
GDPR requirements are not just a list of legal rules. Basically, they combine principles, lawful bases, individual rights, governance duties, security obligations, breach processes, processor oversight, transfer rules, and evidence that shows how the organisation meets its responsibilities.
This article explains the main GDPR requirements in plain English and translates them into practical actions and records an organisation may need to retain. It is a practical overview, not legal advice.
What GDPR requirements mean
The General Data Protection Regulation applies to the processing of personal data. Under the GDPR, personal data concerns an identified or identifiable person; a controller determines why and how — or, rather, why and by what means — personal data is processed; and a processor processes personal data on a controller’s behalf under the Regulation’s definitions in Articles 3–4.
In practice, “GDPR requirements”. Several connected layers:
- Principles: the high-level rules that govern personal data processing.
- Lawful basis: the reason the organisation is allowed to process the data.
- Individual rights: rights that individuals can exercise over their personal data.
- Governance and accountability duties: records, reviews, assessments, and decision-making evidence.
- Security, breach, processor, and transfer obligations: operational controls for protecting and managing personal data.
The GDPR also includes administrative fine powers. For specified infringements, fines can reach up to €20 million or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher; the tier and amount depend on the infringement and circumstances under Article 83.
Who GDPR applies to, including non-EU and Australian organisations
GDPR can apply where personal data is processed in the context of an EU controller’s or processor’s establishment. It can also apply to a non-EU controller or processor where the processing relates to offering goods or services to people in the EU or monitoring their behaviour in the EU, under Article 3. Mere website accessibility from the EU should not be treated as a complete applicability test.
For Australian organisations, the OAIC states that an Australian organisation may need to comply with GDPR if it has an EU establishment or, without one, offers goods or services to individuals in the EU or monitors their behaviour there (OAIC guidance).
Applicability depends on the processing facts, use this as an initial triage tool, not a legal conclusion at this stage.
The 7 GDPR principles
Article 5 sets out the GDPR principles and makes the controller responsible for, and able to demonstrate compliance with, them. That final accountability principle is why evidence matters: organisations need more than policy statements; they need records showing how decisions were made and controls were operated.
| Principle | Plain-English meaning | Practical implication | Example evidence or control |
|---|---|---|---|
| Lawfulness, fairness, and transparency | Process personal data in a lawful, fair, and understandable way. | Identify a lawful basis and explain processing clearly to individuals. | Lawful basis assessment, privacy notice, consent record where applicable. |
| Purpose limitation | Use personal data for specified, explicit, legitimate purposes. | Avoid collecting data for one reason and using it later for an incompatible reason without review. | Processing inventory with stated purposes and change-review notes. |
| Data minimisation | Collect only what is necessary for the stated purpose. | Challenge optional fields, excessive logs, or broad access to personal data. | Data-field review, product design ticket, access review. |
| Accuracy | Keep personal data accurate and up to date where necessary. | Provide routes to correct data and review critical records. | Correction request log, data-quality review. |
| Storage limitation | Keep personal data in identifiable form only as long as needed. | Define retention periods and deletion or anonymisation steps. | Retention schedule, deletion logs, archival review. |
| Integrity and confidentiality | Protect personal data against unauthorised or unlawful processing, loss, destruction, or damage. | Apply risk-appropriate technical and organisational security measures. | Security policy, access control evidence, incident log. |
| Accountability | Be able to show compliance with the principles. | Assign ownership, keep records, and review controls as processing changes. | ROPA, DPIA, approval records, control reviews. |
The main GDPR requirements: actions and evidence to retain
The checklist below is editorial guidance for organising GDPR obligations into actions, evidence, and review ownership. It does not guarantee compliance, and the right evidence depends on the processing context.
