All posts
Compliance Automation8 min readAug 16, 2026

GDPR requirements and principles

Ashish / CEO/Co-Founder
GDPR requirements and principles

GDPR requirements are not just a list of legal rules. Basically, they combine principles, lawful bases, individual rights, governance duties, security obligations, breach processes, processor oversight, transfer rules, and evidence that shows how the organisation meets its responsibilities.

This article explains the main GDPR requirements in plain English and translates them into practical actions and records an organisation may need to retain. It is a practical overview, not legal advice.

What GDPR requirements mean

The General Data Protection Regulation applies to the processing of personal data. Under the GDPR, personal data concerns an identified or identifiable person; a controller determines why and how — or, rather, why and by what means — personal data is processed; and a processor processes personal data on a controller’s behalf under the Regulation’s definitions in Articles 3–4.

In practice, “GDPR requirements”. Several connected layers:

  • Principles: the high-level rules that govern personal data processing.
  • Lawful basis: the reason the organisation is allowed to process the data.
  • Individual rights: rights that individuals can exercise over their personal data.
  • Governance and accountability duties: records, reviews, assessments, and decision-making evidence.
  • Security, breach, processor, and transfer obligations: operational controls for protecting and managing personal data.

The GDPR also includes administrative fine powers. For specified infringements, fines can reach up to €20 million or, for an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher; the tier and amount depend on the infringement and circumstances under Article 83.

Who GDPR applies to, including non-EU and Australian organisations

GDPR can apply where personal data is processed in the context of an EU controller’s or processor’s establishment. It can also apply to a non-EU controller or processor where the processing relates to offering goods or services to people in the EU or monitoring their behaviour in the EU, under Article 3. Mere website accessibility from the EU should not be treated as a complete applicability test.

For Australian organisations, the OAIC states that an Australian organisation may need to comply with GDPR if it has an EU establishment or, without one, offers goods or services to individuals in the EU or monitors their behaviour there (OAIC guidance).

Applicability depends on the processing facts, use this as an initial triage tool, not a legal conclusion at this stage.

The 7 GDPR principles

Article 5 sets out the GDPR principles and makes the controller responsible for, and able to demonstrate compliance with, them. That final accountability principle is why evidence matters: organisations need more than policy statements; they need records showing how decisions were made and controls were operated.

PrinciplePlain-English meaningPractical implicationExample evidence or control
Lawfulness, fairness, and transparencyProcess personal data in a lawful, fair, and understandable way.Identify a lawful basis and explain processing clearly to individuals.Lawful basis assessment, privacy notice, consent record where applicable.
Purpose limitationUse personal data for specified, explicit, legitimate purposes.Avoid collecting data for one reason and using it later for an incompatible reason without review.Processing inventory with stated purposes and change-review notes.
Data minimisationCollect only what is necessary for the stated purpose.Challenge optional fields, excessive logs, or broad access to personal data.Data-field review, product design ticket, access review.
AccuracyKeep personal data accurate and up to date where necessary.Provide routes to correct data and review critical records.Correction request log, data-quality review.
Storage limitationKeep personal data in identifiable form only as long as needed.Define retention periods and deletion or anonymisation steps.Retention schedule, deletion logs, archival review.
Integrity and confidentialityProtect personal data against unauthorised or unlawful processing, loss, destruction, or damage.Apply risk-appropriate technical and organisational security measures.Security policy, access control evidence, incident log.
AccountabilityBe able to show compliance with the principles.Assign ownership, keep records, and review controls as processing changes.ROPA, DPIA, approval records, control reviews.

The main GDPR requirements: actions and evidence to retain

The checklist below is editorial guidance for organising GDPR obligations into actions, evidence, and review ownership. It does not guarantee compliance, and the right evidence depends on the processing context.

A practical way to organise accountability is to map each requirement to an action, a possible owner, and records that can be reviewed later.

