European Union · GDPR

EU General Data Protection Regulation

The EU’s data protection law can reach Australian businesses. Vectra can help you work out if you are covered, and comply.

What it is

The European Union General Data Protection Regulation (the GDPR) sets data protection requirements that apply from 25 May 2018. It harmonises data protection laws across the EU and replaces the earlier national rules. Clear, uniform rules are meant to give businesses legal certainty and build consumer trust in online services.

Who it applies to

It applies to businesses of any size that control or process personal data and have an establishment in the EU. It also covers businesses outside the EU that offer goods or services to people in the EU, or monitor their behaviour there. Some Australian businesses covered by the Privacy Act 1988 (Cth) - known as APP entities - may need to comply.

GDPR data protection concept over a business desk

How Vectra can help with GDPR compliance.

Vectra has the resources to help you achieve GDPR compliance.

Gap assessment

We run a preliminary GDPR gap assessment to show where you stand.

Measures and policies

We help you put in place the right technical and organisational measures, including data protection policies. They let you make sure - and show - that your processing complies with the GDPR.

Monitoring and assurance

We provide ongoing monitoring and assurance.

When the GDPR applies to your business.

Controllers and processors

A controller decides how and why personal data is processed. A processor acts for the controller. The GDPR applies to both, whatever their size.

An establishment in the EU

If your business has an establishment in the EU, its processing of personal data must comply, even if the data is processed outside the EU.

Offering goods or services in the EU

A business outside the EU is covered when its processing relates to offering goods or services to people in the EU, whether or not they pay.

Monitoring behaviour in the EU

A business outside the EU is also covered when it monitors the behaviour of people in the EU, where that behaviour takes place in the EU.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.