Skip to main content
LiveEU

GDPR

General Data Protection Regulation

The EU’s data protection law — and how Audulate keeps you continuously compliant.

Overview

What is GDPR?

The General Data Protection Regulation (GDPR) is the European Union’s data protection law and one of the most influential privacy regimes in the world. It governs how any organisation collects, uses, stores, shares and secures the personal data of people in the EU — names, emails, IP addresses, device identifiers, location and behavioural data all count as personal data.

GDPR rests on seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. In practice that means you need one of six lawful bases for every processing activity, you must tell people clearly what you do with their data, you must keep it secure, and you must be able to demonstrate compliance — not merely assert it.

It also grants individuals a set of enforceable rights: to access their data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and not be subject to solely automated decisions that significantly affect them. Supervisory authorities (the national data protection regulators) can issue fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.

For most teams, GDPR isn’t a single task — it surfaces across the whole product at once: your website (cookies, trackers, the privacy policy), your forms (what you collect and on what basis), your code and cloud (how data is secured and where it lives), and your internal records (who you share data with, for how long, and under what safeguards). That breadth is why compliance is rarely a one-time project.

Applicability

Who must comply?

  • Any organisation established in the EU that processes personal data — as a controller (you decide why and how) or a processor (you act on a controller’s instructions).
  • Any organisation outside the EU that offers goods or services to people in the EU, or monitors their behaviour. This “targeting and monitoring” test (Article 3) pulls in companies anywhere in the world.
  • Organisations of every size: there is no general small-business exemption from the core duties, though some record-keeping obligations scale with headcount, risk and the nature of the data.
  • Businesses processing special-category data (health, biometrics, beliefs and similar) or carrying out large-scale monitoring, which face heightened duties such as mandatory DPIAs and, in some cases, a Data Protection Officer.
  • Non-EU organisations in scope, which may also need to appoint an EU representative under Article 27.

Obligations

What you must maintain

A lawful basis for every activity

Consent, contract, legitimate interests, etc. — documented per processing purpose (Art. 6).

Transparent privacy information

A complete, current privacy notice covering the Art. 13/14 elements.

Valid cookie & tracking consent

Prior, granular, freely-given consent before non-essential cookies and trackers load.

A Record of Processing Activities (RoPA)

Your Art. 30 register of what you process, why, with whom, and for how long.

A way to handle data subject rights

Access, erasure, portability and the rest (Art. 15–22), answered within the statutory window.

Processor agreements & transfer safeguards

Signed DPAs (Art. 28) and a valid mechanism for any transfer outside the EU (Art. 46).

A breach process

Detect, record and — where required — notify within 72 hours (Art. 33/34).

Appropriate security

Technical and organisational measures appropriate to the risk (Art. 32).

Coverage

How Audulate covers GDPR

Automated scan

Automated website & infrastructure scans

Deterministic checks that run on every scan — 70+ GDPR web rules, plus cloud, database and code-level checks.

  • Cookies & consent: a consent banner (CMP) is present, reject is as easy as accept, categories are granular, there are no pre-ticked boxes or cookie walls, and nothing — trackers or storage, including CNAME-cloaked trackers — fires before consent.
  • Privacy policy: present, reachable, current, and covering the Art. 13 elements (lawful basis, retention, rights, transfers, contact).
  • Trackers & third parties: undisclosed third-party cookies, fingerprinting and session-recording tools, third-country transfers without disclosure.
  • Forms & PII: secure submission, CSRF, PII leaking into URLs, special-category data without explicit consent, privacy notice at the point of collection.
  • Security: HTTPS/TLS version, security headers, CSP quality, SRI, mixed content, secure cookies, outdated libraries, email DNS (SPF/DKIM/DMARC).
  • Data-subject-rights disclosures: access, erasure, portability, restriction, objection and the right to complain.
AI-assessed

AI-assessed checks

Where a yes/no rule can’t judge quality, AI reads the actual content and forms a view — then independently verifies high-severity findings to cut false positives.

