EU Organizations
As soon as personal data is processed – regardless of size, sector or type of processing. From micro-enterprises to corporations. No thresholds.
GDPR
Data Protection as a Fundamental Right
The EU General Data Protection Regulation protects the fundamental rights of natural persons when handling personal data. Directly applicable in all EU Member States since 25 May 2018 – with uniform standards for data protection, transparency and individual control.
What is the GDPR?
Regulation (EU) 2016/679 (General Data Protection Regulation) is the central data protection law of the EU. Goal: protection of fundamental rights of natural persons and free movement of data within the EU. Directly applicable since 25 May 2018.
Scope & Application
The GDPR applies territorially and extraterritorially – to all organizations within the EU and to non-EU organizations that process data of EU citizens or monitor their behavior.
EU Organizations
As soon as personal data is processed – regardless of size, sector or type of processing. From micro-enterprises to corporations. No thresholds.
Extraterritorial Application
Companies based outside the EU are also subject to GDPR if they offer goods/services to EU citizens or monitor their behavior (e.g. tracking, profiling).
Exceptions
Private use of social media, household correspondence. Law enforcement falls under Directive (EU) 2016/680. National security also excluded.
Personal Data
Name, email, IP address, cookie IDs, biometric data, location data, online identifiers. Also indirectly identifiable data (pseudonyms with reference).
The 7 Fundamental Principles (Art. 5)
The GDPR anchors seven fundamental principles for any data processing. These form the basis of all requirements and must be demonstrably complied with at all times.
Lawfulness, Fairness, Transparency
Purpose Limitation
Data Minimization
Accuracy
Storage Limitation
Integrity & Confidentiality
Accountability
Rights of Data Subjects
The GDPR strengthens individual control rights over personal data. Data subjects can request access, rectification, erasure, restriction, data portability and object – organizations must actively enable these rights.
Right of Access (Art. 15)
Right to Rectification (Art. 16)
Right to Erasure (Art. 17)
Right to Restriction (Art. 18)
Right to Data Portability (Art. 20)
Right to Object (Art. 21)
Automated Decisions (Art. 22)
Controller Obligations
Organizations processing personal data bear comprehensive responsibility. From Privacy by Design to security measures to documentation obligations – the GDPR demands proactive compliance.
Privacy by Design & Default (Art. 25)
Security of Processing (Art. 32)
Records of Processing Activities (Art. 30)
Data Protection Impact Assessment (Art. 35)
Data Breach Notification (Art. 33/34)
Processing Agreement (Art. 28)
International Data Transfers (Chapter V)
Transfer of personal data outside the EU/EEA is subject to strict requirements. Goal: ensure equivalent data protection level also in third countries.
Adequacy Decision
Standard Contractual Clauses (SCCs)
Binding Corporate Rules (BCRs)
Other Safeguards & Derogations
ayedo and GDPR
Our Software Delivery Platform is GDPR-native designed – from Privacy by Design to EU data residency to comprehensive data subject rights mechanisms. Data protection is not a compliance checkbox, but an architecture principle.
Privacy by Design & Default
EU Data Residency & Sovereignty
State-of-the-Art Security (Art. 32)
Standard DPA
Records of Processing Activities
Data Subject Rights Support
Incident Response & Breach Notification
Data Protection Officer & Governance
ISO Certifications
GDPR in Regulatory Context
The GDPR is the foundation of European digital regulation. All other EU regulations (Data Act, NIS-2, DORA, CRA) build on it or complement it for specific areas.
GDPR & Data Act
GDPR regulates data protection, Data Act regulates data access/use. Both together: protection AND availability. Data Act data access must not violate GDPR – legal bases, DPIAs required. Anonymization/pseudonymization as bridge.
GDPR & NIS-2
GDPR protects personal data, NIS-2 protects network/information systems. Overlaps: Art. 32 GDPR (security) ↔ NIS-2 risk management. Incident reporting in parallel (GDPR → DPA, NIS-2 → CSIRT). Integrated compliance required.
GDPR & DORA
DORA specifies ICT resilience, GDPR remains applicable for data protection. DORA ICT third-party risk includes GDPR processing agreements. Incident reporting coordinated (DORA → financial supervisor, GDPR → DPA). DORA compliance requires GDPR compliance.
GDPR & Cyber Resilience Act
CRA requires secure products (software, hardware), GDPR requires data protection in their use. Privacy by Design (GDPR Art. 25) ↔ Security by Design (CRA). Vulnerability management (CRA) supports Art. 32 GDPR.
GDPR & Cloud Sovereignty
EU data residency, customer key sovereignty, exit capability address GDPR requirements (Art. 32, Art. 44-50). Cloud Sovereignty Framework evaluates GDPR compliance as core factor. EU-only stacks = GDPR-native.
ayedo Compliance Overview
How ayedo systematically addresses GDPR, Data Act, NIS-2, DORA, CRA. Certifications, processes, technical measures. Integrated compliance roadmap. Audit readiness. Complete documentation.
Sanctions & Enforcement
The GDPR enables significant fines and strengthens supervisory authorities with comprehensive powers. Non-compliance can be existential – from financial penalties to reputation damage.
Fine Tiers
Two sanction tiers. Tier 1 (up to €10M or 2% global annual turnover): formal violations (missing documentation, no DPO, no DPIA). Tier 2 (up to €20M or 4% turnover): substantive violations (violation of data subject rights, unlawful processing, missing legal basis).
Authority Powers
Comprehensive supervisory power. Investigations, access to premises/systems, document requests, interviews. Warnings, orders, processing bans, certification withdrawal. Urgency procedures for serious violations. Public announcement of violations.
Civil Liability
Compensation claims by data subjects. Material AND immaterial damage (Art. 82). Litigation option for data subjects. Class actions through consumer organizations possible. Burden of proof reversed: controller must prove absence of fault. Insurance for GDPR violations established.
One-Stop-Shop Principle
Lead supervisory authority for cross-border processing. Main establishment determines lead supervisor. Coordination via EDPB (European Data Protection Board). Complaints possible to any supervisor. Consistency mechanism for disagreements. Simplification for multinational companies.