Eight years on, GDPR enforcement is sharper than ever
The regulation that reset global privacy law is now mature case law, active enforcement and a fixture of every supplier questionnaire. Accountability — being able to demonstrate compliance — is the standard you are held to.
- Applies since
- 25 May 2018 (EU & UK regimes)
- Who's in scope
- Anyone processing EU/UK personal data
- Breach reporting
- 72 hours to the regulator
- Maximum fines
- €20m / £17.5m or 4% of turnover
The highlights
GDPR is less a checklist than an operating discipline built on seven principles — with accountability, the duty to evidence all the others, doing the heavy lifting.
Lawful basis before processingArt. 6
Every processing activity needs one of six lawful bases, chosen and documented before you begin. Consent is the most fragile of the six — legitimate interests and contract carry most business processing, when properly assessed.
Data subject rightsArts. 15–22
Access, rectification, erasure, portability, restriction and objection — each on a one-month clock. Subject access requests remain the most common trigger for regulatory complaints.
Accountability in writingArts. 5(2), 30, 35
Records of processing activities, DPIAs for high-risk processing, privacy notices, retention schedules and processor contracts. If it isn't documented, regulators treat it as not done.
72-hour breach notificationArts. 33–34
Notifiable breaches go to the supervisory authority within 72 hours of awareness, and to affected individuals when the risk is high. The clock demands a rehearsed triage process, not a policy on a shelf.
International transfersChapter V
Data leaving the UK/EEA needs a transfer mechanism — adequacy, SCCs with transfer risk assessments, or the UK IDTA. Cloud stacks make this everyone's problem: most organisations transfer more data than they think.

Where to start
- Refresh the RoPA — your Article 30 record is the index for everything else. If it's stale, your DPIAs, notices and retention schedule are too.
- Stress-test SAR handling — one month, complex exemptions, and increasingly weaponised in disputes. Rehearse it.
- Audit your processors — Article 28 contracts, sub-processor chains and transfer mechanisms — supplier questionnaires now go straight to this.
- Connect privacy to security — GDPR's Article 32 'appropriate technical and organisational measures' is exactly what an ISO 27001 ISMS evidences.
Compliant on paper, uncertain in practice?
Sentinel42 provides GDPR health checks, RoPA and DPIA programmes, and outsourced DPO support — grounded in sixteen years of practitioner experience across regulated sectors.