GDPR: The Obligations That Generate Ongoing Work
Most GDPR effort is not the initial gap assessment. It is the recurring operational load, which falls into six areas.
Records of processing (Article 30). A register of processing activities covering purposes, categories of data subject and personal data, recipients, transfers, retention periods and security measures. It must be current — which means new processing activities have to reach it, and the mechanism for that is usually the weak point.
Lawful basis. Every processing activity needs one of the six bases, decided and documented before processing starts. Consent is the most demanding to operate: freely given, specific, informed, unambiguous, withdrawable as easily as given, and demonstrable. Legitimate interests require a documented balancing test.
Data subject rights. Access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making. One month to respond, extendable by two further months for complex requests. The operational challenge is locating all copies of an individual's data across systems.
DPIAs (Article 35). Required where processing is likely to result in high risk — large-scale special-category data, systematic monitoring, automated decisions with legal effect. A DPIA is a risk assessment with a specific structure, and it must be revisited when the processing changes.
Breach notification (Articles 33–34). Notification to the supervisory authority within 72 hours of becoming aware, unless unlikely to result in risk. Communication to data subjects without undue delay where risk is high. The 72-hour clock runs from awareness, not from confident diagnosis, so the internal escalation path matters more than the notification template.
Accountability (Article 5(2)). You must be able to demonstrate compliance. This is what turns every item above into an evidence requirement.
UK GDPR
Post-Brexit, the UK operates its own GDPR alongside the Data Protection Act 2018, supervised by the ICO. The substance closely tracks the EU regime, with differences in scope, some derogations, and separate territorial application.
Organisations processing data in both jurisdictions generally need to satisfy both, which usually means one control set with jurisdiction-specific annotations rather than two parallel programmes — and attention to whether representatives must be appointed in each.
International Transfers
Transfers outside the EEA require an adequacy decision, appropriate safeguards, or a derogation. In practice most organisations rely on Standard Contractual Clauses, and since Schrems II an SCC alone is not sufficient: a transfer impact assessment must consider whether destination-country law undermines the safeguards, with supplementary measures where it does.
This is documentation-heavy and needs revisiting when the destination, the vendor, or the legal landscape changes — which is why transfer records belong in the same register as vendors rather than in a legal folder.
ISO 27701
ISO 27701 extends ISO 27001 and 27002 with a Privacy Information Management System (PIMS), adding requirements and guidance for controllers and processors. It is certifiable as an extension to an existing ISO 27001 certification — you cannot certify to 27701 alone.
Its value is mapping: 27701 maps its controls to GDPR articles, which gives you a defensible structure for demonstrating accountability, and lets a single control set serve both security and privacy obligations rather than maintaining a separate privacy control library.
The Privacy–Security Overlap
Privacy and information security overlap heavily but are not the same discipline. Security asks whether data is protected; privacy asks whether you should hold it at all, for how long, on what basis, and whether the individual can exercise control over it.
Controls that serve both include access control, encryption, retention and deletion, vendor due diligence, incident response, and logging. Controls that are privacy-specific include lawful basis records, consent management, DPIAs, transfer impact assessments, and the data subject request workflow.
Running them as one control library with framework mappings avoids the common failure where the security team tests access controls for ISO 27001 and the privacy team tests the same controls again for GDPR, reaching different conclusions.
A Practical Readiness Checklist
- Records of processing complete and current, with a route for new activities to reach them.
- Lawful basis documented per activity; legitimate-interest assessments where relied on.
- Privacy notices accurate and matching what the records say you actually do.
- Data subject request process with owners, deadlines and an audit trail.
- DPIA trigger criteria defined, and DPIAs completed for qualifying processing.
- Breach detection and escalation tested against the 72-hour clock.
- Processor contracts with Article 28 terms; sub-processor visibility.
- Transfer mechanisms with impact assessments where required.
- Retention schedule defined and actually enforced in systems.
- Evidence retained for all of the above, because accountability means demonstrating it.
How ActiveERM Supports Privacy Compliance
The GRC platform maps controls to GDPR articles and ISO 27701 clauses within the same library used for ISO 27001 and SOC 2, so a control is tested once. Processing records, DPIAs, vendor assessments and breach incidents sit in the same system as the risk register, with owners, review cadences and retained evidence.
See also our GDPR compliance checklist.