---
title: "GDPR Compliance"
description: "Data processing agreements, subprocessor management, and breach notification under GDPR."
canonical: https://www.orbiqhq.com/eu-regulations/gdpr
html: https://www.orbiqhq.com/eu-regulations/gdpr
publisher: Orbiq GmbH
language: en
---
# GDPR Compliance

Data processing agreements, subprocessor management, and breach notification under GDPR.

- [GDPR Compliance 2026: Principles, Rights & Proof](/eu-regulations/gdpr-compliance.md) - GDPR compliance explained for 2026: the 7 principles, 6 lawful bases, data subject rights, the compliance checklist, 2025–26 fines, and UK/Norway divergence.
- [GDPR Compliance for B2B SaaS: Articles 28–34 Explained](/eu-regulations/gdpr-article-28-32-33-34.md) - A B2B SaaS reference to GDPR Articles 28, 32, 33 & 34 — DPAs, security of processing, and breach notification — with a compliance checklist and links to each deep-dive.
- [Subprocessor Management Under GDPR Art. 28](/eu-regulations/subprocessor-management-gdpr-article-28.md) - What do controllers, DPOs, and procurement teams actually expect from your subprocessor management? A practical guide beyond GDPR Article 28 minimum compliance — covering sub-processor lists, change notifications, data flow transparency, and ongoing due diligence.
- [GDPR Article 33: 72-Hour Breach Notification Rule (2026)](/eu-regulations/gdpr-article-33.md) - GDPR Article 33: when the 72-hour breach clock starts, exactly what to report, the fines for missing it, how to prove compliance, and the UK & Norway position.
- [GDPR Art. 34: Communicating a Breach to Data Subjects (2026)](/eu-regulations/gdpr-article-34.md) - GDPR Article 34: when you must tell individuals about a breach, the high-risk threshold, the three exceptions that get you out of it, and how to prove it.
- [GDPR Article 32: Security of Processing Requirements (2026)](/eu-regulations/gdpr-article-32.md) - GDPR Article 32 explained: the technical and organisational measures required, whether encryption is mandatory, the risk-based test, fines, and how to prove it.
- [GDPR Article 28: DPA Requirements & Processor Duties (2026)](/eu-regulations/gdpr-article-28.md) - GDPR Article 28 explained: the mandatory DPA clauses, controller due-diligence duties, sub-processor authorisation, EDPB Opinion 22/2024, and how to prove it.
- [EU Compliance Software: Complete Buyer's Guide (2026)](/eu-regulations/eu-compliance-software.md) - How to choose EU compliance software in 2026. Covers NIS2, DORA, GDPR, and CRA requirements, key features to evaluate, EU data residency risks, and how Orbiq compares.
- [Compliance Software for Germany: Buyer's Guide 2026](/eu-regulations/compliance-software-comparison.md) - Comparing the best compliance software for German companies in 2026. Covers ISMS, GRC, NIS2, DSGVO/GDPR, BSI IT-Grundschutz, and EU data residency requirements.