Everything you need to know about GDPR
The General Data Protection Regulation (GDPR) governs the collection and processing of personal data of European citizens. All organisations are concerned, regardless of size. With Data Comply One, simplify your GDPR compliance with an all-in-one solution.
May 25, 2018
Effective date
EUR 20M
Max fine (or 4% revenue)
27 countries
EU + applicable outside EU
7 principles
core principles
What is the GDPR?
The General Data Protection Regulation (GDPR) is a European text that came into force on May 25, 2018. It governs the collection, use and protection of personal data of anyone living in the European Union.
Examples of protected personal data
First name, last name, email, phone number
Health data and banking details
IP address, cookies, browsing data
HR data (payroll, CV, performance reviews)
Who is concerned by the GDPR?
Any organisation, regardless of size (SMEs, mid-market, associations, public bodies, e-commerce…), is concerned if it processes personal data (customers, prospects, employees, patients, users, etc.). The GDPR also applies to any foreign company processing personal data of European residents.
Private companies (micro, SME, mid-market, large groups)
Public sector and local authorities
Associations and non-profits
Non-EU companies processing European data
Subprocessors and providers (hosting, software, etc.)
Your GDPR obligations
The GDPR imposes on every concerned organisation a set of organisational, legal and technical obligations to guarantee personal data protection.
Keep a register of processing activities (article 30)
Inform people clearly about the use of their data
Respect data subject rights: access, rectification, erasure, opposition, portability
Secure data (technical and organisational measures)
Carry out data protection impact assessments (DPIA) for high-risk processing
Designate a DPO when required by the regulation
Notify data breaches to the supervisory authority within 72 hours
Risks, sanctions and inspections
Non-compliance exposes you to financial, criminal and reputational sanctions. The supervisory authority can carry out inspections (online, on-site, on documents or hearings).
Administrative fines up to EUR 20M or 4% of global annual revenue
Criminal sanctions for individuals responsible
Reputational damage and loss of customer trust
Compensation actions by impacted data subjects
In 2024-2025, supervisory authorities issued over EUR 300M in fines.
Benefits of successful compliance
Beyond avoiding sanctions, GDPR compliance is a real lever for competitiveness, trust and data governance.
Customer & partner trust – essential in B2B
Win more contracts (notably with public sector and large groups)
Reduced security incidents through better data hygiene
Better data governance and improved decision-making
Differentiation from competitors through visible commitment
Simplifiez votre conformité GDPR avec Data Comply One
GDPR software
Automated register, rights management, DPIA, subprocessors, real-time compliance score.
Discover the softwareOutsourced DPO
A registered DPO dedicated to your organisation. Comprehensive management of your GDPR compliance.
Schedule a chatGDPR e-learning
Train your teams on GDPR fundamentals. Short, engaging modules, downloadable certificates.
View the programGDPR Engaged Label
Highlight your GDPR commitment to your clients with our 3-tier label.
Discover the labelFAQ GDPR
Prêt à piloter votre conformité GDPR ?
30 minutes pour évaluer vos enjeux, sans engagement.
Ils nous font confiance
Plus de 1 000 entreprises et organisations nous font confiance








































































































































































Découvrir les autres réglementations européennes
Construisez une vision globale de votre conformité multi-réglementaire.
NIS 2
Cybersécurité européenne · entités essentielles & importantes.
DécouvrirDORA
Résilience opérationnelle numérique · secteur financier.
DécouvrirAI Act
Gouvernance des systèmes d'intelligence artificielle.
DécouvrirData Act
Partage et accès aux données B2B / B2G.
DécouvrirnLPD
Loi suisse sur la protection des données.
DécouvrirDécouvrir les autres solutions DCO
Combinez plusieurs solutions pour une approche globale de votre conformité.
DPO externalisé
Un DPO désigné CNIL pour piloter votre RGPD.
DécouvrirRSSI externalisé
Un RSSI dédié pour la cybersécurité (NIS 2 · DORA).
DécouvrirPlateforme logicielle
Le logiciel tout-en-un de pilotage de la conformité.
DécouvrirFormation e-learning
Sensibilisez vos équipes avec Daia (RGPD · IA · Cyber).
Découvrir