Skip to Content
  • Craft’s easy-to-use platform simplifies supply chain resilience and speeds time to value with new enhanced capabilities

    Learn More
Craft Logo
  • Platform
  • Solutions
    • Supplier Intelligence

      Conduct checks in hours instead of weeks with comprehensive supplier intelligence you can trust.

    • Supplier Risk Management

      Stay alerted to changes in supplier health to understand threats and avoid disruption.

    • Supply Chain Risk Management

      Gain insights into supplier dependencies and risks to predict and prevent disruption.

  • Risk and Compliance
    • Risk and Compliance Solutions

    • Compliance Hub

      Navigate complex regulatory landscapes

    • Cybersecurity

      Defend against cyber threats.

    • ESG

      Empower sustainable practices with ESG insights.

    • Financial

      Identify and navigate financial risks.

    • Geopolitical

      Navigate geopolitical risks with confidence.

  • Industries
    • Aerospace and Defense

      Simplify risk management in this complex and crucial sector.

    • Federal Government

      Enhance risk visibility and mitigation in federal government.

    • Financial Services

      Navigate challenges within the financial services sector.

    • Manufacturing

      Optimize risk management in manufacturing.

  • Resource Center
    • Resources

      Learn more about Craft, our vision, and what we’re doing to strengthen global supply chain resilience.

    • Blog

      Explore Craft thought leadership from our technology and supply chain experts.

    • Events

      Get the latest industry news, topics, and trends from Craft experts.

  • Company
    • About Us

      Learn about our mission, world-class technology, and esteemed investors.

    • Culture & Careers

      Learn about our culture and check out our current job postings.

    • Newsroom

      Stay up to date on our latest news and announcements.

    • Contact Us

      Learn more about the Craft platform and how we can mitigate risk to your supply chain.

  • Request a Demo
Quick GuidesRegulatory & Compliance

Understanding the General Data Protection Regulation (GDPR)

Share


What is the GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive privacy and data protection law that was enacted by the European Union (EU) on May 25, 2018. It replaces the 1995 Data Protection Directive and establishes stringent rules for how personal data is collected, processed, and stored by organizations operating within the EU or handling data of EU citizens. The GDPR is designed to give individuals greater control over their personal data while imposing strict penalties on organizations that fail to comply with its requirements.

Why was the GDPR created?

The GDPR was created in response to growing concerns about privacy and data protection in the digital age. The rapid expansion of online services and the increasing collection of personal data by companies highlighted the need for a stronger regulatory framework to protect individuals’ privacy rights. The GDPR aims to harmonize data protection laws across the EU, ensuring that all EU citizens enjoy the same level of data protection regardless of where their data is processed. It also seeks to enhance the transparency and accountability of organizations in handling personal data, thereby fostering greater trust between consumers and businesses.

Who has to comply with the GDPR?

The GDPR applies to any organization, regardless of its location, that processes the personal data of individuals residing in the EU. This includes businesses, public authorities, and other entities that offer goods or services to EU citizens or monitor their behavior. Specific examples include:

  • Companies based outside the EU that target EU customers.
  • Data processors and controllers within the EU.
  • Organizations that process large volumes of personal data or sensitive data, such as healthcare providers and financial institutions.

How will the GDPR affect businesses?

The GDPR has far-reaching implications for businesses, particularly in how they handle personal data. Key impacts include:

  • Increased Accountability: Organizations must implement comprehensive data protection policies, including appointing Data Protection Officers (DPOs) in certain cases.
  • Enhanced Consent Requirements: Companies must obtain explicit consent from individuals before collecting and processing their data. Consent must be freely given, specific, informed, and unambiguous.
  • Data Breach Notifications: Businesses must notify the relevant supervisory authority of a data breach within 72 hours of becoming aware of it. In some cases, they must also inform affected individuals.
  • Right to Access and Erasure: Individuals have the right to access their personal data and request its deletion under certain circumstances, commonly known as the “right to be forgotten.”
  • Data Protection Impact Assessments (DPIAs): DPIAs are mandatory for processing activities that pose high risks to individuals’ rights and freedoms.

Non-compliance with the GDPR can result in severe penalties, including fines of up to €20 million or 4% of the company’s global annual turnover, whichever is higher.

How do you comply with the GDPR?

To comply with the GDPR, organizations must implement a robust data protection strategy that includes the following steps:

  1. Appoint a Data Protection Officer (DPO): If your organization processes large amounts of personal data or sensitive data, you may need to appoint a DPO to oversee GDPR compliance.
  2. Conduct Data Audits: Identify and document all personal data processing activities within your organization. This includes understanding what data is collected, how it is processed, where it is stored, and who has access to it.
  3. Implement Data Protection Policies: Develop and enforce policies that align with GDPR requirements, including data minimization, purpose limitation, and data retention policies.
  4. Enhance Security Measures: Implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, or theft. This includes encryption, access controls, and regular security assessments.
  5. Obtain Valid Consent: Review and update your consent mechanisms to ensure they meet GDPR standards. Make it easy for individuals to withdraw consent at any time.
  6. Prepare for Data Subject Requests: Establish procedures to handle requests from individuals exercising their GDPR rights, such as access, rectification, and erasure.