RequirementWhat it meansPractical actionEvidence to retainPossible owner/reviewer
Identify lawful basis for processingProcessing needs at least one Article 6 lawful basis; where consent is used, the controller must be able to demonstrate it under Articles 6–7.Map each processing activity to an appropriate lawful basis. Do not treat consent as the default.Processing register, lawful basis assessment, consent records where applicable.Privacy/legal, process owner, product owner.
Provide transparent privacy noticesControllers must provide clear, accessible information about processing and rights under Articles 12–14.Tell individuals what data is collected, why, how it is used, who it may be shared with, and how rights can be exercised.Current privacy notice, version history, approval records.Privacy/legal, marketing, product, website owner.
Support data subject rightsGDPR provides rights such as access, rectification, erasure, restriction, portability, objection, and rights relating to certain automated decision-making, subject to conditions under Articles 12–22.Create a request-handling process, including identity checks, deadlines, exemptions, and escalation routes.Request logs, response records, identity verification steps, escalation records.Privacy/legal, support, operations, data owner.
Maintain records of processing activitiesRecords of processing activities are required subject to Article 30’s scope and exceptions.Document processing purposes, categories of data, data subjects, recipients, retention, transfers, and safeguards where required.ROPA or equivalent processing inventory.Privacy/GRC, process owners, data owners.
Apply data protection by design and defaultGDPR requires appropriate measures and default settings that limit processing to what is necessary when determining processing means and during processing under Articles 24–25.Include privacy review in product, engineering, procurement, and operational changes.Design reviews, privacy review tickets, approval records, change logs.Product, engineering, privacy, security.
Run DPIAs where higher-risk processing is involvedA DPIA is required before processing likely to create high risk under Article 35.Assess whether a DPIA is required before starting high-risk processing and review it when the processing risk changes.DPIA records, risk decisions, mitigations, approvals.Privacy/legal, security, product, executive risk owner.
Use appropriate processor contractsProcessor processing must be governed by a binding Article 28 contract or legal act.Identify processors and ensure contracts include required data-processing obligations.Signed data processing agreements, vendor review records, contract review notes.Legal, procurement, privacy, vendor owner.
Protect personal data with appropriate security measuresControllers and processors must implement technical and organisational measures appropriate to the risk under Article 32.Apply risk-based security controls rather than a universal technical checklist.Security policies, risk assessments, access reviews, incident logs, control evidence.Security, IT, engineering, risk/GRC.
Prepare for breach notificationControllers must document personal-data breaches and, unless the breach is unlikely to risk individuals’ rights and freedoms, notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware under Articles 33–34.Maintain an incident process that can classify events, assess risk, decide on notification, and record the rationale.Incident response plan, breach assessment records, notification decision logs, communications records.Security, legal/privacy, incident commander, executive owner.
Check DPO and EU representative obligationsA DPO is required only in Article 37 circumstances; a non-EU controller or processor subject to Article 3(2) generally needs an EU representative, subject to Article 27 exceptions.Assess whether a DPO or EU representative is required based on processing facts and exceptions.Decision record, appointment record if applicable, role description.Legal/privacy, executive management, governance.
Manage international transfersTransfers to third countries or international organisations must meet Chapter V conditions; where there is no adequacy decision, appropriate safeguards may be required under Articles 44–46.Identify transfers and determine what transfer mechanism or safeguard review is needed.Transfer inventory, contracts, safeguard assessments, legal review notes.Legal/privacy, procurement, security, vendor owner.

When GDPR requirements need deeper review

Some GDPR questions should not be resolved by a generic checklist, or by a quick review. Consider legal, privacy, or security review where the organisation is dealing with:

  • uncertain applicability outside the EU, including Australian or other non-EU operations;
  • special-category data, criminal-offence data, or other sensitive processing contexts;
  • children’s data;
  • high-risk processing or uncertain DPIA triggers;
  • automated decision-making or profiling;
  • international transfers;
  • breach notification decisions;
  • DPO or EU representative appointment questions;
  • complex controller, joint-controller, or processor relationships.

These areas are fact-specific and can affect lawful basis, rights handling, documentation, contracts, security measures, and supervisory authority engagement.

GDPR readiness is strongest when requirements are translated into owned controls, retained evidence, and repeatable review cycles. For teams that want to manage this operationally, Ciphrix can help structure compliance as continuous evidence and reusable controls across frameworks, without replacing legal advice, independent review, or internal control ownership.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents