Assess your compliance with the General Data Protection Regulation for free.
Since May 2018
CNIL, APDs nationales
20M EUR ou 4% CA
The General Data Protection Regulation (GDPR) is the European reference framework for personal data protection. Applicable since May 2018, it applies to any organization processing data of European residents, regardless of its location.
GDPR has inspired many global legislations and remains the reference for data protection.
Yes, as soon as a Canadian company offers goods or services to EU residents or monitors their behaviour (ad tracking, targeted analytics), even without a physical presence in Europe.
Up to €20 million or 4% of annual worldwide turnover, whichever is greater. National authorities (such as CNIL in France) can also order processing to be suspended.
A DPO is mandatory for public authorities, organizations whose core activity involves regular and systematic large-scale monitoring, or large-scale processing of sensitive data.
72 hours after becoming aware, to the competent supervisory authority. Affected individuals must be informed without undue delay when the breach presents a high risk to their rights.
Canada benefits from a partial adequacy decision (organizations subject to PIPEDA, commercial activities). Otherwise: standard contractual clauses (SCCs) or binding corporate rules (BCRs).