GDPR

The EU privacy regulation: applies the moment your processing reaches European data subjects.

Conditional standard · General Data Protection Regulation (EU) 2016/679

Issued by

European Union

Region

European Union

Effective

In force since May 2018

Oversight

EU and EEA supervisory authorities, coordinated by the EDPB

Applies when

You offer services to, or monitor, people in the EU or EEA

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

GDPR reaches beyond Europe: offer goods or services to people in the EU, or monitor their behaviour, and it applies regardless of where you are incorporated. For organisations expanding internationally, it is usually the first foreign regime that turns up in due diligence.

Its structure will feel familiar to anyone working under the NDPA, which drew on it: lawful bases, data-subject rights, breach notification on a 72-hour clock, impact assessments for high-risk processing, and discipline around cross-border transfers.

Where programmes are tested.

01

Lawful basis and rights

Every processing activity justified, and access, erasure and portability requests answered on time.

02

Breach notification

72 hours to notify the supervisory authority once aware, with the assessment trail to justify the decision.

03

Accountability

Records of processing, DPIAs where risk is high, and transfer safeguards you can produce on request.

Curated once, evidenced continuously.

  • GDPR obligations are curated and cross-mapped alongside the NDPA, so one privacy control set serves both regimes where they overlap.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

GDPR, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Does GDPR apply to Nigerian companies?

Yes, if you offer goods or services to people in the EU or monitor their behaviour, regardless of where you are incorporated. A Nigerian fintech serving EU customers, or a SaaS with EU users, is in scope, and may also need an EU representative under Article 27.

How is GDPR different from the NDPA?

The NDPA drew heavily on GDPR, so the concepts translate: lawful bases, data-subject rights, 72-hour breach notification, impact assessments. The differences are in the machinery: regulators, registration and filing duties, and penalty structures. A control set built for one covers most of the other, which is why they are cross-mapped.

What are the maximum GDPR fines?

Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious infringements, with a lower tier at €10 million or 2%. Enforcement is real: supervisory authorities have issued fines at every scale.

Do we need an EU representative?

If GDPR applies to you and you have no establishment in the EU, Article 27 generally requires appointing a representative there, unless your processing is occasional, low-risk and involves no large-scale special-category data.

Where it connects.

The full catalog
Cross-mapped with
Who answers to it

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.