StructureClerk

GDPR — Free Compliance Assessment

Assess your compliance with the General Data Protection Regulation for free.

In force

Since May 2018

Regulators

CNIL, APDs nationales

Penalties

20M EUR ou 4% CA

What is GDPR?

The General Data Protection Regulation (GDPR) is the European reference framework for personal data protection. Applicable since May 2018, it applies to any organization processing data of European residents, regardless of its location.

GDPR has inspired many global legislations and remains the reference for data protection.

Main obligations

  • Legal basis for each processing
  • Data subject rights (access, rectification, erasure, portability)
  • Breach notification within 72 hours
  • Impact assessments (DPIA) for high-risk processing
  • DPO mandatory for certain organizations
  • Regulated transfers outside EU

How StructureClerk helps

The questionnaire covers key GDPR requirements through ~50 CISO-level questions. Your report identifies your compliance strengths and priority gaps.

Frequently asked questions about GDPR

Does GDPR apply to Canadian companies?+

Yes, as soon as a Canadian company offers goods or services to EU residents or monitors their behaviour (ad tracking, targeted analytics), even without a physical presence in Europe.

What are the penalties under GDPR?+

Up to €20 million or 4% of annual worldwide turnover, whichever is greater. National authorities (such as CNIL in France) can also order processing to be suspended.

Is a DPO (data protection officer) required?+

A DPO is mandatory for public authorities, organizations whose core activity involves regular and systematic large-scale monitoring, or large-scale processing of sensitive data.

What is the breach notification deadline?+

72 hours after becoming aware, to the competent supervisory authority. Affected individuals must be informed without undue delay when the breach presents a high risk to their rights.

How can data be transferred legally from the EU to Canada?+

Canada benefits from a partial adequacy decision (organizations subject to PIPEDA, commercial activities). Otherwise: standard contractual clauses (SCCs) or binding corporate rules (BCRs).