How do you prepare for the GDPR?

Preparation for GDPR compliance involves proactive planning and continuous monitoring. Here’s how to get started:

  1. Awareness and Training: Ensure that all employees, especially those involved in data processing, are aware of GDPR requirements and receive regular training on data protection practices.
  2. Data Mapping: Conduct a thorough data mapping exercise to understand the flow of personal data within your organization and identify any potential compliance gaps.
  3. Review Contracts: Update contracts with third-party vendors and partners to include GDPR-compliant data protection clauses, ensuring they adhere to the same standards as your organization.
  4. Regular Audits: Perform regular audits of your data protection practices to identify areas for improvement and address any compliance issues promptly.
  5. Engage with Supervisory Authorities: Maintain open communication with your national data protection authority to stay informed about regulatory updates and guidance.

Action Plan

1. Understand the Implementation Timeline

The GDPR has been in effect since May 25, 2018. Ongoing compliance is required.

2. Develop a Data Protection Framework

Implement policies and procedures that align with GDPR principles, including data minimization, purpose limitation, and data retention.

3. Conduct Data Protection Impact Assessments (DPIAs):

Assess the risks associated with data processing activities and implement measures to mitigate those risks.

4. Ensure Transparency and Accountability:

  • Publish your privacy policy and make it easily accessible to all stakeholders.
  • Document your data protection practices and keep records of data processing activities.

5. Implement Assurance Measures

  • Regularly review and update your data protection practices to ensure ongoing compliance.
  • Consider engaging third-party auditors to assess your GDPR compliance.

How can Craft help?

Craft’s supplier risk management solutions are designed to streamline compliance and enhance reporting. With our platform:

  • Identify risky suppliers with in-depth company profiles and easily scalable due diligence
  • Continuously monitor your supplier network for changes and potential violations
  • Document your efforts for proof of compliance
  • Collaborate and share information across teams for faster risk mitigation

Learn More

Related Regulations

1. The upcoming European Commission’s ePrivacy Regulation complements the GDPR by focusing on electronic communications and privacy.
2. The Directive on Security of Network and Information Systems (NIS Directive) enhances cybersecurity across the EU.
3. The California Consumer Privacy Act (CCPA) grants California residents rights similar to those under the GDPR, with a focus on transparency and data access.
4. The UK Data Protection Act 2018 ensures that UK data protection laws remain aligned with the GDPR.
5. The ISO/IEC 27001 is an international standard for managing information security that supports GDPR compliance.

Conclusion

The GDPR represents a significant step forward in protecting individuals’ privacy rights in the digital age. For procurement and supply chain professionals, understanding and complying with the GDPR is essential to maintaining customer trust and avoiding hefty penalties. By following the steps outlined in this guide and leveraging tools like Craft’s supplier risk management solutions, your organization can navigate GDPR compliance with confidence.

For more resources on data protection and supply chain compliance, visit Craft’s compliance hub.

Share

In this article

  • What is the GDPR?

  • Why was the GDPR created?

  • Who has to comply with the GDPR?

  • How will the GDPR affect businesses?

  • How do you comply with the GDPR?

  • How do you prepare for the GDPR?

  • Action Plan

  • How can Craft help?

  • Related Regulations

  • Conclusion

  • Risk and Compliance Solutions

    Get the visibility and insights you need to identify and mitigate risk and build a more resilient supply chain.

    Learn More

Related Posts

View All
  • Procurement & Supply Chain

    The Risk Savvy Report: April 22 – May 12, 2025

    Read Now
  • Procurement & Supply Chain

    The Risk Savvy Report: April 1 – 21, 2025

    Read Now
  • Procurement & Supply Chain

    The Risk Savvy Report: March 18 – 31, 2025

    Read Now

Ready to learn more?

Schedule a risk assessment session with our team to learn more about Craft.

Get Risk Assessment
Craft.co

Craft provides organizations with the 360-degree visibility, timely insights, and agility needed to mitigate risk and build stronger supplier networks and more resilient supply chains.


Sign up for our newsletter

  • Platform
  • Solutions
    • Supplier Intelligence
    • Supplier Risk Management
    • Supply Chain Risk Management
  • Risk and Compliance
    • Risk and Compliance Solutions
    • Compliance Hub
    • Cybersecurity
    • ESG
    • Financial
    • Geopolitical
  • Industries
    • Aerospace and Defense
    • Federal Government
    • Financial Services
    • Manufacturing
  • Resource Center
    • Resources
    • Blog
    • Events
  • Company
    • About Us
    • Culture & Careers
    • Newsroom
    • Contact Us
  • Request a Demo
  • Facebook
  • LinkedIn
  • Twitter
  • Terms of Service
  • Privacy Policy
  • Security

© 2025 Craft.co. All rights reserved.

We value your privacy
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits.
By clicking “Accept”, you consent to the use of ALL the cookies.
Privacy Policy
In case of sale of your personal information, you may opt out by using the link Do not sell my personal information.
CustomizeAccept
Consent Preferences

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
Reject All Save My Preferences Accept All