About Us Contact Blog
Governance DocsGovernance Docs
All ToolkitsWhich Toolkit?AboutBlogContactMy AccountCart
FOX v.2.4.9
Browse Toolkits
Governance Docs
  • Browse All Toolkits
  • Information Security & Cybersecurity
  • Data Privacy & Protection
  • Governance, Risk & Compliance
  • Quality Management
  • Health, Safety & Environment
  • AI Governance

My Account

CART

No products in the cart.

Category: GDPR

The General Data Protection Regulation is the EU law governing how personal data may be collected, used, shared and stored. It applies to any organisation processing the personal data of people in the EU, wherever that organisation is based — which is why it reaches far beyond Europe.
Seven principles sit at its core: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The last is the one that creates most of the work, because accountability means you must be able to demonstrate compliance, not merely achieve it.
In practice that demonstration is documentary. A record of processing activities, privacy notices, a lawful basis for each processing purpose, data processing agreements with every processor, data protection impact assessments for high-risk processing, a breach register and a documented procedure for handling data subject requests within one month.
The guides below cover the principles, the eight data subject rights, what a compliant DPA must contain under Article 28, how to run a gap analysis, the full documentation checklist, and how GDPR interacts with ISO 27701.

GDPR gap analysis steps from mapping data to building a prioritised remediation plan

How to Run a GDPR Gap Analysis

Governance Docs17th July 2026

A GDPR gap analysis shows exactly where you stand against the regulation. Here is a step-by-step method to…
Read More
GDPR data subject rights explained including access, rectification, erasure and portability

GDPR Data Subject Rights Explained

Governance Docs17th July 2026

The GDPR data subject rights put individuals in control of their data. Here are all eight rights, how…
Read More
GDPR DPA guide - what a data processing agreement is and the Article 28 requirements

GDPR Data Processing Agreement (DPA): A Complete Guide

Governance Docs17th July 2026

A GDPR DPA is required whenever a third party processes personal data for you. Here is what a…
Read More
The 7 GDPR principles explained from lawfulness and minimisation to accountability

The 7 GDPR Principles Explained

Governance Docs17th July 2026

The seven GDPR principles are the foundation of the whole regulation. Here is what each one requires in…
Read More
GDPR documentation requirements checklist including ROPA, privacy notices, DPAs and DPIAs

GDPR Documentation Requirements Checklist

Governance Docs17th July 2026

The accountability principle makes documentation central to GDPR. Here is a complete checklist of the records you need…
Read More
ISO 27701: Essential Must-Have for Best Data Privacy Strategy.

ISO 27701:2025 vs 2019: What Changed and What You Must Do

Governance Docs30th May 2026

Key Takeaways ISO/IEC 27701:2025 replaced the 2019 edition on 14 October 2025 and is now a standalone standard. An ISO 27001 certificate is no longer a prerequisite for certifying a
Read More
Data Protection Strategy: Must-Have Tips for Scalable Success.

Building a Scalable Data Protection Strategy

Governance Docs18th May 2026

Building a strong data protection strategy is essential for businesses aiming to safeguard sensitive information while growing confidently.…
Read More
GDPR compliance explained - the seven principles, lawful bases, data subject rights and duties

GDPR Explained: A Complete Compliance Guide

Governance Docs22nd April 2026

GDPR compliance is a legal requirement for anyone handling EU personal data. A complete guide to the principles,…
Read More
ISO 27701 privacy information management system explained

ISO 27701: A Guide to Privacy Information Management

Governance Docs10th April 2026

ISO 27701 is the international standard for privacy information management. This guide explains what a PIMS covers, what…
Read More

Recent Posts

ISO 27001 internal audit seven-step cycle under clause 9.2, from audit program to corrective action
ISO 27001 Internal Audit: The Complete 2026 Guide to Clause 9.2

August 11, 2026

ISO 27001 Stage 1 vs Stage 2 audit comparison infographic
ISO 27001 Stage 1 vs Stage 2: The Complete 2026 Audit Guide

August 10, 2026

ISO 27001 gap analysis chart for governance documentation and compliance.
ISO 27001 Gap Analysis: The Complete 2026 Step-by-Step Guide

August 9, 2026

ISO 27001 risk assessment process showing the six steps from criteria to treatment decision
ISO 27001 Risk Assessment: The Complete 2026 Method

August 7, 2026

ISO 27001 Statement of Applicability infographic showing all 93 Annex A controls across four themes
ISO 27001 Statement of Applicability: The Complete 2026 Guide

August 6, 2026

Categories

  • Articles
  • DORA
  • GDPR
  • HIPAA
  • ISO 27001
  • ISO 42001 & AI governance
  • ISO 9001
  • Management systems
  • NIS2
  • Security frameworks
  • SOC 2
Governance DocsGovernance Docs

Reliable ISO & compliance documentation toolkits that help your business meet regulatory standards with ease.

Governance Docs LLC
1209 Mountain Road Pl NE, Suite R
Albuquerque, NM 87110, USA
info@governancedocs.com
+1 812 227 5662

Toolkits

  • ISO 27001:2022
  • GDPR
  • SOC 2
  • PCI-DSS v4.0
  • HIPAA
  • ISO 42001
  • All toolkits →

Company

  • About Us
  • Blog
  • Contact
  • FAQ
  • Which toolkit do I need?

Policies

  • Privacy Policy
  • Terms & Conditions
  • Refund & Return Policy
  • Delivery Policy
© 2026 Governance Docs LLC. All rights reserved.
Secure checkoutstripeVISA