4 Guides

GDPR Compliance Explained

The EU's core privacy law in operational terms, who must comply, the data subject rights, records of processing, and what valid consent means.

The General Data Protection Regulation is the EU's core privacy law, and it set the template most of the world's privacy laws now follow. These guides are written for the operational side of GDPR, the steps a compliance or growth team actually has to take, not a clause-by-clause restatement of the regulation.

GDPR Guides

  1. 1What Is GDPR? A Plain-English Guide
    Guide
    The EU's General Data Protection Regulation, its scope and principles, and why it became the template for privacy law worldwide.
  2. 2Who Must Comply With GDPR (Even Outside the EU)
    Guide
    GDPR's extraterritorial reach, when a company based outside the EU is still in scope, and the controller versus processor distinction.
  3. 3The GDPR Data Subject Rights, Explained
    Guide
    Access, rectification, erasure, restriction, portability, objection, and rights around automated decisions, in plain terms.
  4. 4Records of Processing Activities (RoPA): What Article 30 Requires
    Guide
    What a RoPA is, who has to maintain one under GDPR Article 30, and what belongs in it.
Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.