Cross-Sector

General Data Protection Regulation (EU)

EU regulation on data protection and privacy. Applies to any organization processing personal data of EU residents regardless of the organization's location.

6Categories
52Controls
Readiness

Control Categories

Lawfulness and Consent

10 controls

Legal bases for processing, consent management, and purpose limitation.

Not started

Data Subject Rights

12 controls

Right of access, rectification, erasure, portability, and restriction of processing.

Not started

Data Protection by Design

8 controls

Privacy impact assessments, data minimization, and pseudonymization.

Not started

Data Transfers

6 controls

Cross-border transfer mechanisms, adequacy decisions, and standard contractual clauses.

Not started

Accountability and Governance

9 controls

Data protection officers, records of processing, and breach notification.

Not started

Security of Processing

7 controls

Technical and organizational measures to ensure appropriate security of personal data.

Not started