy and security regulation, protecting the personal data of EU residents.

What It Is

GDPR governs how organizations collect, process, store, and protect the personal data of individuals in the European Union. It requires a lawful basis for every processing activity, gives individuals data subject rights including access, correction, erasure, and portability, and mandates breach notification to regulators within 72 hours of discovery.

Organizations must also implement appropriate technical and organizational security measures, honor data minimization and retention limits, and in many cases document processing activities formally. Penalties for non-compliance can reach up to 4 percent of global annual revenue or €20 million, whichever is greater.

Who It Applies To

Any organization, regardless of where it is physically located, that offers goods or services to people in the European Union or monitors their online behavior, including Northern Virginia businesses with EU customers, partners, employees, or website visitors.

How We Help

  • Map data flows and inventory personal data processing activities

  • Implement technical safeguards such as encryption, access controls, and logging

  • Build breach detection and 72-hour regulator notification procedures

  • Support Data Protection Impact Assessments (DPIAs) for higher-risk processing

  • Maintain audit-ready documentation of technical and organizational measures

Ready to close your compliance gaps?

Get a free security assessment, no obligation.