GDPR Compliance Services
Support for controllers and processors that fall under Regulation (EU) 2016/679, covering records of processing, impact assessments, transfer mechanisms and the approved certification routes that actually exist under the regulation.
What the GDPR Is and Who Enforces It
The General Data Protection Regulation is Regulation (EU) 2016/679 of the European Parliament and of the Council. It was adopted on 27 April 2016 and has applied since 25 May 2018, replacing the 1995 Data Protection Directive. It applies directly in every EU and EEA member state without national transposition.
There is no single European data protection regulator. Enforcement is distributed:
- Each member state designates one or more independent supervisory authorities. They handle complaints, run investigations and impose corrective measures including administrative fines.
- The European Data Protection Board brings together the heads of the national supervisory authorities and the European Data Protection Supervisor. It issues guidelines and opinions, and settles cross border disputes through binding decisions.
- The European Data Protection Supervisor supervises the processing of personal data by EU institutions, bodies, offices and agencies.
- For the most serious infringements, administrative fines reach up to 20 million euro or four per cent of total worldwide annual turnover for the preceding financial year, whichever is higher.
There Is No Accredited GDPR Certificate in the ISO Sense
This is the point most compliance marketing gets wrong. No certification body issues a general purpose GDPR certificate the way it issues an ISO/IEC 27001 certificate. The regulation does provide for certification, but only on its own terms and only for defined processing operations.
- Article 42 permits data protection certification mechanisms, seals and marks. The criteria must be approved by the competent supervisory authority, or by the European Data Protection Board where the scheme is intended to apply across the Union, in which case it becomes a European Data Protection Seal.
- Article 43 governs who may issue the certificate. A certification body must be accredited by the competent supervisory authority, by the national accreditation body, or by both.
- Certification is voluntary, is granted for a limited period and covers specific processing operations rather than the whole organisation. It does not reduce the responsibility of the controller or processor for compliance.
- Europrivacy was approved by the European Data Protection Board on 10 October 2022 as the first European Data Protection Seal. Its criteria are maintained by the European Centre for Certification and Privacy in Luxembourg.
- GDPR-CARPA, adopted by the Luxembourg Commission nationale pour la protection des donnees in June 2022, was the first national certification scheme approved under the regulation.
Anything else offered as GDPR certification is a private attestation written by the seller against its own criteria. That can still be useful evidence for a customer questionnaire, but it carries no standing with a supervisory authority and should not be described as accredited.
The Obligations That Drive Most of the Work
In practice the effort concentrates in a small number of areas, and they are the same areas supervisory authorities look at first when a complaint lands.
- Records of processing activities. A maintained inventory of what personal data you hold, why, on what lawful basis, who you share it with and how long you keep it.
- Lawful basis and consent. Consent must be freely given, specific, informed and unambiguous, and must be as easy to withdraw as it was to give. Legitimate interests require a documented balancing assessment.
- Data protection impact assessments. Required before processing likely to result in a high risk to the rights and freedoms of individuals.
- Data protection officer. Mandatory for public authorities, and where core activities involve regular and systematic monitoring on a large scale or large scale processing of special category data.
- Breach notification. Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach. Affected individuals must be told where the risk to their rights and freedoms is high.
- Data subject rights. Access, rectification, erasure, restriction, portability and objection, answered within one month with a limited extension for complex requests.
- International transfers. An adequacy decision, standard contractual clauses, binding corporate rules or another listed safeguard, supported by a transfer impact assessment.
- Processor contracts. Written terms binding the processor on scope, instructions, confidentiality, security, sub processing, assistance and deletion of data.
How a Univate GDPR Engagement Runs
- Scoping and data mapping. We work through systems, business processes and third parties to build the record of processing activities, and we establish which entities are acting as controller and which as processor.
- Gap assessment. Each obligation is tested against evidence rather than policy text. The output is a finding register with owners and severity, not a score.
- Remediation. Notices, consent capture, retention schedules, rights handling workflow, vendor terms, transfer safeguards and the supporting technical controls.
- Operating rhythm. Rights request handling, breach response drills, vendor review and management reporting, so compliance survives staff turnover.
- Certification or assurance route. Where an approved Article 42 mechanism fits your processing, we prepare you for it. Where it does not, we say so and use ISO/IEC 27001 or an independent assessment report as the evidence customers are actually asking for.
Points Worth Being Careful About
- An ISO/IEC 27001 certificate is evidence of an information security management system. It is not a finding of GDPR compliance, and no auditor is entitled to present it as one.
- Territorial scope reaches organisations established outside the EU where they offer goods or services to individuals in the Union or monitor their behaviour in the Union.
- Appointing a representative in the Union is a separate obligation from appointing a data protection officer, and the two roles are not interchangeable.
- Standard contractual clauses alone are not sufficient. The transfer must be assessed against the law and practice of the destination country, with supplementary measures where needed.
- A retention schedule that exists only on paper is not a control. If the deletion job does not run, the schedule buys you nothing.
GDPR Questions We Are Asked Most Often
Can my organisation be GDPR certified?
Not in the way an organisation is certified to ISO/IEC 27001. The GDPR provides for certification under Article 42 for specific processing operations, using criteria approved by a supervisory authority or by the European Data Protection Board. Europrivacy and GDPR-CARPA are the best known approved schemes. A generic GDPR certificate from a body that has not had its criteria approved is a private attestation, not an accredited certification.
Does ISO 27001 certification make us GDPR compliant?
No. ISO/IEC 27001 certifies an information security management system. It supports the security obligation and is useful evidence, but says nothing about lawful basis, transparency, retention, data subject rights or international transfers.
How quickly must a personal data breach be reported?
The controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it. A later notification must be explained. Individuals must be told where the risk to their rights and freedoms is high.
Does the GDPR apply to a company outside the European Union?
It can. The regulation applies to controllers and processors not established in the Union where they offer goods or services to individuals in the Union, whether or not payment is required, or where they monitor the behaviour of individuals within the Union.
Who enforces the GDPR against our organisation?
The supervisory authority of the member state concerned. For cross border processing a lead supervisory authority coordinates with the other authorities, and the European Data Protection Board resolves disagreements by binding decision.
Tell us what personal data you process, where it sits and who you share it with. We will come back with a scoped GDPR work plan and an honest view of whether an approved certification mechanism is worth pursuing in your case.
Related Services & Resources
Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.








