๐
GDPR Compliance
A Comprehensive Guide to Data Protection
WIA-SEC-024 Standard
Version 1.0 | December 2025
World Certification Industry Association
Chapter 1: Introduction to GDPR
1.1 What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection
law that came into effect on May 25, 2018. It represents the most significant change to data privacy
regulation in over two decades, affecting any organization that processes personal data of EU residents,
regardless of where the organization is located.
Key Facts About GDPR
- Applies to all 27 EU member states plus EEA countries (Iceland, Liechtenstein, Norway)
- Affects organizations worldwide that process EU residents' data
- Maximum fines: โฌ20 million or 4% of global annual turnover, whichever is higher
- Establishes comprehensive rights for data subjects
- Requires demonstrable compliance through documentation
1.2 Who Must Comply?
GDPR applies to:
- Controllers: Organizations that determine the purposes and means of processing personal data
- Processors: Organizations that process personal data on behalf of controllers
- EU Establishments: Any organization with an establishment in the EU
- Non-EU Organizations: Those offering goods/services to EU residents or monitoring their behavior
1.3 Why GDPR Matters
Data protection is recognized as a fundamental human right under the EU Charter of Fundamental Rights.
GDPR embodies the philosophy of ๅผ็ไบบ้ (Hongik Ingan) - "Benefit All Humanity" - by ensuring:
- Individual control over personal data
- Transparency in data processing
- Accountability of organizations
- Protection against misuse of personal information
- Fair and ethical data practices
Chapter 2: Core Principles
Article 5 of GDPR establishes seven fundamental principles that must guide all personal data processing:
1. Lawfulness, Fairness, and Transparency
Personal data must be processed lawfully (with a valid legal basis), fairly (without adverse
effects on individuals), and transparently (individuals understand how their data is used).
2. Purpose Limitation
Data must be collected for specified, explicit, and legitimate purposes. You cannot collect
data for one purpose and then use it for something completely different without additional
consent or legal basis.
3. Data Minimization
Collect only data that is adequate, relevant, and limited to what is necessary. Don't collect
"nice to have" information - only what you genuinely need for your stated purpose.
4. Accuracy
Personal data must be accurate and kept up to date. Inaccurate data must be erased or rectified
without delay. Implement processes to verify and maintain data quality.
5. Storage Limitation
Keep personal data only as long as necessary for the processing purposes. Establish and document
retention periods, and delete or anonymize data when no longer needed.
6. Integrity and Confidentiality
Process data securely using appropriate technical and organizational measures. Protect against
unauthorized or unlawful processing, accidental loss, destruction, or damage.
7. Accountability
The controller is responsible for and must be able to demonstrate compliance with all principles.
This requires documentation, policies, training, and ongoing compliance monitoring.
Practical Application
These principles are not abstract concepts - they have practical implications for every aspect
of data processing. For example, a simple email signup form must:
- Have a lawful basis (typically consent)
- State the specific purpose (e.g., "monthly newsletter")
- Only ask for necessary information (email, maybe name - not address if not needed)
- Include email verification to ensure accuracy
- Specify retention period (e.g., "until you unsubscribe")
- Use secure transmission (HTTPS/TLS)
- Document all of the above
Chapter 3: Lawful Basis for Processing
3.1 The Six Legal Bases
Article 6 requires that every processing activity have one of six lawful bases. Choosing the
correct legal basis is crucial - it affects data subject rights and your obligations.
1. Consent (Article 6(1)(a))
The data subject has given clear consent for you to process their personal data for a specific purpose.
When to use: Marketing, optional features, non-essential processing
Requirements: Freely given, specific, informed, unambiguous, easily withdrawable
Example: Email newsletter signup with opt-in checkbox
2. Contract (Article 6(1)(b))
Processing is necessary to perform a contract with the data subject or to take steps before entering a contract.
When to use: Providing services, fulfilling orders
Cannot use for: "Nice to have" data not essential for the service
Example: Collecting shipping address to deliver purchased goods
3. Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with a legal obligation (EU or member state law).
When to use: Tax records, employment law requirements, health and safety
Example: Retaining payroll records for 6 years for tax purposes
4. Vital Interests (Article 6(1)(d))
Processing is necessary to protect someone's life or physical integrity.
When to use: Medical emergencies, life-threatening situations
Example: Sharing medical information with paramedics in an emergency
5. Public Task (Article 6(1)(e))
Processing is necessary to perform a task in the public interest or in the exercise of official authority.
When to use: Public authorities, official functions
Not available to: Private sector organizations
Example: Government agency processing census data
6. Legitimate Interests (Article 6(1)(f))
Processing is necessary for your legitimate interests or those of a third party, unless outweighed
by the data subject's interests or fundamental rights and freedoms.