A practical way to organise accountability is to map each requirement to an action, a possible owner, and records that can be reviewed later.
| Requirement | What it means | Practical action | Evidence to retain | Possible owner/reviewer |
|---|---|---|---|---|
| Identify lawful basis for processing | Processing needs at least one Article 6 lawful basis; where consent is used, the controller must be able to demonstrate it under Articles 6–7. | Map each processing activity to an appropriate lawful basis. Do not treat consent as the default. | Processing register, lawful basis assessment, consent records where applicable. | Privacy/legal, process owner, product owner. |
| Provide transparent privacy notices | Controllers must provide clear, accessible information about processing and rights under Articles 12–14. | Tell individuals what data is collected, why, how it is used, who it may be shared with, and how rights can be exercised. | Current privacy notice, version history, approval records. | Privacy/legal, marketing, product, website owner. |
| Support data subject rights | GDPR provides rights such as access, rectification, erasure, restriction, portability, objection, and rights relating to certain automated decision-making, subject to conditions under Articles 12–22. | Create a request-handling process, including identity checks, deadlines, exemptions, and escalation routes. | Request logs, response records, identity verification steps, escalation records. | Privacy/legal, support, operations, data owner. |
| Maintain records of processing activities | Records of processing activities are required subject to Article 30’s scope and exceptions. | Document processing purposes, categories of data, data subjects, recipients, retention, transfers, and safeguards where required. | ROPA or equivalent processing inventory. | Privacy/GRC, process owners, data owners. |
| Apply data protection by design and default | GDPR requires appropriate measures and default settings that limit processing to what is necessary when determining processing means and during processing under Articles 24–25. | Include privacy review in product, engineering, procurement, and operational changes. | Design reviews, privacy review tickets, approval records, change logs. | Product, engineering, privacy, security. |
| Run DPIAs where higher-risk processing is involved | A DPIA is required before processing likely to create high risk under Article 35. | Assess whether a DPIA is required before starting high-risk processing and review it when the processing risk changes. | DPIA records, risk decisions, mitigations, approvals. | Privacy/legal, security, product, executive risk owner. |
| Use appropriate processor contracts | Processor processing must be governed by a binding Article 28 contract or legal act. | Identify processors and ensure contracts include required data-processing obligations. | Signed data processing agreements, vendor review records, contract review notes. | Legal, procurement, privacy, vendor owner. |
| Protect personal data with appropriate security measures | Controllers and processors must implement technical and organisational measures appropriate to the risk under Article 32. | Apply risk-based security controls rather than a universal technical checklist. | Security policies, risk assessments, access reviews, incident logs, control evidence. | Security, IT, engineering, risk/GRC. |
| Prepare for breach notification | Controllers must document personal-data breaches and, unless the breach is unlikely to risk individuals’ rights and freedoms, notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware under Articles 33–34. | Maintain an incident process that can classify events, assess risk, decide on notification, and record the rationale. | Incident response plan, breach assessment records, notification decision logs, communications records. | Security, legal/privacy, incident commander, executive owner. |
| Check DPO and EU representative obligations | A DPO is required only in Article 37 circumstances; a non-EU controller or processor subject to Article 3(2) generally needs an EU representative, subject to Article 27 exceptions. | Assess whether a DPO or EU representative is required based on processing facts and exceptions. | Decision record, appointment record if applicable, role description. | Legal/privacy, executive management, governance. |
| Manage international transfers | Transfers to third countries or international organisations must meet Chapter V conditions; where there is no adequacy decision, appropriate safeguards may be required under Articles 44–46. | Identify transfers and determine what transfer mechanism or safeguard review is needed. | Transfer inventory, contracts, safeguard assessments, legal review notes. | Legal/privacy, procurement, security, vendor owner. |
When GDPR requirements need deeper review
Some GDPR questions should not be resolved by a generic checklist, or by a quick review. Consider legal, privacy, or security review where the organisation is dealing with:
- uncertain applicability outside the EU, including Australian or other non-EU operations;
- special-category data, criminal-offence data, or other sensitive processing contexts;
- children’s data;
- high-risk processing or uncertain DPIA triggers;
- automated decision-making or profiling;
- international transfers;
- breach notification decisions;
- DPO or EU representative appointment questions;
- complex controller, joint-controller, or processor relationships.
These areas are fact-specific and can affect lawful basis, rights handling, documentation, contracts, security measures, and supervisory authority engagement.
GDPR readiness is strongest when requirements are translated into owned controls, retained evidence, and repeatable review cycles. For teams that want to manage this operationally, Ciphrix can help structure compliance as continuous evidence and reusable controls across frameworks, without replacing legal advice, independent review, or internal control ownership.