  • Privacy-policy completeness and plain-language quality (Art. 12–14).
  • Cookie-banner quality & dark-pattern detection.
  • Marketing-consent quality and sender identity.
  • Legitimate-interest adequacy, special-category basis, and DSR-process clarity.
  • Third-party processor enumeration and privacy-by-design commitments.
Attested

Organisational controls (attested)

11 off-website obligations you attest to and evidence in-app — Audulate gives you the structured surface and audit trail.

  • Processor DPAs (Art. 28) and annual vendor reviews.
  • Art. 30 RoPA, DPIAs (Art. 35), and consent records.
  • Breach register, staff training, DPO appointment (where required).
  • Art. 32 technical & organisational measures, EU/UK representative, and executed transfer safeguards.

Everything rolls into a single 0–100 compliance score across your website, code and cloud, with audit-ready evidence you can export at any time.

GDPR module suite

The full GDPR stack,
cross-linked.

10 purpose-built modules — cookie consent, DSR, RoPA, DPIA, breach, vendors, notices, DPO — each with a live product UI and shared evidence.

Your live compliance score across all GDPR articles. See exactly where you stand, what's passing, what's failing, and what to fix next.

  • Overall compliance score (0–100)
  • Per-article status breakdown
  • Risk severity heatmap
94

94 / 100 — Excellent

✓ 47 passing✗ 2 failing⚠ 4 warnings
Art. 5Lawfulness & minimisationPASS
Art. 7Consent mechanismFAIL
Art. 13Privacy noticeWARN
Art. 30Record of processingPASS
Art. 33Breach notificationPASS
Art. 35DPIA requiredWARN

Get started

Up and running in 3 steps

1

Run a free scan

Add your website URL — your first scan is free and runs in minutes.

2

Review your findings

See every gap with severity, plain-English explanation and fix guidance.

3

Fix & evidence

Resolve issues, track them over time, and export audit-ready reports.

FAQ

GDPR questions

Does Audulate make me GDPR compliant?

No tool can — compliance is ultimately your responsibility. What Audulate does is make it far easier and continuous: it surfaces gaps across your website, code and cloud, gives you the operating workflows (RoPA, DSR, DPIA, breach response) to meet your obligations, and generates audit-ready evidence so you can demonstrate accountability.

Does it write my privacy policy for me?

No. Audulate audits your existing privacy policy against the Article 13/14 transparency requirements — and uses AI to assess whether it’s genuinely complete and in plain language — but it does not generate legal text. You stay in control of the wording.

I’m a small business — does GDPR apply to me?

If you process the personal data of people in the EU, yes — there is no size exemption from the core duties. Some record-keeping obligations scale with size and risk, but lawful basis, transparency, security and individual rights apply to everyone, from sole trader to enterprise.

What are the penalties under GDPR?

For the most serious infringements, supervisory authorities can fine up to €20 million or 4% of total worldwide annual turnover, whichever is higher; a lower tier (€10M / 2%) applies to other breaches. In practice, enforcement usually begins with engagement and remediation rather than an immediate fine.

Do I need a Data Protection Officer (DPO)?

A DPO is mandatory if you’re a public authority, carry out large-scale systematic monitoring, or process special-category data at scale — otherwise it’s optional but often sensible. Audulate gives you a DPO profile and task queue, and flags where the role’s involvement is expected.

How is this different from a cookie banner tool?

Cookie tools manage the banner itself. Audulate checks whether your banner actually works (and isn’t a dark pattern), plus your privacy policy, forms, security, international transfers, code and cloud — and gives you the GDPR operating tools (RoPA, DSR, DPIA, breach) that a banner can’t.

This page is informational and not legal advice. Coverage describes Audulate’s current capabilities; your compliance obligations depend on your specific circumstances.

Get started today

Your compliance changes
every time you ship.

Audulate keeps up. Free to start.

2 free scans / monthNo credit card5-minute setup