Frameworks /  EU

GDPR

The GDPR is the European Union's data protection regulation, governing how personal data of people in the EU is collected, processed, secured, transferred and deleted. It applies to organisations outside the EU, including in Israel, whenever they target or monitor people in the EU.

What it requires

Processing must rest on a lawful basis (Article 6: consent, contract, legal obligation, vital interests, public task or legitimate interests), with an additional condition under Article 9 for special-category data. Controllers must maintain records of processing activities (Article 30), implement appropriate technical and organisational security measures (Article 32), honour data subject rights including access, rectification, erasure, restriction, portability and objection (Articles 12-23), and carry out a Data Protection Impact Assessment where processing is likely to result in high risk (Article 35). Personal data breaches must be notified to the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals (Article 33), and to affected individuals without undue delay where the risk is high (Article 34). Certain organisations must appoint a Data Protection Officer (Article 37), and transfers of personal data outside the EEA require a valid transfer mechanism such as an adequacy decision or Standard Contractual Clauses with a transfer impact assessment (Chapter V). The maximum administrative fine is up to €20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements; a lower tier of up to €10 million or 2% applies to other infringements.

GDPR applies to any organisation established in the EU, and, under Article 3(2), to organisations anywhere in the world that offer goods or services to people in the EU or monitor their behaviour. Israel holds an EU adequacy decision, which permits personal data to flow from the EU to Israeli recipients without additional safeguards; that adequacy does not exempt an Israeli company from the GDPR when it is itself targeting EU individuals. The practical trigger for most Israeli mid-market companies is a European customer sending a Data Processing Agreement, or an EU-facing product launch.

The controls people actually fail

  • The Article 30 record of processing activities was written once by an external consultant and never updated: new systems, new sub-processors and new data flows were added without touching it.
  • No data retention is actually enforced: the policy promises deletion after X years, but nothing deletes, and old databases, backups and exports persist indefinitely.
  • Sub-processors are used without a signed Article 28 processing agreement, without listing them for customers, and without any transfer mechanism for those outside the EEA.
  • Data subject requests have no operational process: no intake channel, no owner, no clock, no ability to actually locate all copies of one person's data across systems.
  • DPIAs are not performed for high-risk processing (large-scale profiling, biometric processing, systematic monitoring), or are performed as a form-filling exercise with no risk mitigation resulting.
  • Cookie and tracking consent on the website does not match reality: trackers fire before consent, and "legitimate interest" is claimed for marketing analytics that requires consent.
  • There is no breach detection capability, which makes the 72-hour clock unmeetable: you cannot notify within 72 hours of awareness if you never become aware.
GDPR has no certificate to expire, which is precisely why it decays invisibly. Compliance is a property of your live data flows, and those change every time engineering adds a vendor, marketing adds a pixel, or a new product ships. The gap between the record of processing you wrote and the data you hold widens every sprint. The day you discover the size of that gap is usually the day of a breach or a regulator's question.

Does GDPR apply to Israeli companies?

Yes, whenever the Israeli company offers goods or services to people in the EU or monitors their behaviour (Article 3(2)), or processes personal data on behalf of an EU customer as a processor. Israel benefits from an EU adequacy decision, which means personal data can be transferred from the EU to Israel without additional safeguards such as Standard Contractual Clauses, but adequacy governs the transfer, not your own obligations. An Israeli SaaS company with EU users is directly subject to the GDPR.

When do we have to appoint a Data Protection Officer under GDPR?

Article 37 requires a DPO where the processing is carried out by a public authority or body; where the core activities consist of regular and systematic monitoring of data subjects on a large scale; or where the core activities consist of large-scale processing of special categories of data (such as health, biometric or racial/ethnic data) or of data relating to criminal convictions and offences. The DPO must be appointed on the basis of professional qualities and expert knowledge of data protection law and practice, must report to the highest management level, must not be instructed on how to perform the role, and may be an external contractor. Some member states impose additional national requirements.

What is the GDPR breach notification deadline?

Notification to the competent supervisory authority is due without undue delay and, where feasible, not later than 72 hours after becoming aware of the personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals (Article 33). If the breach is likely to result in a high risk to individuals, they must also be informed without undue delay (Article 34). If the full facts are not yet known, you notify within 72 hours with what you have and supply the rest in phases; a processor must notify its controller without undue delay.

What are the maximum GDPR fines?

Two tiers. The higher tier (up to €20 million or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher) applies to infringements of the basic principles, lawful basis, data subject rights and the rules on international transfers. The lower tier (up to €10 million or 2%) applies to infringements such as failures of security (Article 32), records of processing, breach notification, DPIA and DPO obligations. Supervisory authorities also hold corrective powers short of fines, including bans on processing, which are often the more commercially damaging outcome.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.