EU · UK · GDPR

GDPR compliance for companies processing EU data.

Privacy Center, DSR inbox, consent records, breach notification workflow, and audit proof. One workspace for all GDPR obligations.

No credit card required. Privacy Center live in 15 minutes.

ARTICLE 83 PENALTY TIERS

The fines are designed to be significant.

The GDPR's two-tier penalty structure ensures proportionality — but the upper tier can reach 4% of global turnover for large companies.

TierViolations coveredMaximum
Upper tierViolation of core principles, lawfulness, consent, data subject rights, international transfers

€20 Million or 4% of global turnover

Whichever is higher

Lower tierBreach of processor obligations, security requirements, DPA obligations, certification body obligations

€10 Million or 2% of global turnover

Whichever is higher

The UK GDPR mirrors these thresholds in GBP. Companies subject to both EU and UK GDPR face independent enforcement from each authority.

YOUR OBLIGATIONS

Eight things the GDPR requires.

Lawful basis & privacy notice

Articles 6, 13–14

Every processing activity needs a lawful basis. Data subjects must be informed at the point of collection.

Consent management

Articles 7–8

Consent must be freely given, specific, informed, and withdrawable. Keep records of when and how consent was given.

Data subject rights

Articles 15–22

Access, rectification, erasure, restriction, portability, and objection. Respond within 30 days (extendable to 90).

Breach notification

Articles 33–34

72-hour notification to supervisory authority. Communication to affected persons when risk is high.

Record of Processing Activities

Article 30

Controllers must maintain records of all processing activities. Required for demonstrating compliance.

Data Protection by Design

Article 25

Privacy must be integrated into systems and processes by default. Conduct DPIAs for high-risk processing.

DPO & accountability

Articles 37–39

Certain organisations must appoint a Data Protection Officer. All must demonstrate accountability.

International transfers

Chapter V

Transfers outside the EEA require adequate safeguards: SCCs, BCRs, or adequacy decisions.

HOW CONDUIT COVERS EACH OBLIGATION

One workspace. Every GDPR requirement.

GDPR ObligationHow Privacy Conduit covers it
Lawful basis & privacy noticePrivacy Center with GDPR-specific rights descriptions and processing notices.
Consent managementConsent records module: granted, withdrawn, expired, and purpose-tagged entries.
Data subject rightsDSR inbox with 30-day SLA clock, auto-escalation, and per-right response templates.
Breach notificationBreach workflow with 72-hour countdown and DPA notification template.
Record of Processing ActivitiesData inventory + RoPA export generated from your live inventory.
Data Protection by DesignDPIA generator workspace with structured assessment and sign-off workflow.
DPO & accountabilityAudit trail, closure reports, and evidence packages for every case.
International transfersVendor & DPA management module tracks transfer mechanisms per processor.

FREQUENTLY ASKED

GDPR, answered.

What is the GDPR?
The General Data Protection Regulation (GDPR) is the European Union’s data protection law. It governs how organisations collect and process the personal data of individuals in the EU and UK, and grants those individuals a set of enforceable rights over their data.
What rights do individuals have under the GDPR?
Data subjects have the right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and the right to object — set out in Articles 15–22 of the GDPR.
How long does a company have to respond to a GDPR request?
Controllers must respond to a data subject request without undue delay and within one month of receipt. This can be extended by a further two months for complex or numerous requests, with notice to the individual.
What are the penalties for GDPR non-compliance?
Supervisory authorities can impose fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements.
Does the GDPR apply to companies outside the EU?
Yes. The GDPR applies extraterritorially to any organisation that offers goods or services to, or monitors the behaviour of, individuals in the EU — regardless of where the organisation is based.

GET STARTED

Start your GDPR workspace today.

Privacy Center live in 15 minutes. Full GDPR compliance toolkit included.