GDPR applies extraterritorially under Article 3. Any business offering goods or services to EU data subjects — or monitoring their behavior — is in scope, even with no EU office. We deliver the record of processing, DPIA, and SCC package that EU regulators expect.
Article 3 defines when GDPR applies. If your organization meets any of the three triggers below you are a controller or processor — even if your servers, headquarters, and staff are all outside the EU.
Every personal-data processing activity must rest on a documented lawful basis under Article 6. Justify the basis before processing starts; record it in your Record of Processing Activities (Art. 30); tell data subjects which basis applies in your privacy notice.
Check Your Posture →Requires unambiguous affirmative action; must be as easy to withdraw as to give. Required for marketing email, most cookies, and any processing where the data subject has a genuine choice.
Use only when processing is objectively necessary to deliver what the data subject contracted for. Cannot be invoked for "nice-to-have" data extending the scope of the service.
Applies when EU or member-state law mandates the processing (tax records, AML, employment law). The specific legal basis must be identified and cited in your ROPA.
Narrow scope — limited to life-threatening emergencies. Rarely the right basis for routine SaaS processing; document any reliance on it tightly.
Reserved for public authorities or organizations performing an official public function. Most private-sector companies cannot rely on this basis.
Most flexible basis, but requires a documented three-part test: legitimate purpose, necessity, and balancing against data-subject rights. Cannot be used to override consent when consent is appropriate.
Two obligations get disproportionate scrutiny from supervisory authorities: appointing a Data Protection Officer when triggers are met, and the 72-hour breach notification clock under Articles 33–34.
Most US-headquartered companies face overlapping requirements. GDPR is a regulation — enforceable by data-protection authorities with fines up to 4% of global turnover. SOC 2 and PCI-DSS are market or industry obligations. HIPAA, CCPA, and GDPR all touch personal data but define it differently and trigger different breach clocks.
Both protect personal data but GDPR covers any personal data of EU subjects, while HIPAA covers only Protected Health Information held by covered entities and business associates. GDPR requires an explicit lawful basis (consent, contract, legitimate interest, etc.); HIPAA's "minimum necessary" rule is narrower. Breach clock: GDPR 72 hours, HIPAA 60 days.
GDPR is a binding regulation enforced by EU data-protection authorities with penalties tied to global turnover. SOC 2 is an attestation report voluntarily commissioned to win enterprise SaaS deals. Both share security, availability, and confidentiality concepts, but GDPR adds lawful basis, ROPA, DPO, and data-subject rights that SOC 2 does not directly address.
Both grant consumer rights (access, deletion, opt-out of sale), but GDPR has steeper penalties (4% global turnover vs CCPA's $7,500 per intentional violation / $2,500 per unintentional) and stricter cross-border transfer rules (SCCs, adequacy decisions, EDPB guidance). CCRPA's right to correct, limit use of sensitive PI, and opt-out of automated decisioning overlap partially with GDPR Art. 22.
Both demand strong technical controls — access control, encryption, logging, vendor due diligence. But the data subject differs (EU residents vs. cardholders), the enforcer differs (DPAs vs. card brands and acquiring banks), and the penalty structure differs (GDPR fines capped at 4% of global turnover vs. PCI penalties ranging from fines to lost card-processing privileges).
NIST CSF and GDPR share meaningful overlap on technical controls — access control, encryption, monitoring, incident response. But GDPR-specific obligations (lawful basis, ROPA, data-subject rights, cross-border transfer rules) are not addressed by NIST and require dedicated work. Here is a realistic coverage estimate.
| NIST CSF Function | Description | Primary GDPR Articles | Est. Coverage |
|---|---|---|---|
| GV — Govern | Organizational context, risk management strategy, supply chain | Art. 24 (Controller accountability), Art. 28 (Processor contracts), Art. 30 (ROPA) | |
| ID — Identify | Asset management, risk assessment, improvement planning | Art. 30 (ROPA), Art. 35 (DPIA), Art. 39 (DPO tasks) | |
| PR — Protect | Access control, awareness, data security, platform security | Art. 25 (Privacy by Design), Art. 32 (Security of Processing), Art. 6 (Lawful basis) | |
| DE — Detect | Continuous monitoring, anomaly detection | Art. 32 (Security of Processing — testing & monitoring), Art. 33 (Breach detection) | |
| RS — Respond | Incident management, analysis, communication, mitigation | Art. 33 (Notify supervisory authority within 72h), Art. 34 (Notify data subjects) | |
| RC — Recover | Recovery planning, communications | Art. 32 (Restoration of availability), Art. 5(1)(f) (Integrity & confidentiality) |
What this means for you: If you've already invested in a NIST CSF program — or purchased a Rhodigital NIST Policy Package — roughly half of your GDPR technical-control work is already done. A cross-mapping assessment identifies exactly which GDPR articles your existing controls satisfy and which still need dedicated attention (lawful-basis identification, ROPA, DPIA, DPO designation, data-subject-rights procedures, SCCs). See the NIST Policy Package →
GDPR compliance is not a single project — it's an ongoing program. We follow a phased engagement model that ends with sustained operational coverage (DPO-as-a-Service, transfer-mechanism maintenance) rather than an open-ended consulting relationship.
Define your role(s) — controller, joint controller, or processor — across each processing activity. Identify EU data subjects, data types, volumes, and transfer routes. Map each high-risk processing activity to a Data Protection Impact Assessment (DPIA) under Art. 35. The scoping decisions made here determine your supervisory authority, your DPO trigger, and your representative obligation under Art. 27.
Systematic review against the full GDPR accountability package. Each control area — lawful basis, ROPA, data-subject rights procedures, security of processing, breach notification, vendor due diligence — is marked Compliant, Partially Compliant, or Non-Compliant. The deliverable is your Record of Processing Activities (Art. 30) and a prioritized gap register.
Close the gaps. This phase produces privacy notice updates, cookie-consent flows, ROPA inventory, data-subject-rights intake processes, Standard Contractual Clauses for cross-border transfers, vendor due-diligence questionnaires, and an updated internal register of processing activities. For organizations with existing NIST CSF policies, this phase is materially shorter.
Sustained coverage: outsourced DPO fulfilling Art. 38–39 duties, periodic ROPA review, supervisory-authority liaison, breach-response coordination, and ongoing cross-border transfer rule maintenance (SCC updates, EDPB guidance, adequacy decisions). GDPR doesn't end at certification — it requires continuous accountability.
Start with a free security posture check. Understand where you stand before a data subject access request or breach forces the issue.