PrivacyEuropean Union

GDPR compliance

General Data Protection Regulation (EU)

The EU General Data Protection Regulation (GDPR) governs how organisations handle the personal data of individuals in the EU, with strong requirements around lawful basis, data-subject rights, security and accountability. Pelta helps you operationalise GDPR as a managed, evidence-backed program.

Who it's for

Does GDPR apply to you?

  • Organisations processing personal data of EU individuals
  • Companies needing to demonstrate GDPR accountability
  • Teams running GDPR alongside ISO 27001 or DPDPA

What the GDPR governs

The EU General Data Protection Regulation governs how organisations handle the personal data of individuals in the EU. It applies wherever you are based if you process that data, and it is principles-based rather than a control checklist — which makes it easy to nod along to and hard to operationalise. Its weight falls on lawful processing, transparency, the rights of individuals, security, and demonstrable accountability.

This is a general overview, not legal advice. Confirm your obligations — and whether you act as controller or processor — with qualified counsel.

Establish a lawful basis

Every processing activity needs one of six lawful bases. Consent is only one of them, and often not the most robust — pick the basis that genuinely fits the activity and document it.

The six GDPR lawful bases
BasisUse when
ConsentThe individual has given clear, freely-given, withdrawable permission
ContractProcessing is necessary to deliver a contract with the individual
Legal obligationYou must process to comply with the law
Vital interestsProcessing protects someone's life
Public taskProcessing is in the public interest or official authority
Legitimate interestsYour (or a third party's) interests aren't overridden by the individual's rights

Honour data-subject rights

Individuals have rights over their data, and you need a repeatable process to satisfy a request within the statutory timeframe.

Handling a data-subject request

Receive

Any channel

Verify

Confirm identity

Locate

Across systems

Action

Access / erase / fix

Respond

Within the deadline

Demonstrate accountability

GDPR's accountability principle means it is not enough to comply — you must be able to show it. That means a Record of Processing Activities, documented lawful bases, security measures, DPIAs for high-risk processing, and a breach process able to notify within 72 hours where required. A connected evidence approach — where each obligation links to the artefact that proves it — is what keeps accountability real rather than aspirational, and much of it is reusable across ISO 27001 and India's DPDPA.

Common pitfalls to avoid

  • Defaulting to consent for everything, when another lawful basis fits better and is more durable.
  • Treating the Record of Processing Activities as optional — it is the practical foundation of the whole programme.
  • Overlooking processors and sub-processors that handle personal data on your behalf.
  • Having a breach policy but no tested process to actually meet the 72-hour notification window.
How Pelta helps

Run GDPR on one connected platform

Accountability, evidenced

Demonstrate GDPR accountability with obligations mapped to linked evidence.

Privacy risk

Assess and manage privacy risk within your broader risk program.

Vendor and processor risk

Keep tabs on the processors and sub-processors touching personal data.

Reuse across privacy frameworks

Share controls with DPDPA and ISO 27001 to avoid duplicate work.

GDPR FAQs

Who must comply with GDPR?+

Organisations that process the personal data of individuals in the EU, regardless of where the organisation is based. Confirm your role as controller or processor for each activity.

What are the lawful bases under GDPR?+

Six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Every processing activity needs one, and it should be documented.

What is the GDPR breach notification deadline?+

Where a personal data breach is notifiable, controllers are generally required to notify the relevant supervisory authority within 72 hours of becoming aware of it. Confirm the specifics for your situation.

What is a Record of Processing Activities?+

A RoPA is an inventory of what personal data you process, why, and where it flows. It is a requirement for many organisations and the practical foundation of a GDPR programme.

How does GDPR differ from India's DPDPA?+

Both protect personal data and share core principles, but they are distinct laws with different definitions, consent mechanics and enforcement. Much groundwork transfers, but map obligations rather than assume equivalence.

Can I run GDPR and DPDPA together in Pelta?+

Yes. The two overlap on core privacy principles, so many controls and much evidence can be reused across both in Pelta.

See GDPR compliance on Pelta

Manage GDPR compliance on Pelta — map data protection obligations to controls and evidence, handle privacy risk, and demonstrate accountability.