Topics/GDPR
GDPR HUB

Everything on GDPR / DSGVO.

Records of processing (Art. 30), lawful bases, DPAs, 72-hour breach notification, subject rights, DPIAs, international transfers, Schrems II. Mature enforcement — fines exceed EUR 10M routinely in 2025-2026.

English articles

Deutsche Artikel

Frequently asked questions

Who does GDPR apply to?+

Any organization processing personal data of EU residents, regardless of company location (Art. 3 extraterritoriality). A US SaaS with any EU user is in scope. Requires EU representative (Art. 27, exceptions apply), DPAs, international transfer safeguards.

What is the 72-hour breach notification?+

Art. 33 requires notification to the supervisory authority within 72 hours of awareness of a personal-data breach. Art. 34 requires communication to affected data subjects if the breach poses high risk to their rights and freedoms. Clock starts at awareness — not completion of investigation.

What is Legitimate Interest?+

Art. 6(1)(f) lawful basis allowing processing without consent if necessary for controller's or third party's legitimate interests, unless overridden by data subject's rights. Requires documented Legitimate Interest Assessment (LIA). Not available for processing special-category data under Art. 9.

Ready to tackle GDPR?

Matproof covers GDPR in one EU-hosted platform alongside 10 other frameworks. 30-minute demo tailored to your scope.