When to use: Fraud prevention, network security, internal administration
Not available to: Public authorities for their tasks
Requires: Legitimate Interest Assessment (LIA) balancing test
Example: Fraud detection systems to protect customers and business
3.2 Choosing the Right Legal Basis
Selecting the appropriate legal basis is a critical decision that should be made before you begin
processing. Consider:
- Is the processing truly necessary for the stated purpose?
- Could the purpose be achieved differently with less data?
- What rights will data subjects have under this legal basis?
- Can you demonstrate compliance?
Common Mistakes to Avoid
- Using consent when contract is more appropriate
- Claiming legitimate interests without performing an LIA
- Bundling consent for multiple unrelated purposes
- Making consent a condition of service when not necessary
- Changing legal basis mid-processing without justification
Chapter 4: Data Subject Rights
GDPR grants individuals comprehensive rights over their personal data. Organizations must have
processes in place to facilitate these rights efficiently.
4.1 Right of Access (Article 15)
Individuals have the right to obtain confirmation that their data is being processed and to receive
a copy of their personal data along with information about the processing.
Response time: 1 month (extendable to 3 months for complex requests)
Fee: Free (unless manifestly unfounded or excessive)
Must provide: Copy of data, purposes, recipients, retention period, rights information
4.2 Right to Rectification (Article 16)
Individuals can require you to correct inaccurate personal data and complete incomplete data.
Timeframe: Without undue delay
Best practice: Self-service portal for common corrections
4.3 Right to Erasure / Right to be Forgotten (Article 17)
Individuals can request deletion of their personal data when:
- Data is no longer necessary for the purpose it was collected
- They withdraw consent (and there's no other legal basis)
- They object to processing and there are no overriding legitimate grounds
- Data was unlawfully processed
- Erasure is required by law
Exceptions: Legal obligation, public interest, legal claims, freedom of expression
Important: Must also inform recipients of the data about the erasure
4.4 Right to Data Portability (Article 20)
Individuals can receive their personal data in a structured, commonly used, machine-readable format
and transmit it to another controller.
Applies to: Automated processing based on consent or contract
Format: JSON, CSV, XML, or other machine-readable format
Must include: Data provided by individual and data generated by their use of service
4.5 Right to Restriction of Processing (Article 18)
Individuals can request that you stop processing their data (but continue storing it) while:
- Accuracy is being verified
- Processing is unlawful but they don't want erasure
- You no longer need the data but they need it for legal claims
- Their objection is being assessed
4.6 Right to Object (Article 21)
Individuals can object to:
- Direct marketing: Absolute right - must stop immediately
- Processing based on legitimate interests: Must stop unless you demonstrate
compelling legitimate grounds that override their interests
- Processing for research/statistics: Unless necessary for public interest
4.7 Rights Related to Automated Decision-Making (Article 22)
Individuals have the right not to be subject to decisions based solely on automated processing
(including profiling) that produce legal effects or similarly significant effects.
Safeguards required:
- Right to obtain human intervention
- Right to express their point of view
- Right to contest the decision
- Explanation of the logic involved
4.8 Implementing Data Subject Rights
Successful rights management requires:
- Clear procedures and workflows
- Staff training on recognizing and handling requests
- Identity verification processes
- Tracking systems to meet deadlines
- Integration with data systems for data discovery
- Templates for consistent responses
- Escalation procedures for complex cases
Chapter 5: Consent Management
5.1 What is Valid Consent?
Article 7 sets strict requirements for valid consent. It must be:
Freely Given
No imbalance of power, no making consent a precondition for service (unless genuinely necessary),
no bundling consent for unrelated purposes.
Specific
Separate consent for different processing purposes. Granular consent options - not a single
"agree to all" checkbox.
Informed
Individuals must understand what they're consenting to: identity of controller, purposes,
data types, right to withdraw, any automated decision-making.
Unambiguous
Clear affirmative action required (no pre-ticked boxes, no silence/inactivity). Active opt-in,
not opt-out.
5.2 Demonstrating Consent
Controllers must be able to demonstrate that consent was obtained. Record:
- Who consented
- When they consented
- What they were told (consent text, version)
- How they consented (mechanism used)
- Whether they've withdrawn consent
Consent Record Example
User ID: user_12345
Timestamp: 2025-12-25T10:30:00Z
Purpose: Marketing emails
Consent text version: 2.1
Mechanism: Checkbox
IP address: 192.168.1.100
User agent: Mozilla/5.0...
