Find out why Strike Graph is the right choice for your organization. What can you expect?
Find out why Strike Graph is the right choice for your organization. What can you expect?
The General Data Protection Regulation, or GDPR, is Europe’s data privacy and security law that went into effect on May 25, 2018. Governed by the EU’s Information Commissioner's Office (ICO), it imposes obligations on organizations around the world that target or collect data related to people in the EU.
Regardless of where you’re located, if your business collects and/or manipulates the personal data of EU residents—or does so as a subcontractor of another organization—then you need to comply with GDPR.
To get you up to speed, here are some of the basics about GDPR in general and GDPR compliance specifically.
Considered as the world’s strongest set of data protection rules, the full text of GDPR contains 99 individual articles and 173 Recitals. These are broken down into eleven chapters, including:
Getting a little more into the knitty gritty, Chapter 2, Article 5 lays out GDPR’s seven protection and accountability principles, which are important to highlight:
Throughout the articles included in these chapters, there are constant references to and regulations pertaining to personal data, so before continuing, let’s take a more in-depth look at what that constitutes.
Personal data is defined as any information relating to an identified or identifiable natural person (also known as the ‘data subject’).
According to the GDPR text:
An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
You’ll also need to know up front OR be educated on whether you’re a ‘Controller’, a ‘Processor’, a ‘Sub-Processor’, or any combination of these. Here’s a quick rundown:
Now that we have a better handle on the GDPR basics, let’s dive into how your organization can become compliant.
If you’re unsure of whether or not your business needs to be compliant, ask yourself the following questions:
If your answer to any of these questions is yes, your organization needs to be GDPR compliant.
While GDPR.eu provides a general compliance checklist that applies to all organizations, the checklist for US companies also includes those requirements unique to US organizations; US companies should consider both lists. As we outline on this page, here are the eight items on that checklist:
Thankfully, Strike Graph can support GDPR compliance and can even offer it as an add-on to a SOC 2 for any customer handling personal data of EU residents. Don’t worry, leave it to us; we’ll guide your organization as it designs, sets up, manages, and continually improves how it handles consumer personal data per GDPR requirements.
The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.
Strike Graph offers an easy, flexible security compliance solution that scales efficiently with your business needs — from SOC 2 to ISO 27001 to GDPR and beyond.
© 2024 Strike Graph, Inc. All Rights Reserved • Privacy Policy • Terms of Service
Find out why Strike Graph is the right choice for your organization. What can you expect?
Find out why Strike Graph is the right choice for your organization. What can you expect?