GDPR
Conditional standard · General Data Protection Regulation (EU) 2016/679
European Union
European Union
In force since May 2018
EU and EEA supervisory authorities, coordinated by the EDPB
You offer services to, or monitor, people in the EU or EEA
Curated, versioned & cross-mapped
The obligation, plainly.
GDPR reaches beyond Europe: offer goods or services to people in the EU, or monitor their behaviour, and it applies regardless of where you are incorporated. For organisations expanding internationally, it is usually the first foreign regime that turns up in due diligence.
Its structure will feel familiar to anyone working under the NDPA, which drew on it: lawful bases, data-subject rights, breach notification on a 72-hour clock, impact assessments for high-risk processing, and discipline around cross-border transfers.
Where programmes are tested.
Lawful basis and rights
Every processing activity justified, and access, erasure and portability requests answered on time.
Breach notification
72 hours to notify the supervisory authority once aware, with the assessment trail to justify the decision.
Accountability
Records of processing, DPIAs where risk is high, and transfer safeguards you can produce on request.
Curated once, evidenced continuously.
- GDPR obligations are curated and cross-mapped alongside the NDPA, so one privacy control set serves both regimes where they overlap.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
GDPR, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Does GDPR apply to Nigerian companies?
Yes, if you offer goods or services to people in the EU or monitor their behaviour, regardless of where you are incorporated. A Nigerian fintech serving EU customers, or a SaaS with EU users, is in scope, and may also need an EU representative under Article 27.
How is GDPR different from the NDPA?
The NDPA drew heavily on GDPR, so the concepts translate: lawful bases, data-subject rights, 72-hour breach notification, impact assessments. The differences are in the machinery: regulators, registration and filing duties, and penalty structures. A control set built for one covers most of the other, which is why they are cross-mapped.
What are the maximum GDPR fines?
Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious infringements, with a lower tier at €10 million or 2%. Enforcement is real: supervisory authorities have issued fines at every scale.
Do we need an EU representative?
If GDPR applies to you and you have no establishment in the EU, Article 27 generally requires appointing a representative there, unless your processing is occasional, low-risk and involves no large-scale special-category data.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.