Status: Active
5.3 Withdrawal of Consent
Withdrawing consent must be as easy as giving it. Provide:
- Clear information about the right to withdraw
- Simple withdrawal mechanism (one-click unsubscribe links)
- Immediate effect (stop processing without delay)
- Confirmation of withdrawal
- No negative consequences for withdrawal
5.4 Special Category Data Consent
Processing special category data (health, race, religion, etc.) requires explicit consent
under Article 9. This is a higher bar than regular consent:
- Must be express and specific
- Often requires written confirmation
- Clear statement of what data and why
- Cannot be inferred from silence or inactivity
5.5 Children's Consent
For children under 16 (member states can lower to 13), parental consent is required for
information society services. You must:
- Make reasonable efforts to verify parental consent
- Use age-appropriate language
- Explain processing in a way children can understand
- Provide extra protections for children's data
Chapter 6: Data Protection Officer
6.1 When is a DPO Required?
Article 37 requires appointment of a Data Protection Officer when:
- Processing is carried out by a public authority (except courts acting in judicial capacity)
- Core activities consist of regular and systematic monitoring of data subjects on a large scale
- Core activities consist of large-scale processing of special category data or criminal conviction data
What is "Large Scale"?
Not defined in GDPR, but consider:
- Number of data subjects (as number or proportion of population)
- Volume of data and/or range of data items
- Duration or permanence of processing
- Geographical extent
6.2 DPO Qualifications and Independence
The DPO must have:
- Expert knowledge of data protection law and practices
- Understanding of the organization's operations
- Ability to perform risk assessments
- Independence (no conflict of interest)
- Adequate resources and support
6.3 DPO Tasks and Responsibilities
- Monitor compliance with GDPR and organizational policies
- Provide advice on data protection obligations
- Conduct Data Protection Impact Assessments
- Train staff on data protection
- Serve as contact point for supervisory authorities
- Handle data subject inquiries
- Cooperate with supervisory authority
6.4 Working with Your DPO
Organizations should:
- Involve DPO in all data protection matters from the start
- Provide access to all relevant information and operations
- Ensure DPO can perform duties independently
- Not penalize DPO for performing their tasks
- Make DPO's contact details publicly available
Chapter 7: Security Measures
7.1 Article 32: Security of Processing
Controllers and processors must implement appropriate technical and organizational measures to
ensure a level of security appropriate to the risk.
7.2 Technical Measures
Encryption
- At rest: AES-256 for stored data
- In transit: TLS 1.3 or higher for data transmission
- Backups: Encrypted backup files
- Devices: Full disk encryption on laptops and mobile devices
Access Controls
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Principle of least privilege
- Regular access reviews
- Immediate revocation upon termination
Pseudonymization and Anonymization
- Pseudonymization for analytics and testing
- Data masking in non-production environments
- Anonymization when personal identification not needed
- Separate storage of identification keys
System Security
- Regular security testing and vulnerability assessments
- Intrusion detection and prevention systems
- Firewalls and network segmentation
- Antivirus and anti-malware protection
- Security patch management
7.3 Organizational Measures
Policies and Procedures
- Data protection policies
- Acceptable use policies
- Incident response procedures
- Data retention and disposal policies
- Third-party management procedures
Training and Awareness
- Regular GDPR training for all staff
- Role-specific training (DPO, IT, HR, Marketing)
- Security awareness programs
- Phishing simulation exercises
- Privacy champion program
Physical Security
- Secure facility access controls
- Visitor management
- Clean desk policy
- Secure destruction of physical records
- CCTV and surveillance
7.4 Testing and Monitoring
- Regular security audits
- Penetration testing
- Vulnerability scanning
- Log monitoring and analysis
- Security incident tracking
Chapter 8: Breach Notification
8.1 What is a Personal Data Breach?
A breach of security leading to the accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to, personal data.
Types of Breaches
- Confidentiality breach: Unauthorized access or disclosure
- Availability breach: Accidental or unauthorized loss, destruction
- Integrity breach: Unauthorized or accidental alteration
8.2 Notification to Supervisory Authority (Article 33)
If a breach is likely to result in a risk to individuals' rights and freedoms, you must notify
the supervisory authority within 72 hours of becoming aware of it.
What to Include:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact details (usually DPO)
8.3 Notification to Data Subjects (Article 34)
If the breach is likely to result in a high risk to individuals' rights and
freedoms, you must also notify affected data subjects without undue delay.
Exceptions:
- Technical protection measures were applied (e.g., encryption)
- Subsequent measures eliminate the high risk
- Notification would require disproportionate effort (public communication instead)
8.4 Breach Response Process
1. Detection and Containment (0-4 hours)
- Detect and verify the breach
- Contain the breach to prevent further damage
- Preserve evidence for investigation
- Activate incident response team
2. Assessment (4-24 hours)
- Determine scope: what data, how many people
- Assess risk to individuals
- Decide if notification required
- Begin documentation
3. Notification (24-72 hours)
- Notify supervisory authority if required
- Notify affected individuals if high risk
- Inform other parties (processors, law enforcement)
4. Remediation (Ongoing)
- Implement fixes and security improvements
- Monitor for additional incidents
- Support affected individuals
- Complete investigation
5. Post-Incident Review
- Document lessons learned
- Update policies and procedures
- Improve security measures
- Train staff on findings
8.5 Breach Documentation
Article 33(5) requires documentation of all breaches (even if not notified), including:
- Facts of the breach
- Effects and consequences
- Remedial actions taken
Chapter 9: International Transfers
9.1 Why Transfers Need Safeguards
GDPR's protections must "travel" with the data when it moves outside the EU/EEA. Organizations
cannot circumvent GDPR by moving data to countries with weaker protections.
