Suspect a breach? Report it immediately — response within 1 hour.Report an incident

GDPR (General Data Protection Regulation)

EU framework governing the collection, processing, and movement of personal data.

Last updatedAugust 22, 2026

Who's affected

Any organization established in the European Union that processes personal data, as well as organizations outside the EU that target or monitor individuals located in the EU (offering goods/services, tracking behavior).

What the framework requires

A documented legal basis for each processing activity, a records of processing register, security measures proportionate to risk, transparent information to data subjects, mechanisms for exercising rights (access, rectification, erasure, portability), a Data Protection Impact Assessment (DPIA) for high-risk processing, safeguards for transfers outside the EU, and notification of data breaches to the competent supervisory authority and, where applicable, to affected individuals.

Compliance steps

01

Map processing activities and personal data flows

02

Identify legal bases and update the records of processing register

03

Conduct a DPIA for high-risk processing activities

04

Implement technical and organizational security measures

05

Formalize procedures for data subject rights requests and breach notification

Common mistakes

  • Incomplete or outdated records of processing
  • No DPIA carried out on processing that is in fact high-risk
  • Transfers of data outside the EU with no safeguard mechanism (standard contractual clauses, adequacy decision)
  • Breach notification procedure never tested before an actual incident occurs

Cross-mapping to other frameworks (UCM)

FrameworkCovered
loi-09-08-cndp
nis2

Downloadable resource

Get the checklist by email.

Frequently asked questions

Does the GDPR apply to a Moroccan company?

Yes, if it processes data of individuals located in the EU in connection with offering goods or services, or monitoring their behavior, regardless of where the company is established.

How does it differ from Morocco's Law 09-08 (CNDP)?

Both frameworks share similar principles (consent, purpose limitation, security) but fall under different authorities and scopes; an organization active in both Morocco and Europe generally needs to satisfy both.

Is a Data Protection Officer (DPO) mandatory?

It is mandatory in specific cases defined by the regulation (public authority, large-scale monitoring, large-scale processing of sensitive data); outside those cases, appointing one remains a sound governance practice.

What does a DPIA actually cover?

A Data Protection Impact Assessment describes the processing, assesses its necessity and proportionality, identifies risks to data subjects, and defines measures to mitigate them.