9.2 Transfer Mechanisms
1. Adequacy Decisions (Article 45)
The European Commission recognizes certain countries as providing adequate data protection.
Transfers to these countries don't require additional safeguards.
Adequate Countries: UK, Canada (commercial), Japan, South Korea, Switzerland,
New Zealand, Uruguay, Argentina, and others.
2. Standard Contractual Clauses (Article 46)
Pre-approved contract templates provided by the European Commission. The 2021 version includes
four modules for different transfer scenarios.
3. Binding Corporate Rules (Article 47)
Internal policies for multinational companies to transfer data within their corporate group.
4. Derogations (Article 49)
Specific situations allowing transfers without safeguards:
- Explicit informed consent
- Necessary for contract performance
- Important public interest
- Legal claims
- Vital interests
9.3 Transfer Impact Assessment (TIA)
Following the Schrems II decision, organizations must assess whether the destination country's
laws might undermine the safeguards. Consider:
- Government surveillance laws
- Data disclosure requirements
- Individual redress mechanisms
- Rule of law and independent oversight
9.4 Supplementary Measures
If the TIA reveals risks, implement additional technical, organizational, or contractual measures:
- End-to-end encryption with EU-held keys
- Pseudonymization or anonymization
- Multi-party computation
- Enhanced contractual protections
- Transparency and notification obligations
Chapter 10: Implementation Guide
10.1 Getting Started: The First 30 Days
Week 1: Assessment
- Form GDPR compliance team
- Appoint or designate DPO (if required)
- Conduct high-level data inventory
- Identify critical gaps
- Prioritize compliance activities
Week 2-3: Foundation
- Map data flows (what, where, why, how long)
- Document lawful basis for each processing activity
- Begin Records of Processing Activities (RoPA)
- Review privacy notices
- Assess vendor contracts
Week 4: Quick Wins
- Update website privacy notice
- Implement consent checkboxes where needed
- Create data subject request email/form
- Conduct initial staff awareness session
- Document progress
10.2 Building Your Compliance Program
Governance
- Establish privacy governance committee
- Define roles and responsibilities
- Create escalation procedures
- Set compliance KPIs
- Regular management reporting
Policies and Procedures
- Data protection policy
- Data retention schedule
- Data subject rights procedures
- Breach response plan
- Vendor management procedures
- DPIA process
Technology Solutions
- Consent management platform
- Data subject request portal
- Data mapping and discovery tools
- Privacy management software
- Encryption and security tools
10.3 Ongoing Compliance
Monthly
- Review data subject requests status
- Monitor consent withdrawal rates
- Check vendor compliance
- Review any incidents or near-misses
Quarterly
- Audit consent records
- Review and update RoPA
- Assess new projects for DPIA needs
- Staff training sessions
- Compliance metrics reporting
Annually
- Comprehensive compliance audit
- Review all policies and procedures
- Update privacy notices
- Refresh Data Processing Agreements
- Re-assess DPIAs
- Full staff training program
10.4 Measuring Success
Track compliance through metrics such as:
- Data subject requests handled within deadline (target: 100%)
- Average response time for requests
- Staff training completion rate (target: 100%)
- Privacy notice view/acceptance rates
- Consent withdrawal vs. grant rate
- Vendor compliance score
- Security incidents and time to resolution
- DPIA completion for new projects
Signs of Mature Compliance
- Privacy considered in all new projects from the start
- Staff proactively identify privacy issues
- Efficient, streamlined rights management
- Strong vendor accountability
- Regular audits with action plans
- Privacy as competitive advantage
10.5 Final Thoughts
GDPR compliance is not a one-time project but an ongoing journey. The regulation embodies the
principle of ๅผ็ไบบ้ (Hongik Ingan) - "Benefit All Humanity" - by ensuring that personal data
is treated with respect and that individuals have control over their information.
Organizations that embrace privacy as a core value, rather than viewing it as a compliance
burden, will build stronger relationships with customers, reduce risks, and create competitive
advantages in an increasingly privacy-conscious world.
The WIA-SEC-024 standard provides the framework and tools to achieve comprehensive GDPR
compliance. By implementing these practices, organizations contribute to a more ethical,
transparent, and trustworthy digital ecosystem that benefits all humanity.